A vendor-management playbook relies only on a security schedule and skips data-processing agreements because 'security covers GDPR.' What correction is needed?
Select an answer to reveal the explanation.
Short Explanation
A security appendix is great armor, but it isn't the whole GDPR contract kit. You still need proper processor terms—roles, instructions, sub-processors, assistance duties—not just a lock icon on a schedule. Security and processing clauses work as a pair.
Full Explanation
Article 28 requires a binding contract (or other legal act) setting out processing subject-matter, duration, nature, purpose, data types, obligations, and security among other elements. A standalone security schedule may support TOMs but typically does not replace the full processor contractual discipline controllers must maintain.