Sub-processors and security measures

Status: 12 September 2026 – inventory for legal and technical review

1. Sub-processor inventory

2. Draft technical and organisational measures

Physical and access protection

Disclosure and separation

Availability and recovery

Review

[TECHNICAL REVIEW: Keep these statements only if every item is actually implemented and documented. Add backup intervals, encryption methods, roles, log and deletion periods.]

3. Data-breach process

  1. Record the incident, protect systems and limit access.
  2. Assess categories of data, affected people, scope, cause and risk.
  3. Involve legal advice/data-protection contact; assess required notification to authority and data subjects in time.
  4. Document measures and decisions; fix the cause and perform follow-up review.

[LEGAL AND ORGANISATIONAL REVIEW: Responsible person, reporting channels, 72-hour period and communication templates.]