---
title: "Supplier GDPR Compliance: DPA Requirements & Audit Guide"
description: Sharing personal data with suppliers? See what UK GDPR Article 28 requires, what a data processing agreement must contain and how to audit your suppliers.
image: https://resources.trustkeith.co/hubfs/Resources%20Card%20template%2c%20Guides%20(55).png
---

[![642bcbad7735490755580d8d\_trust-keith-logo](https://resources.trustkeith.co/hubfs/642bcbad7735490755580d8d_trust-keith-logo.svg "642bcbad7735490755580d8d_trust-keith-logo")](https://www.trustkeith.co/)

- Product 
    - [Privacy OS](https://www.trustkeith.co/product/privacy-os)
    - [Dedicated DPO](https://www.trustkeith.co/product/dedicated-dpo)
    - [Automated Data Discovery](https://www.trustkeith.co/product/automated-data-discovery)
    - [Intelligent Workflows](https://www.trustkeith.co/product/intelligent-workflows)
    - [Staff Training](https://www.trustkeith.co/product/staff-training)
    - [Global Risks & Controls](https://www.trustkeith.co/product/global-risks-controls)
    - [Proportional Policies](https://www.trustkeith.co/product/proportional-policies)
    - [Monitoring & Reporting](https://www.trustkeith.co/product/monitoring-reporting)
- Solutions 
    - [By Industry](https://www.trustkeith.co/solutions/industry)
    - [By Team](https://www.trustkeith.co/solutions/team)
    - [By Use Case](https://www.trustkeith.co/solutions/use-case)
    - [By Privacy Regulation](https://www.trustkeith.co/solutions/regulations)
- [How it works](https://www.trustkeith.co/how-it-works)
- [Customers](https://www.trustkeith.co/customers)
- [Pricing](https://www.trustkeith.co/pricing)
- [Resources](https://resources.trustkeith.co)
- [Company](https://www.trustkeith.co/company)

[![Talk to an expert](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/24879685/859c2149-73c5-4ae5-a465-6c639d24614f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/24879685/859c2149-73c5-4ae5-a465-6c639d24614f)

[![Trust Keith](https://resources.trustkeith.co/hs-fs/hubfs/raw_assets/public/Trustkeith_March2023/images/trust_keith.png?width=500&name=trust_keith.png "Trust Keith")](https://www.trustkeith.co/)

- Product 
    - [Privacy OS](https://www.trustkeith.co/product/privacy-os)
    - [Dedicated DPO](https://www.trustkeith.co/product/dedicated-dpo)
    - [Automated Data Discovery](https://www.trustkeith.co/product/automated-data-discovery)
    - [Intelligent Workflows](https://www.trustkeith.co/product/intelligent-workflows)
    - [Staff Training](https://www.trustkeith.co/product/staff-training)
    - [Global Risks & Controls](https://www.trustkeith.co/product/global-risks-controls)
    - [Proportional Policies](https://www.trustkeith.co/product/proportional-policies)
    - [Monitoring & Reporting](https://www.trustkeith.co/product/monitoring-reporting)
- Solutions 
    - [By Industry](https://www.trustkeith.co/solutions/industry)
    - [By Team](https://www.trustkeith.co/solutions/team)
    - [By Use Case](https://www.trustkeith.co/solutions/use-case)
    - [By Privacy Regulation](https://www.trustkeith.co/solutions/regulations)
- [How it works](https://www.trustkeith.co/how-it-works)
- [Customers](https://www.trustkeith.co/customers)
- [Pricing](https://www.trustkeith.co/pricing)
- [Resources](https://resources.trustkeith.co)
- [Company](https://www.trustkeith.co/company)

[![Talk to an expert](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/24879685/859c2149-73c5-4ae5-a465-6c639d24614f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/24879685/859c2149-73c5-4ae5-a465-6c639d24614f)

[![Talk to an expert](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/24879685/859c2149-73c5-4ae5-a465-6c639d24614f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/24879685/859c2149-73c5-4ae5-a465-6c639d24614f)

![Menu Icon](https://resources.trustkeith.co/hubfs/raw_assets/public/Trustkeith_March2023/images/icon-menu.svg) ![Menu close](https://resources.trustkeith.co/hubfs/raw_assets/public/Trustkeith_March2023/images/icon-x.svg)

![](https://resources.trustkeith.co/hubfs/Resources%20Card%20template%2c%20Guides%20(55).png)

# Third-Party Risk and Data Protection: Managing Your Supplier Chain

 Published by [Trust Keith](https://resources.trustkeith.co/author/trust-keith) on  Oct 6, 2026, 5:05:53 PM

**Quick answer:** If you share personal data with a supplier, UK GDPR makes you responsible for choosing one that can protect it, and for having a written data processing agreement in place that meets Article 28. Then keep checking, in proportion to the risk. Know who your suppliers are, where the data goes, and what happens if something goes wrong.

**Contents**

- •  [Why Third-Party Risk Gets Underestimated](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#why-third-party-risk-gets-underestimated)
- •  [Processors vs Controllers: Who's Responsible for What](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#processors-vs-controllers-who-s-responsible-for-what)
- •  [What a Data Processing Agreement Must Contain Under UK GDPR](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#what-a-data-processing-agreement-must-contain-under-uk-gdpr)
- •  [How to Audit Your Supplier Chain](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#how-to-audit-your-supplier-chain)
- •  [What to Look For in a Supplier's Data Protection Posture](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#what-to-look-for-in-a-supplier-s-data-protection-posture)
- •  [International Transfers Through Suppliers](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#international-transfers-through-suppliers)
- •  [What to Do When a Supplier Won't Sign a DPA](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#what-to-do-when-a-supplier-won-t-sign-a-dpa)
- •  [Frequently Asked Questions](https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#faq)

---

## **Why Third-Party Risk Gets Underestimated**

Here's a quick exercise. Write down every supplier that touches your customers' personal data. Payroll, CRM, support desk, analytics, email platform, and that one tool someone in marketing signed up for on a free trial in 2023. Now count them. Now ask who's actually checked each one.

Most scale-ups land on a bigger number than they expected, and a much smaller number of suppliers that have been properly looked at. Growth does that. Every new tool solves a problem, and every new tool is another place your data lives.

Here's the catch. The responsibility doesn't travel with the data. If a supplier mishandles personal data you handed over, you're still answerable as the organisation that decided to share it. The government's [Cyber Security Breaches Survey 2025/2026](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026) found that 43% of businesses reported a breach in the last 12 months. Your suppliers sit inside that risk, whether or not they're on your radar.

Supplier risk is easy to ignore because it's invisible until it isn't. Nobody sends you a notification when a vendor's security slips. You find out when something goes wrong, usually at the worst possible moment.

So this guide covers what you need to do when you share personal data with suppliers, what the contract has to say, how to check on your suppliers without drowning in paperwork, and what to do when someone won't play ball.

---

## **Processors vs Controllers: Who's Responsible for What**

Ask five people in your business who's responsible when a supplier gets it wrong, and you'll probably get five different answers. The law's answer is clearer than you'd think, and it starts with two roles.

A **controller** decides why and how personal data is used. A **processor** handles personal data on the controller's behalf and on the controller's instructions. In most supplier relationships, you're the controller and your supplier is the processor.

That split is important because it decides who owes what. As the controller, you're responsible for choosing suppliers carefully and putting the right terms in place. The processor is responsible for sticking to your instructions and protecting the data while it's in their hands. UK GDPR's [Article 28](https://gdpr-info.eu/art-28-gdpr/) says controllers must only use processors that provide sufficient guarantees they'll meet the requirements of the law.

### **When your supplier isn't a processor**

Not every supplier fits neatly. Some decide for themselves why and how they use the data, which can make them a controller in their own right, or a joint controller with you. Analytics and advertising platforms are common culprits here. The label depends on what's actually happening with the data, not on what the contract calls them.

Get this wrong and the paperwork won't match reality. So it's worth working out each supplier's role before you reach for a template.

### **Sub-processors count too**

Your supplier's suppliers matter as well. If your processor brings in a sub-processor, your data goes with it. You need to know who they are, and the contract needs to deal with it.

---

## **What a Data Processing Agreement Must Contain Under UK GDPR**

"We've got a contract with them" isn't the same as "we've got a compliant data processing agreement." Plenty of supplier terms mention data protection in a line or two and call it done. Article 28 asks for a lot more.

Under [Article 28](https://gdpr-info.eu/art-28-gdpr/), the agreement has to be binding and in writing. It needs to set out the subject matter and duration of the processing, its nature and purpose, the type of personal data involved, and the categories of people the data is about. Then it has to commit the processor to a specific list of obligations.

- **Documented instructions**: the processor only handles personal data on your written instructions, including for transfers outside the UK.
- **Confidentiality**: anyone who handles the data is bound by a duty of confidence.
- **Security**: the processor puts appropriate technical and organisational measures in place.
- **Sub-processors**: they only appoint them with your authorisation, and they pass the same obligations down the chain.
- **Individual rights**: they help you respond to requests from people exercising their rights, such as subject access requests.
- **Breaches and assessments**: they help you meet your security, breach notification and impact assessment duties.
- **Deletion or return**: when the service ends, they delete or return the data, as you choose.
- **Audit**: they give you the information to show compliance, and allow audits and inspections.

That breach point deserves a closer look. Under [Article 33](https://gdpr-info.eu/art-33-gdpr/), a processor must tell the controller about a personal data breach without undue delay. You then have 72 hours from becoming aware to report it to the ICO, where it's required. If your agreement doesn't set a clear timeframe for your supplier to tell you, that clock is running on your side while you wait for an email.

A good agreement is specific, not clever. It should be short enough that somebody in your business can actually read it and know what it commits them to.

[![Trust Keith Office Hours](https://resources.trustkeith.co/hs-fs/hubfs/Blog%20Banners%20(21).png?width=2048&height=400&name=Blog%20Banners%20(21).png)](https://resources.trustkeith.co/office-hours)

---

## **How to Audit Your Supplier Chain**

An audit sounds like a big, scary thing. For suppliers, it doesn't have to be. Think of it as a sensible routine: know who you've got, know what they do with your data, and check on them in proportion to the risk.

### **Step one: build the list**

Start with a supplier register. For each supplier, note what personal data they handle, whose data it is, where it's stored, and who owns the relationship in your business. Your records of processing should already hold much of this. If they don't, that's a useful discovery in itself.

### **Step two: tier them by risk**

Not every supplier deserves the same scrutiny. Sort suppliers into tiers based on how sensitive the data is, how much of it there is, and what would happen if it went wrong.

### **Step three: check proportionately**

High-risk suppliers get a proper look: a security questionnaire, evidence such as certifications or test summaries, and a review of their sub-processors. Lower-risk suppliers might only need a signed agreement and a quick annual check. Proportionate beats exhaustive every time, because an exhaustive process is one nobody keeps up.

### **Step four: keep it moving**

A supplier review isn't a one-off event. Contracts renew, services change, and suppliers get acquired. Put review dates in the diary and keep a record of what you checked and what you decided. That record is exactly what you'll want if anyone ever asks how you manage supplier risk, whether that's a regulator, a customer or an investor running due diligence. If that last one is on your horizon, Trust Keith's guide to [preparing for privacy due diligence](https://resources.trustkeith.co/how-to-prepare-for-privacy-due-diligence-a-practical-guide-for-uk-scale-ups) shows what they'll look for.

It's also where Trust Keith's supplier management module earns its keep. A live register of suppliers, their agreements and their review dates, kept alongside the rest of your privacy programme, means the audit isn't a scramble each time someone asks.

---

## **What to Look For in a Supplier's Data Protection Posture**

A slick sales deck tells you very little. What you want is evidence that the supplier treats data protection as part of how they work, not as a box they tick before signing.

Some things worth looking for:

- **Clear answers, quickly**: a supplier that can tell you where your data's stored, who can access it and how long they keep it has probably thought about it. One that goes vague is telling you something too.
- **Security evidence**: independent certifications, penetration testing summaries, and a straight description of their access controls and encryption.
- **A sub-processor list**: ideally public, with a way to be notified when it changes.
- **A breach process**: a named route for telling you quickly when something goes wrong, and a track record of how they've handled past incidents.
- **Help with individual rights**: a practical way to get hold of data or delete it when someone asks.
- **An exit plan**: a clear answer on what happens to your data when you leave.

Pay attention to how they respond, as well as what they say. A supplier that welcomes your questions and has a ready-made data processing agreement is easier to work with than one that treats every query as an imposition. It's an early sign of how a breach conversation would go.

And here's a thing that's easy to forget. Your own people are part of this too. Teams sign up for tools without a second thought, and that's how unreviewed suppliers appear. Good [GDPR training for your team](https://resources.trustkeith.co/what-your-team-need-to-know-when-it-comes-to-gdpr-training) means more of them know to ask "who's the supplier and have we checked?" before they hit the sign-up button.

[![Trust Keith Resources](https://resources.trustkeith.co/hs-fs/hubfs/Blog%20Banners%20(12).png?width=3584&height=700&name=Blog%20Banners%20(12).png)](https://www.trustkeith.co/resources)

---

## **International Transfers Through Suppliers**

Here's one that catches people out. You've chosen a UK supplier, so your data stays in the UK. Except it often doesn't, because that supplier uses a cloud host, a support team or a sub-processor somewhere else.

When personal data leaves the UK, UK GDPR's rules on restricted transfers apply. In plain terms, you need a lawful mechanism for sending it: an adequacy decision covering the destination, or appropriate safeguards such as the ICO's International Data Transfer Agreement or the UK Addendum to the EU's standard contractual clauses. For the latter, you'll usually also need to assess the risk of the transfer. The ICO's [UK GDPR guidance and resources](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/) sets out how these mechanisms work.

The practical job is to find out where the data goes. For each supplier, ask:

- Where's the data stored and processed?
- Can anyone outside the UK access it, for example for support?
- Which sub-processors are involved, and where are they based?
- Which transfer mechanism covers each route?

This is another reason the agreement matters. Article 28 requires the processor to act only on your documented instructions, including on transfers, so your contract should say plainly where data can and can't go.

---

## **What to Do When a Supplier Won't Sign a DPA**

It happens. Particularly with large vendors who send out one set of terms to everyone and don't expect pushback. So what do you do when they won't budge?

First, check what you've actually been offered. Many big suppliers already include a data processing addendum in their standard terms, often buried in a link at the bottom of a page. It's worth reading before you assume nothing exists.

If their standard terms do cover the Article 28 requirements, you may not need to negotiate anything. If they don't, ask for the gaps to be fixed. Be specific about what's missing, whether that's sub-processor controls, breach notification timing or audit rights.

If they still refuse, you've got a decision to make, and it's a business one. Options include:

- **Escalate**: ask who in the supplier's business handles privacy terms. It's often a different person from your account manager.
- **Limit the data**: use the service in a way that doesn't involve personal data, or share much less of it.
- **Switch**: look at alternatives that will sign.
- **Record the risk**: if you decide to carry on, document why, who approved it, and what you're doing to reduce the exposure.

What you can't do is carry on without a compliant agreement and hope nobody asks. If a regulator ever does, you'll want to point to a decision you made deliberately, not a gap you never noticed. The same goes for the wider cost of getting this wrong, which goes well past fines, as covered in [the hidden costs of getting data protection wrong](https://resources.trustkeith.co/the-hidden-costs-of-getting-data-protection-wrong-trust-keith).

---

## **Frequently Asked Questions**

### **Do I need a data processing agreement with every supplier?**

You need one with every supplier that processes personal data on your behalf. That's the core requirement of [Article 28](https://gdpr-info.eu/art-28-gdpr/). If a supplier never touches personal data, you don't need one. If it's a controller in its own right, you'll need a different kind of arrangement, such as a data sharing agreement.

### **Who's responsible if a supplier has a data breach?**

Both of you can be. The processor has its own legal duties, including telling you about a breach without undue delay. But you're still the controller, so you're responsible for choosing suppliers carefully, having the right contract in place and reporting to the ICO where required.

### **How often should I review my suppliers?**

It depends on the risk. Suppliers handling sensitive or large volumes of data should be reviewed at least annually, and whenever something changes, such as a new sub-processor, a new service or a security incident. Lower-risk suppliers can be checked less often.

### **Can I use my supplier's standard data processing agreement?**

Yes, as long as it covers everything Article 28 requires. Check it against the list rather than assuming it does. Where it falls short, ask for amendments or an addendum.

### **What's the difference between a processor and a sub-processor?**

A processor handles personal data on your behalf. A sub-processor is a third party your processor brings in to help deliver the service. You need to authorise sub-processors, and your processor stays responsible for them.

---

Supplier management isn't the glamorous end of data protection. But it's where a lot of risk lives, and it's one of the more fixable parts. Know who you've got, get the agreements right, and check in proportion to the risk. That's most of it.

And if any of this still feels uncertain, or you'd like to talk it through with someone who's handled it before, you're welcome to book some time with our team. We're happy to see how we can help. Trust Keith's supplier management tools and dedicated privacy experts are there to take the admin off your plate, with no pressure attached.

[![chat to an expert](https://resources.trustkeith.co/hs-fs/hubfs/chat%20to%20an%20expert.png?width=228&height=57&name=chat%20to%20an%20expert.png)](https://www.trustkeith.co/talk-to-us)

[![Trust Keith - take data protection off your plate, for good](https://resources.trustkeith.co/hs-fs/hubfs/blog%20cta%20(5).png?width=3450&height=1150&name=blog%20cta%20(5).png)](https://www.trustkeith.co/)

 

## Curious how Trust Keith can help take data compliance off your plate?

[![Talk to an expert](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/24879685/859c2149-73c5-4ae5-a465-6c639d24614f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/24879685/859c2149-73c5-4ae5-a465-6c639d24614f)

[![Trust Keith](https://resources.trustkeith.co/hs-fs/hubfs/raw_assets/public/Trustkeith_March2023/images/trust_keith01.png?width=268&name=trust_keith01.png "Trust Keith")](https://www.trustkeith.co/)

[![Talk to an expert](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/24879685/859c2149-73c5-4ae5-a465-6c639d24614f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/24879685/859c2149-73c5-4ae5-a465-6c639d24614f)

- Features 
    - [Comply with data regulations](https://www.trustkeith.co/product/comply-with-regulations)
    - [Discover your data risks](https://www.trustkeith.co/product/discover-data-risks)
    - [Expert Advice](https://www.trustkeith.co/product/expert-advice)
    - [Govern your data protection programme](https://www.trustkeith.co/product/govern-data-protection)
    - [Manage breaches and incidents](https://www.trustkeith.co/product/manage-breaches-and-incidents)
    - [Train your staff](https://www.trustkeith.co/product/train-your-staff)
- Product 
    - [How it works](https://www.trustkeith.co/how-it-works)
    - [Marketplace](https://www.trustkeith.co/marketplace)
    - [Pricing](https://www.trustkeith.co/pricing)
    - [Customers](https://www.trustkeith.co/customers)
- Trust Keith 
    - [Company](https://www.trustkeith.co/company)
    - [Talk to us](https://www.trustkeith.co/talk-to-us)
    - [LinkedIn](https://www.linkedin.com/company/trustkeith/)
    - [Privacy policy](https://trustkeith.trustkeith.co/)

© Trust Keith 2026. Trust Keith Ltd is a company registered in England and Wales number 12283797.

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide#blogposting",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Trust Keith"
  },
  "dateModified" : "2026-10-06T16:05:53+0000",
  "datePublished" : "2026-10-06T16:05:53+0000",
  "description" : "Sharing personal data with suppliers? See what UK GDPR Article 28 requires, what a data processing agreement must contain and how to audit your suppliers.",
  "headline" : "Third-Party Risk and Data Protection: Managing Your Supplier Chain",
  "inLanguage" : "en-GB",
  "isPartOf" : {
    "@id" : "https://resources.trustkeith.co/#blog",
    "@type" : "Blog",
    "name" : "Trust Keith Resources Blog",
    "publisher" : {
      "@id" : "https://www.trustkeith.co/#organization"
    }
  },
  "mainEntityOfPage" : {
    "@id" : "https://resources.trustkeith.co/supplier-gdpr-compliance-dpa-requirements-audit-guide",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@id" : "https://www.trustkeith.co/#organization",
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn.prod.website-files.com/5f462e8160aa877216f7d4b7/642bcbad7735490755580d8d_trust-keith-logo.svg"
    },
    "name" : "Trust Keith",
    "url" : "https://www.trustkeith.co/"
  }
}
```