Procurement Policy Support
GDPR Obligations and Liability for Service Providers
Under Art. 28 GDPR, private and public entities are liable and accountable for the GDPR breaches made by their data processors, except if the latter are GDPR-certified:
In consequence, it is their responsibility to monitor and prove that their processors are fully GDPR compliant. Fortunately, the same article also recognises that an approved GDPR certification can be used to demonstrate sufficient guarantees.
Impact of Processor Certification on the Data Controller
| Service provider: | If uncertified | If GDPR certified |
|---|---|---|
| Liability & legal risks | Full | Reduced |
| Compliance monitoring workload | Full | Reduced |
| Due diligence costs | Full | Reduced |
| Financial risks under Art. 83 GDPR | Full | Reduced |
Procurement Policy Strategy
While you can use certification to demonstrate your own GDPR compliance, requesting your service providers to be GDPR-certified is a no brainer. It substantially reduces your risks, costs and workload. The recommended strategy consists in:
- Contact your procurement team to inform them on the opportunity to reduce risks, costs, and workload for your organization.
- Update the procurement policy by integrating GDPR-certification as a new factor in the selection process of service providers that are receiving any personal data. You can include it as a weighted factor for a transition period of 24 months, followed by a mandatory requirement after this period.
- Inform your service provider about your new policy and invite them to request a GDPR certification.
Support Programme for Procurement Policy Optimization
ECCP provides free online resources to all organizations that are updating their procurement policies. In addition, a special support programme is available to companies with a large number of data processors. Any company that has a procurement programme with more than 20 data processors and a procurement budget of over 10 Million Euros can apply to our Support Programme for Procurement Policy Optimization. Selected applicants receive personalized live support for optimizing their procurement policy, as well as a Welcome Pack for free. Apply to the Support Programme.
Template Clauses
DPO Message to the procurement team
"Dear procurement team,
Under the GDPR, our organization is exposed to major and unnecessary risks, costs, and workload when using service providers that are not GDPR-certified. We invite you to update the selection criteria applied to our service providers by including the GDPR certification as a key requirement. We suggest to apply a transition phase of 24 months during which it will be a weighted criterion, before turning it into a mandatory requirement. This adaptation will contribute to reduce the risks, compliance monitoring costs, and workload for our organization.
We remain available to further explain and discuss this topic.
Sincerely,
The DPO Team"
Standard Procurement Clause
"To minimize the risks of GDPR non-compliance, service providers who are processing personal data shared by us are encouraged to demonstrate the full GDPR-compliance of their service offering by means of a GDPR certification. Such certification will be recognized as a strong advantage and competitive advantage in the selection process. By [add a date in 24 months or more], GDPR-certification is expected to become a mandatory requirement."
Message to Service Providers
"Dear Service Provider and Data Processor,
Our organization takes personal data protection and its GDPR obligations at heart and very seriously. We would like to inform you that we have decided to update our procurement policy.
Under Art. 28 GDPR, data controllers are exposed to risks and liability in case of non-compliance by their data processors. In order to mitigate our risks, we encourage our service providers to demonstrate full GDPR-compliance of their service offering by means of a GDPR certification. Such certification will be recognized as a strong competitive advantage in the selection process of our service providers and data processors.
At a later stage, in 24 months, GDPR-certification is expected to become a mandatory requirement for our procurement policy.
While such GDPR certification is likely to require some effort from our partners, we are confident that it will also constitute a strong competitive advantage for them towards other B2B partners and clients, and may enable them to gain new market shares.
You will find more information on GDPR certification online, for instance at gdprcertification.com and europrivacy.com.
Sincerely,
The Procurement Team"