top of page

A reminder of the importance of vendor due diligence

  • Writer: Elaine Morrissey
    Elaine Morrissey
  • Oct 2
  • 1 min read

2 October 2025


Yet another reminder from a supervisory authority of the importance of vendor due diligence.


The Polish Supervisory Authority has fined both the data controller McDonald's and its processor 24/7 Communication for multiple GDPR infringements arising from a data breach of employee data.


Of particular note:


  • Obligations from legislation cannot be excluded by the Data Processing Agreement (DPA)

  • The controller did not exercise proper supervision over the personal data entrusted to the processor

  • Both the controller and processor need to have in place appropriate technical and organisational measures

  • The processor failed to enter into a DPA with its sub-processor

  • Failure to appropriately engage the Data Protection Officer (DPO). Such failure impacted the possibility of preventing the data breach


Vendor due diligence is not a 'one and done', it is a continuous requirement and don't forget the ever important DPO.



For any queries on this article or how Rock Consultancy can support your organisation, please contact us at info@rockconsultancy.ie


 
 

Recent Posts

See All
AI Regulation SI 366/2025

2 October 2025 While many of us were enjoying summer holidays, a short but mighty Statutory Instrument (SI) was introduced. To give it...

 
 
bottom of page