Compliance & Data ProtectionSuppliers & Third Parties
Vendor Management Policy
Selection, risk assessment, and monitoring of vendors and sub-processors
SSM.ro uses a limited number of trusted vendors for infrastructure and services. This policy governs their selection, risk assessment, and monitoring.
Selection and due diligence
The following are evaluated when selecting a vendor:
- Security — certifications (ISO 27001, SOC 2), encryption practices, isolation
- Compliance — the ability to comply with GDPR (data processing clauses)
- Reliability — availability, SLA, reputation
- Data location — the storage region and transfer implications
Vendor risk assessment
The risk of a third party / sub-processor being compromised is tracked in the Risk Register (risk #10), with controls:
- TLS in transit for all vendors; mTLS or API token for the electronic signature provider
- Limited credentials per vendor, with minimal privileges
- Data minimization for data transmitted to each vendor
Contractual agreements
- Data Processing Agreements (DPA / GDPR clauses) with vendors that process personal data
- Confidentiality clauses for all collaborators and providers
- Standard Contractual Clauses (SCC) for transfers outside the EEA
Continuous monitoring
- Periodic review of critical vendors and their security status
- Monitoring of service status (Heroku, AWS) for availability
- Updated list of sub-processors: Sub-processors