Under Article 28 GDPR, controllers must use processors that provide sufficient guarantees that appropriate technical and organisational measures will be implemented in a manner that meets GDPR requirements and protects data subjects’ rights.

Procurement teams can support this obligation by including certification under a scheme approved pursuant to Article 42 GDPR in supplier requirements and tender documentation.

In practice, organisations can:

  • Request information on the GDPR certification of the proposed service
  • Make certification a mandatory requirement
  • Award additional points to certified services during supplier evaluation
  • Ask existing processors to complete certification within a defined timeframe

These requirements can be applied both when selecting new suppliers and when reviewing existing service agreements.

This helps ensure that data protection considerations remain part of procurement decisions throughout the supplier relationship, rather than being addressed only after a contract has been signed.

This can create a clearer and more consistent approach to supplier assessment, while helping reduce risks, monitoring efforts, and associated costs.

Turn GDPR Certification into a Practical Procurement Requirement

Explore Europrivacy’s procurement support page for practical recommendations on requesting GDPR certification and including it in procurement policies and tender documentation: https://europrivacy.com/en/procurement-support

error: Content is protected !!
Europrivacy Community
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and enabling your purchases and subscriptions. No user monitoring or analytics are performed.