What is third-party data sharing?
Third-party data sharing is any disclosure of data to an outside organization. For a service provider this mostly means subprocessors, the vendors that process customer data on its behalf. GDPR requires processors to get authorization before adding a subprocessor and to flow down the same data protection terms.
What the buyer is really asking
Who else gets the buyer's data? Point to your subprocessor list and explain how customers hear about changes to it. Also say whether any transfer outside that list needs written approval.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you handle data sharing with third parties?”
- “Provide a list of your subprocessors.”
- “Do you notify customers before adding a new subprocessor?”
- “Do you require authorization before transferring customer data?”
Evidence to have ready
- Your public subprocessor list
- The subprocessor change notice clause in your DPA
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.