Vendor and Processing Operation Assessment

Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

 

Welcome to the Vendor Assessment and Processing Operation Assessment User Guide. Conducting vendor assessments is crucial for ensuring that third-party providers meet your organisation’s data protection standards and comply with relevant privacy regulations. In today’s data-driven environment, vendors often play a significant role in processing and handling personal data on behalf of organisations, which makes it essential to evaluate their data security practices, regulatory compliance, and overall risk profile.

Vendor assessment enables your organisation to systematically evaluate each vendor’s approach to data protection, including their handling of personal data, technical safeguards, and adherence to legal obligations. By thoroughly assessing vendors, your organisation can identify and mitigate potential risks before data is shared, maintain accountability in data management, and ensure that all parties involved in data processing uphold the required standards of privacy and security.

A processing operation assessment provides a structured form to help guide you through a vendor assessment, allowing you to document findings and capture any associated risks, issues, tasks, or lessons through the Governance Platform Lite. 

Access to Vendor Assessment and Processing Operation Assessment is included as part of 9ine’s Privacy Platform and Vendor Platform licences. For further information, contact [email protected].

Accessing vendor assessment and processing operation assessment

Upon purchasing 9ine’s Privacy Platform or Vendor Platform and its associated features, users can be granted access to Vendor and Processing Operation Assessments. Your organisation’s administrator(s) have the option to allocate permission via  User Management (previously referred to as People) available to administrators in the header.

 Vendor: Granting access to this feature allows users to create new vendors and processing operation assessments but does not automatically grant access to all existing vendors. Users need to be assigned as owners, members, notified users, or attachment reviewers of specific vendors to gain edit access to those areas and their associated processing operation assessments. A vendor’s permissions include:

  • Owner
  • Member
  • Notified User
  • Attachment Reviewer

Processing Operation Assessment: Similarly, access to this feature does not automatically grant rights to view or edit all processing activities. Users must be specifically added as owners, members, reviewers, approvers, attachment reviewers, or notified users for individual assessments to gain edit permissions. A processing operation assessment’s permissions include:

  • Owner
  • Member
  • Reviewers
  • Approvers
  • Attachment reviewers
  • Notified users 

In addition, any owners, members, notified users, or attachment reviewers of any risks, issues, lessons or tasks are also granted edit access to the processing operation assessment but they do not gain access to the vendor and the other assessments associated with the vendor. 

Tip:

For user convenience and when applicable, a user can also be designated as a vendor area owner or member, granting them access to all assessments for a vendor.

 

There can only be a single owner of a vendor and processing operation assessment, but there are no limits to the number of members or notified users. Each attachment and processing operation assessment can also have one reviewer, approver and attachment reviewer. Owners can edit and delete their assigned items, while all other roles have edit rights but cannot delete. When more than two members or notified users are added, the additional user details are combined into a single pill, which can be clicked to view further details. These pills are alphabetically ordered.

Warning:

If a vendor is linked to data protection impact assessment, record of processing area, or record of processing activity, users with access to the linked item are granted access to the vendor and all associated processing operation assessments.

 
 
 

Adding and removing notified users

Adding removing notified users forms

To add a notified user, use the mention function in the “Additional Notes” featur...

To add a notified user, use the mention function in the Additional Notes feature.

  • To begin, click the @ symbol on your keyboard and type the first name of the user you wish to mention. 
  • A user can be mentioned at the start, in the middle, or at the end of the entered text. 
  • To remove a user as a notified user, simply delete their name from the relevant note. 
  • Mentioning a user sends an in-Platform notification and an email unless the user has disabled email notifications. 
  • The email notification sends a complete copy of the text entered by the user in the 9ine Platform, to the user’s registered email address.

 

 
 

Understanding how to create a vendor and processing operation assessment

Begin by clicking New Vendor, to get started. You will then be presented with a popup which displays four fields:

  • Select Application
  • Legal name
  • Trading name
  • Address 
  • Zip/Post Code/PO box
  • Country (Headquarters)
  • Country (where processing will take place)
  • Owner
  • Member(s)
  • Notified user(s)
  • Link RoP
  • Link RoPA
  • Link DPIA
  • Vendor Code
  • Next Review Date

  • A contact(s) table Add Details
    • Type
    • First Name
    • Last Name
    • Role
    • Contact Information

Two of the fourteen fields are mandatory when creating a new vendor including: legal name and owner.

On entering the required fields, you have three options:

  • Save & Exit: Saves the information, creates the vendor, and returns you to the vendor log.
  • Save & Create POA: Saves the information, creates the vendor, and opens a new popup with five additional fields (detailed below).

Save & Create POA

On clicking Save & Create POA you are presented with five further fields which include the title of processing operation assessment, owner, member(s), department(s), and next review date. You then have the option to:

  • Save & Exit: which saves the processing activity and navigates you back to the vendor log.
  • Save & Add Details which saves the processing operation assessment and navigates you into the full form assessment.
  • Save & Create another POA: which saves the processing operation assessment but allows you to create another associated with the vendor.

 
 

Quickstart your vendor and processing operation assessment from the vendor library

Quickstart your vendor and processing operation assessment from the vendor library

If your organisation has access to Vendor Platform and your organisation’s admini...

If your organisation has access to Vendor Platform and your organisation’s administrator(s) have granted you access, you have the option to Quickstart a vendor and its processing operation assessment from the Vendor Library. 

On navigating to the library you can easily identify where assessments are:

  • Coming soon
  • Recently updated
  • New
  • Part of 9ine’s certified program

For further information, refer to the information provided with the Preview.

On clicking Preview, you can access additional details about the vendor assessment, including its current status, whether special category data or artificial intelligence is involved, and any safeguarding considerations. Additionally, any associated risks, issues, lessons, and tasks are displayed, providing a comprehensive view of all relevant information at a glance.

In the Description accordion of each assessment, 9ine allows for the inclusion of additional relevant information that may be essential for understanding updates or specific details related to the assessment. This is particularly useful for documenting any updates, changes, or specific elements included in the assessment, providing a comprehensive view of the vendor or processing operation's evaluation over time.

On the individual tiles within the library, relevant icons display key details when hovered over, allowing you to quickly access additional information, such as the assessment’s status, involvement of special category data, artificial intelligence usage, and any safeguarding concerns. This feature provides an at-a-glance overview, helping you stay informed of critical aspects directly from the tile view.

Quickstarting from the Vendor Library action will add the vendor and its associated processing operation assessment to the relevant logs. Vendors and processing operation assessment that have been initiated via the Quickstart feature will be easily identifiable by a distinct icon in the first column. Upon editing and saving a Quickstart assessment, the icon will automatically be removed.

 
 

Creating a new record of processing operation assessment or editing an existing one (including a Quickstart form)

When creating a new processing operation assessment from scratch or via the Quickstart workflow or editing an existing activity, you will be navigated to the form and presented with six headers, including:

  • Processing Operation Description
  • Processing Compliance
  • Safeguarding
  • Security And Systems
  • Assessment Summary
  • Review & Approval

To efficiently move through the six steps, you can use the clickable navigation tabs when there are no unsaved changes on the form. However, after making changes, you must navigate using the primary buttons located at the bottom of the page.

The title of the processing activity is consistently displayed at the top of the form, and to the right, a unique reference number is provided. This number is prefixed with POA and followed by a unique identifier that cannot be edited. 

Processing responsibilities such as the controller, joint controller, data processor or any other external party will be identified during the discovery phase of populating your organisation’s processing operation assessments.

The Processing Operation Description step allows you to capture if the personal data is transferred to another country. 

Transferring personal data to another country may introduce additional risks, as many countries have specific regulations governing cross-border data transfers. Data transfer to another jurisdiction can occur in various ways, such as when information is emailed, stored on cloud servers located overseas, or accessed from another country. These actions may expose data to differing levels of protection based on the destination country’s laws, making it essential to assess and mitigate associated risks carefully.

In the Processing Compliance step, selecting an option—N/A, Yes, No, or Don’t Know—activates an additional information field where you can provide further details. This feature allows for enhanced clarity and context around your selection, supporting a more comprehensive assessment.

On the Safeguarding step you are initially presented with a single question. 

On selecting Yes, additional questions are presented.

Similar to the previous step, selecting an option— Yes, No, or Don’t Know—activates an additional information field where you can provide further details.

In the Security and Systems step, you will begin with a single question. If you select Yes or Don’t Know, additional questions will appear to gather more detailed information. This step is best completed in collaboration with your IT team to ensure thorough and accurate responses, as it involves technical aspects of systems and security that require IT expertise.

 
 

Selecting data subjects and the associated personal and special category data

Selecting data subjects and the associated personal and special category data

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Proc...

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Processing Operation Assessment, and Incident Management), you can select data subjects along with their associated personal and special category data. On selecting a data subject, their details appear in a pill below the question for easy reference.

Tip:

If a data subject type is not available in the Platform’s default list, you can add it using the +Other function. Any data subjects added this way will be accessible to all users in your organisation for future use.

 

Each data subject appears in the popup when you click Select Personal Data or Select Special Category Data.

When a user adds any Personal Data or Special Category Data in the corresponding pop-up, a Copy To All button becomes visible. This button allows the user to copy the selected data option to all applicable entries, ensuring consistency and efficiency across the forms.

The secondary number displayed in the Answered pill represents the total number of selected data subjects. For example, if one data subject was initially selected and an additional two were chosen, the count would change from 1 to 3.

 

 
 

Creating an associated risk, issue, lesson, or task (Summary of Activities)

Create associated risk

In the top right-hand corner there is a +New button which provides four options: ...

In the top right corner there is a +New button which provides four options: New Risk, New Issue, New Lesson, and New Task.  

For more detailed information on the specific logs, please refer to their individual user guides:

When creating a risk, issue, lesson, or task the details are automatically added to the Summary of Activities table.

 
 

Utilising the additional notes and attachments features for a vendor and processing operation assessment

Utilising the additional notes and attachments features

The “Additional Notes” feature allows you to maintain a single repository of info...

The Additional Notes feature allows you to maintain a single repository of information related to a moduleName. You can add multiple notes at once using the Save Note function. These notes are saved without the need to click the primary Save at the bottom of the page.

When adding a new note, a record of the user's details, date, and time of entry are added, and the most recent notes will automatically appear at the top of the list. If an individual note is edited, the time and date of the note are updated.

Tip:

Individual notes can only be edited or deleted by the user who originally created the note. However, users have the option to add comments to notes created by others.

 

Additional formatting functionality is provided in the additional notes feature. If entering large volumes of data, click the Full Screen or Expand Popup options.

Warning:

  • For security purposes, the 9ine Platform will log users out of their active sessions after 45 minutes of inactivity, with a reminder triggered at 30 minutes of inactivity. 
  • If you are in full screen mode, the reminder may not appear unless you have browser-based notifications enabled. 
  • Typing in the field is not considered activity; activity is only registered when clicking Cancel or Save.
 

The Attachments feature allows you to upload files or images using your native file explorer. You can upload up to five attachments at once. 

  • Maximum file size: 10MB
  • A maximum of five files can be uploaded at a time
  • Supported file types: jpg, jpeg, tif, tiff, png, odg, otg, txt, rtf, doc, docx, pages, odt, ott, odm, pdf, xml, xmlx, numbers, ods, ots, ppt, pptx, key, keynote, odp, otp, xls, xlsx, tsv, csv, pst, eml, emlx, ost, oft, msg
  • The file name cannot contain special characters :/?<>|"\ #+&'~

Each attachment uploaded can be assigned a reviewer, allocated a review date, and further information can be included. This process ensures that attachments added remain current and do not become obsolete.

 
 

Uploading a vendor or processing operation assessment logo

In both the new and edit workflows for a vendor or processing operation assessment, you have the option to upload a custom logo. Once added, you can either reset it to the default 9ine Platform logo or replace it with a new image at any time, providing flexibility in representing each vendor or assessment visually.

 
 

Understanding how to use the vendor and processing operation logs

When creating a new vendor or processing operation assessment, or editing an existing one, the details entered are added to the respective log. Each vendor and processing operation assessment  are automatically assigned a unique reference number (starting with VEN and POA) that cannot be edited.

To see only the vendors you are responsible for, use the My Vendors toggle in the top right corner of the Vendor log. This filter will display items where you are listed as the owner, member, or notified user. Please note that this feature is unavailable on the Processing Operation Assessment (POA) log when in the Vendor Details view but becomes accessible when you switch to the Processing Operation Assessment (POA) log view. Here you will have the option to enable My POAs.

In the Vendor Log, you can toggle between the following layouts:

  • Vendor Assessment (VA) layout
  • Processing Operation Assessment (POA) layout

Any changes made to the and POA layout are specific to each user and log, applying only to your profile. 

When accessing data through any of the three available logs, you will find common functionality is consistently available across them.

Default sorting is applied to the Ref No., which can be altered by clicking on the title of any other column. Clicking a column header once sorts the log by the selected column, and clicking it a second time reverses the order.

To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Apply. You also have the option to Save View.

You can also change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login. 

Tip:

The changes applied to the sequence order of the log and in the View popup are user and log specific and only applied to your profile.

The sequence order in the View popup does not update to reflect the order created through your dragging and dropping actions.

 

To focus on a specific vendor or processing operation assessment, you can use the Filter or Search functions. When a filter is active, an orange icon appears next to the filter icon for easy recognition. 

  • To quickly clear any filters, click the Clear Filters button in the popup. 
  • You can also apply a temporary filter without clicking Save Filter.
  • To revert back to your saved filter, click Reset.
  • Similarly, you can select data points and click Apply without saving your filter options.

To bulk manage Vendors or POAs, select one or more checkboxes located on the far-left side of the relevant log. Once one or more vendors are selected, the Manage Vendors button will appear above the log. Similarly, when POAs are selected, the Manage button will become available. Clicking the Manage Vendors button provides four options: manage, duplicate, close, and delete. Choosing manage allows you to bulk modify the owner, members, and next review date of the selected vendors.

Clicking the Manage button for POAs provides additional sub-options. Users are able to manage the POA along with its associated risks, issues, lessons, and tasks. Individual associated items can also be managed separately. Choosing manage allows you to bulk modify the owner, members, and next review date of the selected POAs. It also includes a Copy to all tabs feature, which enables users to apply the same data values across all associated items. Users may also manage associated items, allowing them to update the owner, members, status, and next review date (or due date for tasks). In addition, users may duplicate, close, or delete a POA or its individual associated items.

Users may select individual Vendors or POAs, or select all records on a page by ticking the checkbox in the column header. For the selection of Vendors or POAs, provide options as:

  • Current Page: selects all records on the page you are viewing.
  • All Pages: selects all records that match the current filters across all pages, excluding Closed records.
  • Clear Selection: removes all current selections
 
 

Downloading a vendor or processing operation assessment

Downloading Forms

To download a moduleName(s) and its activities click the Download button located in the top right-hand corner of the moduleName log. You can customise the download report to include or exclude data by using the search bar, filter, view options, or My moduleName functions.  Upon clicking Download, the export is processed in the background. Once complete, you will receive both an in-platform notification and an email notification. The exported file is provided in XLS format.

On the moduleName log, You have three download options available:

  • Log - Downloads in XLS format.
  • Advanced - Downloads in XLS format.
  • Form (available in the quick actions menu) - Downloads in DOCX format.
 
 

Understanding the quick actions for a vendor

The vendor log provides a range of quick-access functions within the menu options, including:

  • Create POA
    This allows you to directly create a new processing operation assessment associated with the vendor.
  • Add Note
    Opens the vendor details page directly on the Additional Notes feature. 
  • Add Member(s)
    Opens a members popup to quickly grant users access to the vendor.
  • Link RoP
    Opens the link popup, allowing you to select a record of processing area.
  • Link RoPA
    Opens the link popup, allowing you to select a record of processing activity.
  • Link DPIA
    Opens the link popup, allowing you to select a data protection impact assessment.
  • Duplicate
    Duplicates the vendor, you can choose to add the Copy of prefix to the Vendor title and its child items, or duplicate it without the prefix. Additional Notes and Attachments will also be duplicated. Logged time and costs associated with child items will not be copied. Child items will not receive the Copy of prefix unless the Prefix All Items button is selected.
  • Revisions
    Opens the vendor revisions popup detailing the user name, date, and time of the last revision.
  • Close
    Marks a vendor and all its associated processing operation assessments, risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Reopen
    Marks a closed vendor as open and restores all associated items. Related activities are returned to open status. Associated tasks are returned to not started, while linked risks, issues, and lessons are returned to open status.
  • Delete
    Marks a vendor and all its associated processing operation assessments, risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.

 
 

Understanding the quick actions for a processing operation assessment

The processing operation assessment logs (via the switch layout feature on the vendor log or on the vendor details page) provides a range of quick-access functions within the menu options, including:

  • Add Note 
    Opens the processing operation assessment form directly on the Additional Notes feature. 
  • Add Member(s)
    Opens a members popup to quickly grant users access to the processing activity.
  • Add Reviewer(s)
    Opens a reviewers popup to quickly grant users access to the processing operation assessment. 
  • Add Approver 
    Opens an approver popup to quickly grant users access to the processing operation assessment. 
  • Duplicate
    Duplicates the processing operation assessment, you can choose to add the Copy of prefix to the POA title and its child items, or duplicate it without the prefix. Additional Notes and Attachments will also be duplicated. Logged time and costs associated with child items will not be copied. Child items will not receive the Copy of prefix unless the Prefix All Items button is selected.
  • Download
    Downloads the processing operation assessment form in a DOCX format.
  • Publish Application
    Users can create an application by selecting the Publish Application option from the three-dot menu in POA. While creating the application, the Vendor and POA fields are pre-selected.
  • Close
    Marks a processing operation assessment and all its associated risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Reopen
    Marks a closed processing assessment, open, and restores all associated items. Related tasks are returned to not started, while associated risks, issues, and lessons are returned to open status.
  • Delete
    To delete, navigate to Vendor Details and click the quick menu option and select Delete. On selecting Delete, it marks a processing operation assessment and all its associated risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.

 
 

Configuring vendor and processing operation notification settings

Global Due Date Notifications Alerts

To ensure you're always informed of key moduleName milestones, users can configure their personal notification preferences within the Notification Settings area of the 9ine Platform. This enables both email and in-Platform alerts for important events in the moduleName lifecycle such as end dates, due dates, renewal reminders, termination deadlines, and next review dates.

To activate alerts:

  1. Navigate to your Notifications (available in the header)
  2. Click the Notification Settings icon

Toggle Global Lifecycle Alerts on for both In Platform and Email to receive notifications through both channels.

Under Reminder, you can select how far in advance you would like to be notified of an upcoming milestone (e.g. 7, 14, or 30 days before the due date). This ensures you receive early warnings before deadlines approach. You can choose any period from 1 to 31 days in advance.

These reminders are designed to give moduleName owners and stakeholders enough lead time to review, act, or make decisions before renewal or termination windows close.

To receive multiple reminders, you can enable Repeat notifications.

  • Repeats are available in weekly intervals and are only triggered if your chosen reminder period is 7 days or more.
  • The number of notifications is based on your reminder window:

For example:

  • If your reminder is set to 10 days, you’ll receive 1 notification.
  • If it’s set to 16 days, you’ll receive 2 notifications.

This flexible notification system helps ensure key events never go unnoticed, especially in busy school environments where planning ahead is essential.