/ THE SHORT ANSWER
- 01Assess distinct processing activities rather than accepting one broad vendor label.
- 02Ask how deletion reaches indexes, logs and backups.
- 03Make unresolved contractual and technical questions visible in the buying decision.
/ dotSuper point of view
dotSuper analysis: procurement should turn privacy assurances into testable commitments tied to a defined use.
Define what you intend to send
[1] That is a useful purchasing discipline.
Before asking whether a supplier is suitable, specify what the company wants the service to do and why personal data is involved.
Prepare a representative fictional example.
Include document type, expected users, output and the intended recipient.
A customer service summary and an employee case summary may use similar technology, but their purposes and affected people differ.
List information that should never enter this use.
That boundary helps the vendor explain configuration options and helps employees understand the eventual workflow.
If the supplier's answer depends on a different plan, region or optional feature, record the exact configuration behind the claim before comparing prices.
Map processing roles to actual activities
[2] Whether that relationship describes every activity in the proposed service needs examination; do not assume the contract title answers it.
Ask the vendor to explain inference, service telemetry, abuse monitoring, support and model improvement separately.
Record the purpose of each activity and the supplier's claimed role.
A simple no training statement may leave other processing unexplained.
Bring this map to the responsible data protection and legal specialists.
They can assess the relevant basis and obligations using actual information.
Procurement's contribution is to make ambiguous answers visible, obtain supporting terms and avoid bundling unresolved activities into a single approved label.
Request evidence that survives the sales presentation
The table is an original procurement tool.
It does not replace the complete assessment required for the particular data and use.
Ask the supplier to identify exclusions in its answer.
A retention commitment may apply to uploaded documents but not incident logs.
An access restriction may apply to ordinary support staff but not emergency operations.
Neither difference should remain implicit when the purchasing decision is made.
| Question | Evidence to request | Warning sign |
|---|---|---|
| Who processes what? | Activity and subprocessor map | Only a generic privacy brochure |
| Who can access content? | Support roles and access procedure | Unexplained global administrator access |
| How long is data kept? | Retention by storage layer | One period covering unlike records |
| Can we leave? | Export and deletion procedure | Deletion limited to visible uploads |
| What changes require notice? | Contractual change mechanism | Material changes only in release notes |
A hypothetical customer service assistant
Supplier A offers a lower subscription price and says its main storage is in Germany.
Supplier B provides a clearer map of support access, retention layers and a documented deletion workflow.
The team should not conclude that Supplier B is automatically lawful or that Supplier A is unsuitable.
It should compare the unresolved issues and the effort needed to resolve them.
Hosting geography is one relevant fact, while the full processing arrangement determines what still requires assessment.
The manufacturer narrows the first proposed use to fictional and appropriately prepared evaluation data while the review proceeds.
It asks both suppliers to explain how a ticket, its derived index and related diagnostic records would be handled on termination.
This creates a comparable purchasing question with concrete evidence.
Price the operating work as well as the licence
Estimate those activities separately, using your team's own assumptions.
Do not present a vendor's automation promise as a saving until the proposed workflow demonstrates it.
Decide who receives supplier notices and who can act on them.
A subprocessor change sent to an unmonitored procurement inbox is not an effective review process.
Route material notices to the people responsible for the affected use and retain their decision.
Avoid demanding every possible assurance from every supplier.
Match the depth of review to the information, people and consequences involved.
Excessive questionnaires can produce generic answers, while a focused fictional workflow often reveals whether the supplier understands the operational arrangement you are actually proposing.
Approve a bounded use and preserve an exit route
Add unresolved conditions clearly.
A business sponsor should understand whether the use can proceed, proceed with restrictions or wait for additional evidence.
Before relying on the service, know how the workflow continues during suspension or termination.
Identify which records must be exported, which source systems remain authoritative and who verifies access removal.
An exit plan should support an operational decision, not sit unused in a procurement appendix.
The smallest useful next step is a data-flow review for one proposed use.
Bring procurement, IT and the responsible privacy function together around the same example.
The resulting record should explain why the selected arrangement fits the task and which changes would require the decision to be reopened.
What this page cannot conclude
- 01This guide does not establish a lawful basis, transfer mechanism or need for a DPIA in a specific deployment.
- 02The DSK 2024 guidance is a dated orientation document, not a complete current legal checklist.
- 03This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01Artificial intelligence and data protection, guidance dated 6 May 2024Datenschutzkonferenz (DSK) · accessed Sep 15, 2026
- 02General Data Protection Regulation, Regulation (EU) 2016/679European Parliament and Council, EUR-Lex · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Ask Better GDPR Questions Before Buying AI. dotSuper. https://dotsuper.net/feeds/applied-systems/germany-gdpr-ai-vendor-decisions