GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

VND-010 Third-Party Data Disclosure Controls

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Disclosure of personal or sensitive data to third parties is authorised, documented and governed by data sharing agreements. Recipients are limited to the minimum data required for the disclosed purpose. Disclosures are logged and the record is maintained. Customers are notified of third-party disclosures in the privacy notice.

Rationale

Uncontrolled third-party data sharing is both a data protection violation and a breach of customer trust. Tracking disclosures is required for accountability and for supporting data subject rights requests.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (10)

DSP-10Sensitive Data Transferinformative
DSP-10Sensitive Data Transferinformative
GDPR-Art.44General Principle for Transfers to Third Countriesinformative
GDPR-Art.5.1bPurpose Limitationinformative
AC-21Information Sharingpartial
PM-21Accounting of Disclosuresfull
P6.1Disclosure of Personal Informationpartial
P6.2Third-Party Disclosurefull
P6.3Disclosure to Third Partiesfull
P6.4Third-Party Agreementsinformative

Evidence (2)

recorddocumentmanual

Third-party data disclosure log recording all authorised disclosures of personal or sensitive data to external parties with disclosure purpose and recipient details.

Example: Data Disclosure Register (Confluence / spreadsheet), listing each third-party disclosure event or standing disclosure relationship with: recipient name, data categories disclosed, disclosure purpose, legal basis, disclosure mechanism (API / file transfer / direct access), authorisation record, and date

Test: Request the data disclosure register or relevant RoPA extract. Verify: (1) all third-party disclosures are recorded, (2) each disclosure has a documented legal basis or authorisation, (3) data shared is consistent with the minimum necessary for the stated purpose, (4) disclosures to third parties align with what is stated in the privacy notice.

contractdocumentmanual

Data sharing agreements with all third parties who receive personal or sensitive data, establishing permitted use, handling obligations and return/deletion requirements.

Example: Executed Data Sharing Agreements or equivalent contractual provisions (DSAs, information sharing addenda) with third-party recipients, each specifying: permitted use of disclosed data, prohibition on onward sharing without consent, security obligations, retention limits, deletion/return on termination, and compliance with applicable data protection law

Test: Request data sharing agreements for the top 5 third parties identified in the disclosure register. Verify: (1) a written agreement governs each disclosure relationship, (2) each agreement restricts the recipient to the disclosed purpose only, (3) onward sharing is prohibited or requires approval, (4) deletion/return obligations are specified, (5) agreements are signed and current.

Questions (2)

boolean

Are disclosures of personal or sensitive data to third parties recorded in a disclosure register?

Every standing third-party disclosure relationship should appear in the data inventory or a dedicated disclosure register. Recipients must be restricted to the minimum data required for the stated purpose, and disclosures must be consistent with what is stated in the privacy notice.

multi

What controls govern the disclosure of personal or sensitive data to third parties?

A data sharing agreement or equivalent contractual provision governs every disclosure relationshipEach disclosure is logged with recipient, data categories, purpose and legal basisDisclosures are limited to the minimum data necessary for the stated purposeOnward sharing by recipients is prohibited or requires approvalThird-party disclosures are listed in the public-facing privacy noticeDisclosures are reviewed periodically to confirm they remain necessary and proportionateNone of the above

All six active controls indicate a mature third-party disclosure programme. Absence of a disclosure register makes it impossible to fulfil data subject requests or demonstrate accountability to a supervisory authority.