Monitoring of Data Processors

- Companies must regularly audit their data processors to ensure data protection compliance.
- The controller remains responsible for data protection, even when data processing is outsourced.
- Before commissioning: Review the data processor's technical and organizational measures.
- Regular audits: Certificates, questionnaires, and on-site inspections by qualified experts.
- Extend audits to include any sub-processors used and document the findings.
Many companies rely on one or even several data processors in their day-to-day operations. Companies that use data processors should monitor them regularly to ensure that an adequate level of data protection is maintained. This is because, as the controller, a company remains responsible for data processing even when it is outsourced to a service provider. We outline the key points to consider when auditing data processors.
Using Data Processors
Almost every company uses data processors to carry out the processing of personal data on its behalf. This includes, for example, hosting providers, SaaS providers (e.g., for CRM or HR systems), document shredding services, or marketing agencies. In these cases, a data processing agreement must be concluded that meets the requirements of Art. 28 GDPR. As the "controller," the company remains responsible for the data processing and the adequate protection of personal data, even when outsourcing processing to a data processor.
For this reason, the controller's right to audit is a mandatory component of a data processing agreement. Before auditing a data processor, it is usually worth checking the signed data processing agreement, as it may contain specific details regarding how audits should be conducted.
Initial Assessment Before Engagement
The controller is responsible for ensuring that the data processor is "suitable." In concrete terms, this means that the processor implements appropriate technical and organizational measures to meet GDPR requirements and ensure the protection of the rights of the data subjects. Therefore, it is important to assess the data processor's suitability before engaging them. In addition to reviewing the data processing agreement to be signed, this includes, in particular, an assessment of the technical and organizational measures the processor has implemented for data protection. Aspects such as whether the processor has experience with the tasks to be outsourced or whether there have been any previous data breaches or other incidents involving the processor should also be taken into account.
The controller's data protection officer should be involved in this assessment where appropriate. The results should be documented, and the data processor should only be engaged if their suitability has been confirmed.
How can data processor audits be conducted?
After the initial assessment of a data processor, they should be audited on a regular basis. Audits of data processors can be carried out in various ways:
- by having the data processor provide evidence of compliance with data protection requirements (e.g., certificates, reports from an independent auditor, current security concept),
- by having the data processor complete a questionnaire provided by the controller (this may include questions about internal data protection organization, technical and organizational measures related to the outsourced processing, or sub-processors),
- by conducting an on-site inspection of the premises or data processing facilities.
Audits should be carried out by a knowledgeable and independent party, such as the controller's data protection officer. Audits and their results should always be documented, and the data processor should be requested to make improvements if necessary. If it is determined that the data processor cannot meet the data protection requirements, the controller should refrain from further engagement.
Controllers should define a clear process for auditing their data processors, which also ensures the regularity of these audits (e.g., once a year).
Monitoring Sub-processors
Contractors frequently engage further sub-processors, which can quickly make data flows difficult for the controller to track. To prevent this, you should not only carefully check which sub-processors are being used and what data protection agreements are in place with them at the start of the engagement, but also as part of your regular audits. The data processor must ask the controller for approval in advance before engaging a new sub-processor or changing an existing one, or at least provide an opportunity to object—depending on the terms of the data processing agreement. Whether this is being done reliably should be verified during an audit.
Don't neglect your audits
It is not uncommon for a data protection breach by a data processor to reflect back on the controller, forcing the controller to justify their choice of processor during regulatory investigations, for example. In such cases, it is often helpful to be able to provide evidence of the initial vetting of the processor as well as subsequent regular audits. Regular reviews also help to identify potential vulnerabilities at the processor in good time, allowing for corrective measures to be taken. For these reasons alone, controllers should not neglect the oversight of their processors; they should establish appropriate processes and ensure the necessary resources and expertise are in place.
Working with data processors is rarely avoidable and generally offers many advantages. However, to ensure the benefits outweigh the risks, companies should not take the oversight of their processors lightly. We would be happy to advise you on any questions you may have regarding this topic.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.












