New · GDPR Rating

Your subcontractors' GDPR compliance,
in one automated scan

Article 28 of the GDPR requires you to verify that suppliers handling personal data offer sufficient guarantees. Conitiv automatically analyzes their external surface and produces a score on 1,000 points, without relying on their cooperation.

F1
Supplier A — Management Consulting
328
/ 1 000
Weak
F2
Supplier B — IT Services & Systems Integration
695
/ 1 000
Good
24 criteria analyzed
Scan without third-party cooperation
CNIL registry verification
Updatable on demand
The challenge

GDPR: the obligation to assess your subcontractors

Article 28 of the GDPR

"The controller shall use only processors providing sufficient guarantees to implement appropriate technical and organizational measures."

As soon as a supplier accesses personal data of your clients, employees, or partners — a hosting provider, IT services company, HR firm, SaaS software — they become a data processor under the GDPR. You have a legal obligation to verify that they offer sufficient guarantees before entrusting them with this data.

In practice, the vast majority of companies settle for collecting a declaration of honor or a signed DPA. These documents provide no insight into the supplier's actual maturity. Conitiv analyzes what the supplier actually publishes: their website, legal pages, cookie banner, and DPO declared to the CNIL.

📋

A declaration of honor is no longer sufficient

The CNIL and European supervisory authorities require concrete evidence of due diligence, not just a co-signed DPA.

🔍

Hundreds of suppliers to assess

A manual GDPR compliance audit of a single supplier takes several hours. Conitiv does it in less than a minute for every third party in the portfolio.

📅

A state that changes over time

A compliant supplier today may remove their cookie banner tomorrow. Continuous monitoring replaces the point-in-time audit.

⚠️

Liability comes back to you

In the event of a data breach at a subcontractor, the data controller remains exposed if due diligence is not documented.

What Conitiv analyzes

7 axes, 24 criteria

Each criterion is qualified as "Measured" (technically observed on the site) or "Assessed" (judged on the text of legal pages).

110pts

Legal notices

4 criteria · Identity, purposes, legal basis, data categories

195pts

Privacy policy

5 criteria · Accessibility, clarity, completeness, dating, footer link

170pts

Cookies & trackers

4 criteria · Banner present, equivalent refusal, categories, prior consent

145pts

Data subjects' rights

4 criteria · Access, rectification, deletion, portability

115pts

Security

3 criteria · DPO contact, widespread HTTPS, secure forms

140pts

Consistency

3 criteria · Retention periods, practice/declaration consistency, GDPR forms

125pts

DPO declared to CNIL

1 binary criterion · Verification against the CNIL public registry

"Measured" criteria are technically verified by domain scan and CNIL registry consultation. "Assessed" criteria result from AI analysis of legal page text. Results available in under one minute.

Result examples

Two profiles, two realities

The GDPR rating reveals gaps between suppliers in the same category.

S1
Supplier A — Management Consulting
Business consulting · Automatic analysis
328
/ 1,000

Data protection is reduced to a paragraph of principle with no substantive information. No cookie banner, no DPO declared to the CNIL, and a tracker placed before any consent.

Privacy policy
Detected
Cookie banner
Absent
Legal notices
Detected
HTTPS
Active
CNIL DPO
Not declared
Cookies before consent
1 cookie
Legal notices41/110
Privacy policy74/195
Cookies & trackers0/170
Data subjects' rights39/145
Security70/115
Consistency104/140
DPO declared CNIL0/125
Compliant points
  • ✓Complete publisher identity
  • ✓Fully HTTPS site
  • ✓European Union hosting
  • ✓Legal link in page footer
Non-compliant points
  • ✗No consent banner
  • ✗Tracker before consent
  • ✗No DPO declared to CNIL
  • ✗GDPR rights not presented
S2
Supplier B — IT Services & Systems Integration
Information systems consulting · Automatic analysis
695
/ 1,000

Overall satisfactory compliance level: dated policy, DPO declared to CNIL, CMP deployed. Two weaknesses: a tracker placed before consent and no legal basis indicated.

Privacy policy
Detected
Cookie banner
CMP Didomi
Legal notices
Detected
HTTPS
Active
CNIL DPO
Declared
Cookies before consent
2 cookies
Legal notices62/110
Privacy policy169/195
Cookies & trackers90/170
Data subjects' rights109/145
Security88/115
Consistency52/140
DPO declared CNIL125/125
Compliant points
  • ✓Dated policy (Jan. 2025)
  • ✓DPO declared to CNIL registry
  • ✓Didomi CMP deployed
  • ✓All GDPR rights presented
  • ✓Retention periods declared
Non-compliant points
  • ✗Analytics tracker before consent
  • ✗No legal basis indicated
  • ✗Empty cookie section in policy
  • ✗Cross-border transfers without safeguards
What the scan reveals

The most discriminating indicators

🍪

Cookie banner & prior consent

The absence of a banner or the placement of trackers before consent is the most common breach. It represents up to 170 points. Technically measured by server scan, not by reading the policy.

⚠ Most frequent breach in our analyses
🏛️

DPO declared to the CNIL public registry

125 binary points: the DPO is declared or not. Conitiv consults the CNIL public registry in real time for each supplier. A declared DPO is the strongest signal of organizational maturity.

⚠ Less than 20% of SMEs have declared one
🔐

Privacy policy: completeness

195 points analyzed by AI on the text of legal pages. Criteria cover purposes, legal bases, data categories, retention periods, data subjects' rights, and CNIL mentions.

⚠ Most policies are missing legal bases
What you gain

From declaration to proof

Documented due diligence, not declared

The GDPR rating produces a dated, timestamped, and exportable proof. In the event of a CNIL inspection or challenge, you have a history of scores for each subcontractor.

Portfolio prioritization by risk

The score on 1,000 ranks your suppliers. DPAs to renegotiate, audits to trigger, remediation plans to request — all sorted by actual risk level.

Integrated into Conitiv's 360° score

The GDPR rating is added to Cyber, RSE, and Solvency ratings in the supplier's global risk score. The DPO and compliance teams work on the same view as procurement.

Without relying on the supplier

The scan requires no third-party cooperation. It analyzes the public web domain and the CNIL registry. You get results even if the supplier doesn't respond to your questionnaires.

Actionable recommendations

For each non-compliant criterion, the rating produces a precise recommendation to pass on to the supplier or integrate into your remediation plan.

Continuous monitoring, real-time alerts

Schedule periodic updates. In case of significant degradation — banner removal, CNIL registry removal — you receive an alert before the risk materializes.

Take action

Test the GDPR Rating on your third-party portfolio

A 30-minute demonstration with your suppliers handling personal data and a live scan.

Request a demo →
Parlez à un
expert Conitiv