← All resources

Privacy review checklist

What to review when a vendor privacy policy changes

A vendor privacy-policy change may be routine, or it may reveal a new data use, recipient, location, retention practice, or product feature. A consistent review framework helps teams focus on what changed and what internal records or commitments may need attention.

By Brig Ricks, business attorney and founderPublished August 19, 20267-minute read

Start with the actual relationship

Identify which product or service uses the vendor, what information is involved, where the service is used, and whether the vendor acts as a processor, controller, service provider, contractor, or another role under applicable arrangements. The same policy change can have very different consequences depending on the data flow.

Retrieve the governing contract, data-processing addendum, security review, privacy impact assessment, vendor questionnaire, and internal notice or record that relied on the earlier disclosures.

Review the dimensions most likely to matter

Compare the prior and current policy and identify additions, removals, and meaningful rewrites. Avoid assuming that a new heading is substantive or that unchanged wording means the vendor’s practices are unchanged.

  • Categories and sources of personal information
  • Purposes of collection, use, and processing
  • Advertising, analytics, profiling, and AI-related use
  • Recipients, subprocessors, affiliates, and sale or sharing language
  • International transfers and processing locations
  • Retention periods or criteria
  • Security representations and incident contacts
  • Individual rights, appeals, and request methods

Reconcile the policy with contractual promises

Public privacy policies do not replace the negotiated contract or DPA. Check whether the change is consistent with processing instructions, confidentiality, subprocessor notice, data-location, retention, deletion, security, and assistance obligations.

If the public policy and contract appear inconsistent, preserve both records and obtain a qualified review before concluding which language controls or what remedy is available.

Close the operational loop

Possible responses include asking the vendor for clarification, updating a vendor assessment, changing product settings, revising a privacy notice or data map, notifying internal stakeholders, objecting to a subprocessor, or escalating legal review. Record why the organization selected the response and who owns any follow-up.

Related SaaS Tracker workflowExplore privacy policy monitoring
Continue building the process

Trial terms: No payment method required. Your 30-day Essentials trial starts when your organization workspace is successfully created. No charge and no automatic conversion. At or before expiry, an authorized organization representative may choose any available paid plan and complete checkout; paid access begins only after verified payment. Otherwise, active service stops and the workspace becomes read-only under the Terms and Data Export and Deletion Procedure. One trial per eligible new organization.