Privacy Agreement Review
Checks data processing agreements and vendor privacy terms against the standard positions and records the answer.
Tools
OneTrust, TrustArc, FairNow, Icertis
Outcomes
Every agreement reviewed against standard terms • Subprocessor changes recorded with a date • Records of processing updated at signature • Transfer gaps closed before go-live
Documentation
Instruction-ready detail below
What breaks: data processing agreements reach the company through procurement and get signed as part of a vendor bundle. Nobody confirms that the subprocessor list, the transfer mechanism, or the deletion promise matches what privacy agreed to, and the review is never written down. Six months later the records of processing cannot explain what we promised a vendor, because nobody recorded the answer. What the workflow does: it reads the signed agreement and lists the subprocessor list, the transfer basis, the breach notice window, the deletion terms, and any audit right, then compares each to the standard positions. Differences come back as a short list with the clause and a suggested wording. The approved answer is written into the records of processing with a date, and each new subprocessor raises a change record that privacy has to acknowledge. What a person still approves: privacy approves the transfer basis and the subprocessor change, and legal approves any clause that departs from the standard wording.