PDPA Supplier and Processor Due Diligence Checklist
A practical checklist for procurement, legal, security, IT, and business teams that rely on third parties to process or access personal data.
Third parties extend your risk perimeter
A supplier can improve efficiency and capability, but it may also introduce privacy, security, resilience, and contractual risk. The goal of due diligence is not to create unnecessary paperwork. It is to understand the processing, apply proportionate controls, document decisions, and manage material risk throughout the relationship.
CHECK 1
Know the service
Document what the supplier provides, which business process it supports, what personal data is involved, and whether the supplier can access, host, analyse, or transfer that data.
CHECK 2
Assess data and risk
Identify sensitive, high-volume, business-critical, or cross-border processing. Risk should drive the depth of due diligence and approval.
CHECK 3
Review security controls
Assess identity and access management, encryption, backup, logging, vulnerability management, incident response, secure development, and independent assurance where relevant.
CHECK 4
Review privacy practices
Understand processing instructions, confidentiality, purpose limitations, retention, deletion, individual-rights support, sub-processors, and contact routes.
CHECK 5
Check hosting and transfers
Document hosting locations, support locations, international transfers, cloud regions, and onward transfer arrangements where known.
CHECK 6
Strengthen contract terms
Use appropriate clauses on processing instructions, confidentiality, safeguards, subcontracting, incident notification, assistance, audit or assurance, return or deletion, and termination.
CHECK 7
Monitor over time
Do not treat due diligence as a one-time task. Reassess critical suppliers after major changes, incidents, renewals, control failures, or service expansion.
A proportionate approach
A low-risk supplier should not require the same level of assessment as a provider that hosts sensitive, high-volume, business-critical, or cross-border personal data. Use risk tiering to focus time and management attention where it matters most.
Supplier readiness
Make third-party risk visible.
Use the readiness assessment to identify priority gaps in vendor governance, contract controls, data visibility, and security assurance.
Start free assessment →