← Back to insights
THIRD PARTIES

PDPA Supplier and Processor Due Diligence Checklist

A practical checklist for procurement, legal, security, IT, and business teams that rely on third parties to process or access personal data.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Contract and compliance requirements should be reviewed against current official requirements and the organisation’s risk profile.

Third parties extend your risk perimeter

A supplier can improve efficiency and capability, but it may also introduce privacy, security, resilience, and contractual risk. The goal of due diligence is not to create unnecessary paperwork. It is to understand the processing, apply proportionate controls, document decisions, and manage material risk throughout the relationship.

CHECK 1

Know the service

Document what the supplier provides, which business process it supports, what personal data is involved, and whether the supplier can access, host, analyse, or transfer that data.

CHECK 2

Assess data and risk

Identify sensitive, high-volume, business-critical, or cross-border processing. Risk should drive the depth of due diligence and approval.

CHECK 3

Review security controls

Assess identity and access management, encryption, backup, logging, vulnerability management, incident response, secure development, and independent assurance where relevant.

CHECK 4

Review privacy practices

Understand processing instructions, confidentiality, purpose limitations, retention, deletion, individual-rights support, sub-processors, and contact routes.

CHECK 5

Check hosting and transfers

Document hosting locations, support locations, international transfers, cloud regions, and onward transfer arrangements where known.

CHECK 6

Strengthen contract terms

Use appropriate clauses on processing instructions, confidentiality, safeguards, subcontracting, incident notification, assistance, audit or assurance, return or deletion, and termination.

CHECK 7

Monitor over time

Do not treat due diligence as a one-time task. Reassess critical suppliers after major changes, incidents, renewals, control failures, or service expansion.

A proportionate approach

A low-risk supplier should not require the same level of assessment as a provider that hosts sensitive, high-volume, business-critical, or cross-border personal data. Use risk tiering to focus time and management attention where it matters most.

Supplier readiness

Make third-party risk visible.

Use the readiness assessment to identify priority gaps in vendor governance, contract controls, data visibility, and security assurance.

Start free assessment →