A vendor-management programme signs data processing agreements then never reviews security posture, access rights, or DPA performance afterward. What does responsible GDPR-aligned vendor oversight require?
Select an answer to reveal the explanation.
Short Explanation
Signing the DPA is the wedding, not the marriage. You still need to check that the vendor keeps protecting personal data over time. One signature on day one is not lifelong autopilot.
Full Explanation
Controllers must use only processors that provide sufficient guarantees and must ensure processing meets GDPR requirements on an ongoing basis, including through contractual terms and oversight practices contemplated by Article 28. Continuous monitoring—access reviews, security assurance, and DPA performance—supports those guarantees. Treating signature day as the end of vendor management leaves residual risk unmanaged.