GDPR, answered.
The 3 questions from GDPR we have written up so far. Each one covers what it is really asking, which of your documents answers it, what to attach alongside, and the specific ways it gets answered badly.
Do you use sub-processors, and can you provide a current list?
Confirmed in your documentsThe list is easy. What reviewers actually check is whether the unglamorous ones are on it: the error tracker, the support desk, the AI provider.
Third-party risk · Art. 28(2)
Where is customer data hosted, and can it be kept in a specific region?
Reused from your libraryThe database is the easy half. A reviewer at an EU company is asking about every sub-processor and about who can read a record from where.
Data governance · Ch. V
Will you notify us before adding or changing a sub-processor?
Confirmed in your documents"We will notify you" and "we will notify you thirty days before" are different commitments, and this question is asking for the second.
Third-party risk · Art. 28(2)
Answer the whole GDPR at once.
Upload the file you were sent. FillTrust drafts each answer from your own documents and shows the passage it came from.