Contract & Legal Requirements
- Right to audit or receive independent third-party assurance artifacts is included
- Data processing agreement (DPA) is signed and aligns with GDPR Article 28 requirements
- Service level agreements (SLAs) for security controls are clearly defined
- Termination and data return procedures are documented with specific timelines
- Liability and indemnification terms cover data breach scenarios
Escalation Criteria & Required Actions
If any of these criteria are met, follow the escalation action before approval
| Criteria | Required Action |
|---|
| Vendor cannot provide data flow diagram | Defer procurement until available |
| Data stored outside approved regions | Escalate to Legal/Compliance |
| No SOC 2 or ISO 27001 within last 12 months | Request compensating controls or defer |
| Breach notification window > 72 hours | Negotiate contractual amendment |
| Customer data used for AI training by default | Require opt-out confirmation in contract |
| Subprocessors undisclosed or undefined | Reject until disclosure provided |