A tender data-processing schedule changes the proposed service when one of its obligations requires a different processing activity, operating control, supplier arrangement, resource or commercial commitment. Produce a clause-linked gap record showing the issued requirement, the service as offered, supporting evidence, the necessary change, cost and delivery consequences, unresolved legal questions and approval. The record should distinguish a capability already available from a change that is merely proposed. Privacy counsel determines the parties’ legal roles and applicable law; delivery and commercial owners decide whether the reviewed service can be supplied on those terms.
The offer promises regional hosting and attaches a standard processing agreement. The buyer’s annex also restricts overseas support, requires advance approval of every new subprocessor, demands rapid incident updates and calls for deletion of all copies shortly after exit. The product’s normal support and backup arrangements do not satisfy those promises. Unless the team compares the annex with the actual service, the signed contract will describe a different operation from the one priced.
Review the operational consequences before answering that the schedule is accepted. This is an EU GDPR-based contract-to-service review, with sources checked on 6 September 2026. Other jurisdictions, sector rules and public-sector restrictions need separate qualified review. The examples are fictional and describe no Zephior or customer systems. A privacy questionnaire maps evidence to answers; this review instead determines what must change to perform an issued contractual schedule. It does not replace a legal opinion, a full audit-rights assessment, a transfer assessment or final contract authority.
Review inputs
Read the schedule with the service it would bind
Start with the buyer’s complete issued package. A processing schedule may incorporate a security standard, a supplier policy, a retention table and provisions in the main agreement. Record each document’s version, exact clause location and stated priority. Follow references into annexes and clarification answers. If an attachment is unavailable or two documents impose conflicting duties, keep that uncertainty in the review; do not substitute the supplier’s usual agreement for the missing buyer text.
Beside this package, freeze the service being bid: contracting entity, product edition, optional functions, delivery countries, support model, subcontracted activities and planned start. A diagram of a different edition cannot prove this one. Distinguish what exists now, what can be configured, what needs development and what depends on a third party’s consent. Use controlled references to confidential architecture and contracts rather than copying them into a broadly circulated bid log.
For an EU processor arrangement, Article 28 GDPR defines the required agreement content and duties. The buyer can also ask for contractual detail or tighter operating conditions. Keep those bases apart. A twelve-hour notification promise may come from this schedule; it should not be introduced as a universal GDPR deadline. A rule allowing processing only in named countries may constrain a flow even where counsel identifies an available international-transfer mechanism.
Give each gap a stable identifier and enough fields to survive handover: clause, obligation, affected activity, current evidence, mismatch, treatment, owner, due date, cost, approval, blocked action and reopen trigger. The useful result is a decision about this service, not a percentage of clauses whose wording resembles the standard agreement.
| Field | What the reviewer records | What would leave it unresolved |
|---|---|---|
| Issued duty | Source version, clause, actor, action and deadline | Missing annex or uncertain precedence |
| Affected operation | Named service activity and current evidence reference | Evidence belongs to another edition |
| Gap treatment | Configuration, design change, clarification, departure or hold | Change depends on unconfirmed supplier agreement |
| Release basis | Owner, approved cost, completion proof and decision authority | Only an informal sales assurance exists |
Roles and instructions
Separate processing purposes before accepting the role labels
Complete the processing description using the buyer’s actual intended use: subject matter, duration, operations, purposes, personal-data types and categories of people. Include exceptional inputs such as health details in a support attachment when the service permits them. A blank annex or a field saying all customer data conceals the scope the teams need to assess. Ask the buyer to resolve missing intended-use facts through the authorized route, and refer lawful-basis or special-category questions to privacy counsel. A signed processing agreement alone does not establish that the proposed collection is lawful.
A schedule that names the supplier a processor for everything still needs a factual review. Draw distinct rows for the buyer’s core workload, support requests, product telemetry, fraud prevention, billing and any proposed reuse. Record who decides why each activity occurs and its essential parameters. EDPB Guidelines 07/2020 treat these roles as functional and activity-specific; the contract’s label does not settle a contradictory factual arrangement.
Consider a fictional permit service whose optional analytics function combines identifiable user journeys across customers. If the tender limits processing to the buyer’s instructions for permit administration, the reviewer must identify the conflict. Possible treatments include disabling the function for this service, changing the processing design, or asking counsel to assess whether a separate purpose can lawfully and contractually be offered. Calling the data telemetry, or replacing names with identifiers, does not resolve the question.
Document the instruction channel as an operating mechanism. Who at the buyer may issue an instruction, who receives it, how is it authenticated, and how are urgent instructions recorded? Separate a permitted processing instruction from a commercial scope change. A pricing dispute does not authorize ignoring a legal duty, and an instruction does not automatically authorize new development or a new processing purpose. Route suspected unlawful instructions to the appointed privacy and legal owners before action; Article 28(3) includes an obligation to inform the controller when the processor considers an instruction unlawful.
Supplier and location changes
Trace the receiving entity, not only the hosting country
The supplier chain must be able to perform the promises the prime bidder makes. Under Article 28(4), the relevant data-protection obligations must be imposed on the further processor, and the initial processor remains responsible to the controller for that further processor’s performance. Compare the relevant contracts with the proposed schedule: confidentiality of authorized personnel, assistance, security, audit cooperation and deletion. An authorization to appoint the provider does not prove that its contract or service can support these duties.
Follow the data through live processing, support attachments, diagnostics, message delivery, backups, disaster recovery and exit exports. For each flow, identify the receiving legal entity, processing function, actual access location and storage location. Record the conditions under which access becomes possible. A support organization can be relevant even when it rarely opens customer records. Verify that the bid’s regional hosting statement covers only the facts it has actually established.
Article 28 distinguishes prior specific and general written authorization for another processor; general authorization includes notice of intended additions or replacements and an opportunity to object. Translate the issued mechanism into dates and responsibilities. Compare the buyer’s required notice period with the notice the supplier receives from its own provider. If the upstream notice arrives too late, the gap needs a supplier agreement, an alternative service path or an authorized contractual treatment.
EDPB Opinion 22/2024 addresses visibility of the processing chain and verification of sufficient guarantees. Its position includes keeping the identities of processors and subprocessors available to the controller. For the bid record, separate this disclosure from approval status. A name on a website does not prove that this buyer authorized that entity for this activity. Keep protected contact and contractual evidence in the designated review channel.
Transfer analysis needs the entities and circumstances as well as the countries. EDPB Guidelines 05/2021 distinguish disclosure to another controller or processor abroad from access by an employee within the same entity; other security duties still matter. Ask counsel to classify the actual flow. The Article 28 clauses in Decision 2021/915 expressly do not themselves satisfy Chapter V transfer obligations. Neither those clauses nor a lawful transfer route overrides a tighter location restriction in the issued tender.
Operating workload
Test incident, rights and assurance duties against a working day
Security measures need a service-specific response. If the annex requires customer-controlled keys, segregation of particular data, a testing cadence or a defined restoration target, identify the relevant component, configuration, responsible team and evidence. Decide whether the feature is included in the proposed edition and price. Article 32 GDPR requires measures appropriate to risk; a certificate or a standard security paragraph does not prove that an additional buyer requirement is implemented.
For incident reporting, separate the event that starts the clock, the recipient and the content expected at each stage. Article 33(2) requires a processor to notify the controller without undue delay after awareness of a personal data breach. The qualified seventy-two-hour supervisory notification rule in Article 33(1) concerns the controller. The tender may demand earlier or broader contractual reporting. Test who can send an initial report overnight, how missing facts are labelled and when updates follow, without waiting for a finished root-cause report unless the applicable duty permits that.
Rights-request and impact-assessment assistance also consume people’s time. Take one request through receipt, buyer authentication, record identification, extraction, quality review and secure handover. Preserve the buyer’s decision authority and avoid disclosing other people’s records. Estimate normal demand and a bounded surge case. If the schedule requires assistance at no additional charge, show the associated staffing or contingency in the bid price rather than assuming the work is negligible.
Review audit cooperation at the level needed to identify a service gap. Check whether the supplier can provide the evidence and access contemplated by Article 28(3)(h) and the issued annex while protecting other customers. Note unavailable provider access, prohibited disclosures and conflicts between schedules. Refer the detailed inspection protocol and remediation terms to the audit-rights review. An attractive evidence package cannot silently replace an inspection right.
| Issued obligation | Practical test | Decision evidence |
|---|---|---|
| Initial incident notice | A qualifying event is detected outside office hours | Authorized sender, route, timing and incomplete-fact wording |
| Rights assistance | One person has records in production and support history | Search scope, reviewer, secure output and effort |
| Supplier replacement | A provider announces a change on shorter notice | Buyer objection window and usable alternative |
| Assurance access | The requested evidence includes shared infrastructure | Permitted disclosure and unresolved access gap |
Copies and exit
Make the deletion promise account for recovery copies
Inventory the data populations covered by return and deletion: live records, search indexes, exports, support attachments, replicated stores, backups and copies held by subprocessors. Separate the buyer’s retention instructions during service from obligations after processing services end. Article 28(3)(g) addresses the controller’s choice of return or deletion and deletion of existing copies, subject to the stated legal-storage exception. It does not provide a general exemption for inconvenient backup design.
Test the exact deadline in the issued schedule. If backups are immutable for ninety days and the draft requires every copy removed within thirty, record a sixty-day difference. Do not call the thirty-day duty satisfied merely because ordinary users cannot access the copy. Ask the technical owner what can be changed, with what recovery consequences, and ask counsel what wording is permissible. Any proposed restricted-retention arrangement remains a proposal until the required legal and contractual basis is resolved.
Restoration can reintroduce data that was deleted from live systems. The review therefore needs a treatment for deletion instructions after recovery, the point at which ordinary processing resumes and the evidence of completion. For legally required retention, record the applicable basis, dataset, duration, access limitation and approving owner. A vague reference to compliance retention is insufficient. Reconcile return format, transfer security, deletion verification and subprocessor confirmation before pricing exit assistance.
Worked case
A booking-service bid needs four changes before acceptance
In a fictional EU procurement, Alderwick Cultural Authority is buying a workshop-booking service. Schedule P version 4 permits personal-data access only from the EEA, names an advance approval process for subprocessors, requires an initial notice of a covered incident within twelve hours and requires deletion of all copies within thirty days after the processing service ends. These are stipulated contract terms, not standard legal thresholds. The proposed service uses an overseas affiliate for night support and retains immutable backups for ninety days.
The reviewer opens four rows. The support owner proposes EEA-only coverage and removes the affiliate from this offer’s access model. The messaging supplier has not yet supplied the approval evidence required by the buyer. The incident owner demonstrates an on-call reporting route but still needs approval for the exact notification wording. The backup owner identifies a customer-specific thirty-day design that requires implementation and recovery testing. None of these proposals is recorded as already delivered.
Finance estimates €14,000 for the support transition, €22,000 for backup changes and €4,000 for incident preparation: €40,000 once. The new support coverage costs €18,000 each year. Over a three-year base term, the listed changes total €94,000 before tax, excluding unpriced messaging changes and any extension. The €94,000 is therefore a partial change estimate, not an approved fixed-price uplift or the full cost of data protection. Delivery lead times must fit the tender’s actual milestone dates.
The result is a hold on unconditional schedule acceptance. Release requires the messaging evidence and authorization route, successful backup testing, approval of the service description and incident language, and commercial authority for the revised costs. If the procurement does not permit a needed departure, the team must meet the issued obligation or reconsider the bid. A note buried in an architecture appendix would not cure contradictory unconditional acceptance.
| Gap | Proposed treatment | Proof before release |
|---|---|---|
| Non-EEA night support | Restrict this offer to EEA coverage | Staffing, access controls and revised service approval |
| Unconfirmed messaging processor | Complete the specified approval route | Current supplier evidence and required authorization |
| Twelve-hour incident notice | Fund and approve an on-call initial report | Test record, named duty owner and wording approval |
| Ninety-day backup retention | Implement the proposed thirty-day design | Deletion and recovery tests against Schedule P v4 |
What good looks like
Useful outcomes from review a tender data-processing schedule
- Every material schedule obligation points to a defined processing activity and service owner.
- Contract requirements and legal duties remain separately identified.
- Support, supplier and deletion gaps have a feasible treatment or an explicit hold.
- The priced service includes the resources needed for approved assistance and controls.
- The final decision identifies the exact schedule and service versions it covers.
Operating model
How to run the work
- 01
Fix the review baseline
Collect the issued schedule, completed and blank annexes, linked policies, clarifications, hierarchy and bid acceptance rules. Record the offered edition, entities and service design.
- 02
Map processing to clauses
Separate production, support, telemetry, testing, recovery and exit. For each activity, record purpose, people, data, recipients, locations and proposed legal role.
- 03
Test the operating obligations
Compare instructions, supplier approvals, technical measures, assistance clocks, access rights and deletion promises with evidenced service behavior.
- 04
Resolve the service differences
Choose an evidenced existing capability, costed design change, permitted clarification or departure, or hold. Track the dependencies and proof needed for each change.
- 05
Reconcile and approve
Check the resulting design against price, security answers, support levels, liability and exit. Obtain the appropriate legal, delivery, security and commercial decisions.
- 06
Control the release
Bind approval to the exact offer and schedule. Reopen affected rows after changes and transfer approved obligations to the delivery owner without exposing protected evidence.
Evaluation
Questions that change the decision
- Does each stated role fit the underlying processing facts?
- Which obligation exceeds the service currently priced?
- Can a required supplier or access change be completed before its contractual due date?
- What must the buyer clarify through the permitted procedure?
- Which commitments remain blocked pending evidence or authority?
- Does a changed schedule invalidate an earlier approval?
Failure modes
Where teams lose control
A hosting location is used to answer every access and transfer question.
A general supplier list is mistaken for permission to use the required subprocessor.
A contract promise is accepted because a policy uses similar words.
The controller’s regulator-notification clock is copied into the processor’s buyer-notification obligation.
Active-record deletion is described as deletion of backups and downstream copies.
A proposed exception is hidden in a technical answer while the contract form says unconditional acceptance.
Measurement
Measure the finished job
Measure the completed workflow, including review effort and exceptions. Output volume on its own is not evidence of a better process.
- Material clauses without service evidence
- Required changes with no accountable delivery owner
- Supplier approval lead time against the service start
- Unfunded implementation and recurring assistance costs
- Deletion populations without an evidenced completion method
- Open legal questions and release-blocking conditions
Questions
Common questions
Can our standard processing agreement replace the buyer’s schedule?
Only if the procurement permits that treatment and the required authority accepts it. First determine the issued document hierarchy and acceptance rules. A standard agreement helps identify differences, but attaching it does not establish that it overrides the buyer’s annex.
Does regional hosting resolve the location review?
No. Examine storage, support, diagnostics, backups, messaging and exports separately. Record the receiving entities and access locations. Counsel must assess transfer questions, and the service must still satisfy any stricter contractual location requirement.
Is seventy-two hours the processor’s incident deadline?
Under the EU GDPR, Article 33(2) requires processor notification to the controller without undue delay after awareness of a personal data breach. Article 33(1) contains the controller’s qualified seventy-two-hour supervisory notification rule. Read any additional buyer reporting clock separately.
Can we exclude immutable backups from deletion?
Do not assume an exclusion. Record the actual backup retention and compare it with the law and issued schedule. A different design or expressly reviewed contractual treatment may be needed. Restricted access alone does not prove deletion, and any legal-storage exception needs a specific basis.
Do Article 28 standard clauses authorize international transfers?
Decision 2021/915 states that its controller-processor clauses do not themselves ensure compliance with Chapter V transfer obligations. A separate assessment of the actual transfer and applicable mechanism is needed. A transfer mechanism also does not remove a conflicting tender location restriction.
When is the review complete?
When each material clause has an evidenced fit or an authorized, feasible treatment with the correct timing, and the exact schedule, service and price have been reconciled. Unresolved legal meaning, supplier evidence or approval remains visible as a hold. Completion of the review does not itself authorize contract signature or submission.
Sources
Primary references
- GDPR: Articles 4, 28, 32, 33 and Chapter V European Union
- Decision 2021/915: controller-processor clauses and completed annexes European Commission
- Guidelines 07/2020, version 2.1: factual controller and processor roles European Data Protection Board
- Guidelines 05/2021, version 2.0: identifying international transfers European Data Protection Board
- Opinion 22/2024: processors, subprocessors and sufficient guarantees European Data Protection Board
Zelius
Managed tender intelligence and bid execution for teams that want the commercial outcome.
Suppliers, founders and commercial teams pursuing public or private opportunities. Start with the workflow, constraints and evidence you already have.