Processor Records
by Formiti's Global DPO Team
A structured register of data processors and sub-processors with contract status tracking, DPA management, and compliance oversight.

Who uses this module?
DPOs, Procurement Teams, Vendor Managers, Legal Counsel.
What governance problem does it solve?
Organisations often lack visibility into their processor landscape, leading to undocumented sub-processing chains and missing DPAs. Processor Records provides a single source of truth for all third-party data processing relationships.
What are the key workflows?
- Register processors with contract details, DPA status, and data categories processed
- Track sub-processor chains with notification and approval workflows
- Monitor DPA expiry and renewal dates
- Record due diligence outcomes and security review results
- Link processors to specific ROPA activities
Register processors with contract details, DPA status, and data categories processed
Track sub-processor chains with notification and approval workflows
Monitor DPA expiry and renewal dates
Record due diligence outcomes and security review results
Link processors to specific ROPA activities
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Processor register with DPA compliance status
Sub-processor chain documentation
Due diligence completion rates
Contract and DPA renewal calendar
How does it connect to other Privacy360 modules?
- Linked to ROPA processing activities
- Vendor Assessments feed due diligence outcomes into Processor Records
- DSAR fulfilment references processors holding subject data
- AI Suppliers module mirrors this pattern for AI-specific vendors
What are some example use cases?
A DPO discovers a processor has onboarded a new sub-processor; the notification triggers a review workflow and updated DPA addendum within the platform.
Procurement filters all processors with expired DPAs and initiates bulk renewal tracking ahead of an annual audit.
A compliance analyst maps all processors handling special category data to prioritise security reviews.
Related modules
ROPA Records
Maintain records of processing activities with clear ownership, data mapping, review controls and AI Processor disclosure — and let the record automatically open and pre-fill the DPIA, LIA, transfer and AI assessments it triggers.
Vendor Assessments
Score third parties against privacy and security criteria, rate portfolio risk, and hold vendors to reassessment cycles rather than one-off checks.
DSAR Requests
Manage data subject requests with workflow tracking, ownership, deadlines and response evidence.
AI Suppliers
Track AI-specific supplier commitments — AI terms, no-training guarantees, transparency documentation — across the AI supply chain.