Corpenza
Get Started
Independent Audit and Compliance8 min

Data Protection for International Companies: Controller, Processor and Vendor Checks

A practical GDPR role, processor agreement and vendor-check framework for international companies.

Berk Tüzel
Berk Tüzel
July 30, 2026
data-protectiongdprvendor-checks
Data Protection for International Companies: Controller, Processor and Vendor Checks

International companies need a data-protection operating model before adding a new SaaS vendor, payroll provider or group service centre. The core question is factual: who decides why and how personal data is processed, and who processes it only on documented instructions?

What is the controller–processor distinction?

Under the GDPR, a controller determines purposes and means of processing; a processor acts on behalf of the controller. Labels in a contract do not decide the role. Map the actual data flow, the business purpose and who can make decisions about the processing.

Read the official EDPB controller and processor guidance alongside GDPR Article 28. The guidance is a framework; the facts of a specific arrangement still matter.

What should an international vendor check cover?

Record the data categories, data subjects, processing purpose, locations, sub-processors, access controls, retention, incident route and exit plan. Verify whether the vendor will make its own decisions or follow your written instructions. Keep the answers with the procurement record, not only in email.

What belongs in a processor agreement?

A compliant processor contract needs more than the words “GDPR compliant”. It should describe subject matter and duration, nature and purpose, types of personal data, categories of data subjects, documented instructions, confidentiality, security, sub-processor controls, assistance, deletion or return, and audit information as required by Article 28.

How should group companies be assessed?

Do not assume that a group company is automatically a processor. A shared service centre may be a processor for one activity and a controller or joint controller for another. Give each processing activity its own role analysis and document the cross-border data transfer route where relevant.

Which controls make the vendor review usable?

Assign an owner, set a renewal date, require approval before a new sub-processor or purpose, and test the incident contact path. Link security evidence to the processing record. A vendor check becomes operational only when procurement, legal, information security and the business owner use the same evidence set.

FAQ

Is a cloud vendor always a processor?

Often, but not automatically. The role follows the actual processing and decisions, not the product category.

Can a contract call both parties processors?

A contract may use a label, but the GDPR role must reflect the facts. Where roles differ by activity, the contract and records should say so.

Does this checklist replace legal advice?

No. It is a practical control list. Contact Corpenza for implementation support and obtain qualified advice for your specific processing and transfer arrangements.

For a foundation, see our GDPR basics for small companies.

Start Your Global Growth Today

Let's reach your business goals together with 50+ expert consultants and partner networks in 9+ countries. First consultation is free.

Get Started