Privacy review checklist
What to review when a vendor privacy policy changes
A vendor privacy-policy change may be routine, or it may reveal a new data use, recipient, location, retention practice, or product feature. A consistent review framework helps teams focus on what changed and what internal records or commitments may need attention.
Start with the actual relationship
Identify which product or service uses the vendor, what information is involved, where the service is used, and whether the vendor acts as a processor, controller, service provider, contractor, or another role under applicable arrangements. The same policy change can have very different consequences depending on the data flow.
Retrieve the governing contract, data-processing addendum, security review, privacy impact assessment, vendor questionnaire, and internal notice or record that relied on the earlier disclosures.
Review the dimensions most likely to matter
Compare the prior and current policy and identify additions, removals, and meaningful rewrites. Avoid assuming that a new heading is substantive or that unchanged wording means the vendor’s practices are unchanged.
- Categories and sources of personal information
- Purposes of collection, use, and processing
- Advertising, analytics, profiling, and AI-related use
- Recipients, subprocessors, affiliates, and sale or sharing language
- International transfers and processing locations
- Retention periods or criteria
- Security representations and incident contacts
- Individual rights, appeals, and request methods
Reconcile the policy with contractual promises
Public privacy policies do not replace the negotiated contract or DPA. Check whether the change is consistent with processing instructions, confidentiality, subprocessor notice, data-location, retention, deletion, security, and assistance obligations.
If the public policy and contract appear inconsistent, preserve both records and obtain a qualified review before concluding which language controls or what remedy is available.
Close the operational loop
Possible responses include asking the vendor for clarification, updating a vendor assessment, changing product settings, revising a privacy notice or data map, notifying internal stakeholders, objecting to a subprocessor, or escalating legal review. Record why the organization selected the response and who owns any follow-up.