Procurement skips security due diligence on a personal-data vendor because the vendor’s slide deck shows an ISO certification logo. What does responsible vendor management under GDPR security expectations require?
Select an answer to reveal the explanation.
Short Explanation
A logo on a slide is not a force field. You still need proportionate checks—contracts, access, and follow-up—matched to how risky the processing is. Certification can help; it cannot replace responsible vendor management.
Full Explanation
Controllers remain responsible for ensuring processors provide sufficient guarantees of appropriate technical and organisational measures (Article 28 and Article 32 themes). Certifications may evidence aspects of a security programme but do not eliminate the need for risk-proportionate due diligence, contractual controls, and ongoing oversight. Treating an ISO mark as automatic, permanent compliance theatre undercuts effective vendor management.