Home › Free tools › Vendor & DPA register
Every audit asks for the list of vendors that touch customer data, and which of them have a signed data processing agreement. Most companies underestimate that list by about half. This builds it.
Runs in your browser. Nothing is sent anywhereStart with your card statement. Every recurring software charge is a candidate. Then add the free tools that still touch customer data.
| Vendor | What data they touch | Criticality | DPA signed | Security / trust page | Last reviewed |
|---|
It is the list of third parties that process, store or can access your customer data, together with what each one does and what agreement governs it. Auditors ask because your security is bounded by theirs: a vendor with access to customer data is part of your attack surface whether or not anyone wrote it down.
The fastest method is to open your company card statement or billing export and write down every recurring software charge - that catches most of them. Then add anything free that still touches customer data, such as an analytics tool, a mailing list, or a support inbox.
A Data Processing Agreement sets out what a vendor may do with personal data you send them. If you handle personal data of people in jurisdictions with data protection law, you generally need one with each processor. Most established vendors publish a standard DPA you can accept without negotiation.
No. Everything stays in your browser's local storage and nothing is transmitted. Export to CSV or Markdown to keep a copy or share it.