Certus
← All services

Vendor Privacy Reviews

Structured due diligence on the third parties who process your data on your behalf — before and during the relationship.

What it is

A due diligence and ongoing oversight framework for assessing vendors, cloud providers and processors against PDPL's controller-processor obligations, cross-border transfer requirements, and your own risk appetite.

Why it matters

Under PDPL, accountability for personal data does not transfer when you hand it to a vendor. A weak data processing agreement or an unassessed sub-processor is one of the most common sources of real regulatory exposure — and one of the least visible until something goes wrong.

What Certus does
  • Build a risk-tiered vendor assessment model calibrated to data sensitivity and processing volume.
  • Review and strengthen data processing agreements and cross-border transfer clauses.
  • Assess sub-processor chains and cloud data residency against PDPL requirements.
  • Establish an ongoing review cadence tied to contract renewal and risk tier.
What you receive
  • A vendor privacy risk assessment model and scoring criteria
  • Reviewed and strengthened data processing agreement templates
  • A prioritised list of vendor remediation actions
  • An ongoing vendor review cadence integrated into procurement
Typical timeline

3–6 weeks for an initial portfolio review; ongoing reviews scoped per vendor tier.

Who this is for

Procurement, Legal, CISOs and Business Owners responsible for vendors and cloud services handling personal data.

How this differs from a generic consultancy

We assess vendors the way a regulator would — not by ticking off whether a data processing agreement exists, but whether it actually holds up.