HomeFree tools › Vendor & DPA register

Vendor & DPA register

Every audit asks for the list of vendors that touch customer data, and which of them have a signed data processing agreement. Most companies underestimate that list by about half. This builds it.

Runs in your browser. Nothing is sent anywhere
0vendors listed
0missing a DPA
0marked critical

Your vendors

Start with your card statement. Every recurring software charge is a candidate. Then add the free tools that still touch customer data.

Vendor What data they touch Criticality DPA signed Security / trust page Last reviewed

Questions people ask about this

What is a vendor register and why do auditors ask for it?

It is the list of third parties that process, store or can access your customer data, together with what each one does and what agreement governs it. Auditors ask because your security is bounded by theirs: a vendor with access to customer data is part of your attack surface whether or not anyone wrote it down.

How do I find every vendor we use?

The fastest method is to open your company card statement or billing export and write down every recurring software charge - that catches most of them. Then add anything free that still touches customer data, such as an analytics tool, a mailing list, or a support inbox.

What is a DPA and do I need one?

A Data Processing Agreement sets out what a vendor may do with personal data you send them. If you handle personal data of people in jurisdictions with data protection law, you generally need one with each processor. Most established vendors publish a standard DPA you can accept without negotiation.

Is my vendor list sent anywhere?

No. Everything stays in your browser's local storage and nothing is transmitted. Export to CSV or Markdown to keep a copy or share it.