Free template

Vendor risk template

A simple vendor review template covering common data processed, review cadence, and privacy/security prompts.

  • Vendor profile: name, domain, category, owner, business purpose
  • Common data processed: personal data, account data, payment data, logs, or support data
  • Risk review: DPA, SOC 2 report, ISO certificate, breach history, subprocessors
  • Review cadence: annual, semiannual, or event-driven
  • Template picker: AWS, Google Workspace, GitHub, Stripe, Vercel, Supabase, Slack, OpenAI, Anthropic

Use this as a starting point

This page is an educational checklist/template, not legal advice. PrivaBase helps turn the checklist into cited evidence, reusable answers, and a buyer-ready packet.