A European company's procurement team has shortlisted an AI analytics vendor. The vendor's sales team claims their product is "fully GDPR compliant" and has several enterprise customers in the EU.
A company is evaluating a third-party AI vendor. The vendor claims their service is "GDPR compliant." What is the MOST important follow-up question the privacy officer should ask?
- A.B. "Can you provide your Data Processing Agreement, sub-processor list, and describe your transfer mechanisms for any data leaving the EEA?"
- B.A. "What version of Python do you use for your backend?"
- C.C. "Are you ISO 27001 certified?"
- D.D. "Do you use encryption at rest?"
Why A is correct
"GDPR compliant" is a vague self-declaration with no regulatory certification backing it. The substantive review requires: (1) the DPA to verify it meets Article 28 requirements, (2) the sub-processor list to identify any downstream data sharing (e.g., if they use a US-based cloud provider), and (3) transfer mechanisms (SCCs, Adequacy Decision, BCRs) for any EEA data transfers. ISO 27001 is a security standard, not a GDPR compliance certification. Encryption at rest is one technical measure among many. Python version is irrelevant.
Know someone studying for AI Security Fundamentals? Send them this one.