GDPR and vendors
GDPR and B2B vendor onboarding: what you actually need to be able to prove.
Not another generic "how to comply with GDPR" guide. What you actually need when a supplier sends you documents with personal data inside them — and the difference between "we have a policy" and "we can prove it".
What GDPR actually requires when verifying a supplier
Supplier onboarding almost always involves processing personal data, even when the company itself isn't the point — an insurance policy carries the broker's name, a registration document carries a representative's details, a contact form carries the name and phone number of the person you're dealing with. GDPR doesn't ask whether you collected this data on purpose — it asks whether you have a legal basis to process it, whether you know how long you're keeping it, and whether you can answer who had access to it.
In practice, for vendor onboarding that means three concrete obligations: a legal basis (usually Article 6(1)(b) or (f) — contract performance, or a legitimate interest in verifying a counterparty), a clear boundary on who inside the company sees which data, and the ability to reconstruct the history — who approved the supplier, based on which documents, and when.
That last one is what most often goes missing. A privacy policy on your website is one side of the coin. The other is the question an auditor or a regulator actually asks: "show me what the approval process for this specific supplier looked like, six months ago."
Where this typically breaks down
A familiar pattern: the supplier e-mails documents, somebody reviews them, the approval happens in a Teams call or an e-mail thread, and the decision lands in a spreadsheet as a single cell reading "approved". Six months later nobody remembers exactly who approved it, on the basis of which version of the document, or whether anyone checked the insurance policy's expiry date at all.
This isn't a hypothetical risk. It's exactly the moment a procurement audit or a GDPR check stops being a formality and becomes a problem — not because the company did something wrong, but because it can't prove it didn't. To an auditor, no evidence looks identical to no process, even when the process genuinely existed in someone's head.
How an immutable audit trail changes what you can prove
This is where VendoCerta differs from a spreadsheet and an inbox in a way that carries legal weight, not just organisational tidiness: every recorded action — a change to a supplier's status, a document decision, an approval, an invitation sent, a file downloaded — becomes an audit trail entry. There is no edit or delete function anywhere in the interface, in any role, including the company owner. The system never overwrites an existing event.
In practice, that means the question "show me what the approval process for this supplier looked like" has an answer in the form of a specific record: who, what, when — and for a data change, also what the values looked like before and after. Even unauthorised access attempts are recorded as their own event, so repeated attempts are visible, not silent.
History filters land in the page address, so a specific slice — say, the full history of one supplier or one onboarding case — can be handed to an auditor as a plain link, with nothing to explain about where to look.
Role separation as a real GDPR control, not just convenience
GDPR states the minimisation principle directly — personal data should only be seen by people who genuinely need it to do their job. VendoCerta enforces this structurally rather than on goodwill: documents marked as sensitive (mostly payment-related) require a separate permission that, in practice, only the owner and the business administrator hold. The system administrator — the role responsible for configuration, diagnostics and backups — has no visibility into suppliers, documents or bank accounts at all. That separation is designed in, not optionally configured.
Two-factor authentication is mandatory for roles with access to business data and cannot be skipped — another thing you need to be able to demonstrate when asked about technical and organisational measures under Article 32, not just declare in a policy document.
What this doesn't solve — honestly
VendoCerta is a record and a control mechanism, not legal advice. It will not decide for you whether a given category of data needs a Data Protection Impact Assessment, it will not fill in your Record of Processing Activities for you, and it will not replace a conversation with a lawyer when signing a data processing agreement with a supplier who processes data on your behalf.
What it gives you: the point at which those decisions actually become documentable — who decided, when, on what basis — instead of reconstructed from memory six months later.