Your subcontractors' GDPR compliance,
in one automated scan
Article 28 of the GDPR requires you to verify that suppliers handling personal data offer sufficient guarantees. Conitiv automatically analyzes their external surface and produces a score on 1,000 points, without relying on their cooperation.
GDPR: the obligation to assess your subcontractors
"The controller shall use only processors providing sufficient guarantees to implement appropriate technical and organizational measures."
As soon as a supplier accesses personal data of your clients, employees, or partners — a hosting provider, IT services company, HR firm, SaaS software — they become a data processor under the GDPR. You have a legal obligation to verify that they offer sufficient guarantees before entrusting them with this data.
In practice, the vast majority of companies settle for collecting a declaration of honor or a signed DPA. These documents provide no insight into the supplier's actual maturity. Conitiv analyzes what the supplier actually publishes: their website, legal pages, cookie banner, and DPO declared to the CNIL.
A declaration of honor is no longer sufficient
The CNIL and European supervisory authorities require concrete evidence of due diligence, not just a co-signed DPA.
Hundreds of suppliers to assess
A manual GDPR compliance audit of a single supplier takes several hours. Conitiv does it in less than a minute for every third party in the portfolio.
A state that changes over time
A compliant supplier today may remove their cookie banner tomorrow. Continuous monitoring replaces the point-in-time audit.
Liability comes back to you
In the event of a data breach at a subcontractor, the data controller remains exposed if due diligence is not documented.
7 axes, 24 criteria
Each criterion is qualified as "Measured" (technically observed on the site) or "Assessed" (judged on the text of legal pages).
Legal notices
4 criteria · Identity, purposes, legal basis, data categories
Privacy policy
5 criteria · Accessibility, clarity, completeness, dating, footer link
Cookies & trackers
4 criteria · Banner present, equivalent refusal, categories, prior consent
Data subjects' rights
4 criteria · Access, rectification, deletion, portability
Security
3 criteria · DPO contact, widespread HTTPS, secure forms
Consistency
3 criteria · Retention periods, practice/declaration consistency, GDPR forms
DPO declared to CNIL
1 binary criterion · Verification against the CNIL public registry
"Measured" criteria are technically verified by domain scan and CNIL registry consultation. "Assessed" criteria result from AI analysis of legal page text. Results available in under one minute.
Two profiles, two realities
The GDPR rating reveals gaps between suppliers in the same category.
Data protection is reduced to a paragraph of principle with no substantive information. No cookie banner, no DPO declared to the CNIL, and a tracker placed before any consent.
- ✓Complete publisher identity
- ✓Fully HTTPS site
- ✓European Union hosting
- ✓Legal link in page footer
- ✗No consent banner
- ✗Tracker before consent
- ✗No DPO declared to CNIL
- ✗GDPR rights not presented
Overall satisfactory compliance level: dated policy, DPO declared to CNIL, CMP deployed. Two weaknesses: a tracker placed before consent and no legal basis indicated.
- ✓Dated policy (Jan. 2025)
- ✓DPO declared to CNIL registry
- ✓Didomi CMP deployed
- ✓All GDPR rights presented
- ✓Retention periods declared
- ✗Analytics tracker before consent
- ✗No legal basis indicated
- ✗Empty cookie section in policy
- ✗Cross-border transfers without safeguards
The most discriminating indicators
Cookie banner & prior consent
The absence of a banner or the placement of trackers before consent is the most common breach. It represents up to 170 points. Technically measured by server scan, not by reading the policy.
DPO declared to the CNIL public registry
125 binary points: the DPO is declared or not. Conitiv consults the CNIL public registry in real time for each supplier. A declared DPO is the strongest signal of organizational maturity.
Privacy policy: completeness
195 points analyzed by AI on the text of legal pages. Criteria cover purposes, legal bases, data categories, retention periods, data subjects' rights, and CNIL mentions.
From declaration to proof
Documented due diligence, not declared
The GDPR rating produces a dated, timestamped, and exportable proof. In the event of a CNIL inspection or challenge, you have a history of scores for each subcontractor.
Portfolio prioritization by risk
The score on 1,000 ranks your suppliers. DPAs to renegotiate, audits to trigger, remediation plans to request — all sorted by actual risk level.
Integrated into Conitiv's 360° score
The GDPR rating is added to Cyber, RSE, and Solvency ratings in the supplier's global risk score. The DPO and compliance teams work on the same view as procurement.
Without relying on the supplier
The scan requires no third-party cooperation. It analyzes the public web domain and the CNIL registry. You get results even if the supplier doesn't respond to your questionnaires.
Actionable recommendations
For each non-compliant criterion, the rating produces a precise recommendation to pass on to the supplier or integrate into your remediation plan.
Continuous monitoring, real-time alerts
Schedule periodic updates. In case of significant degradation — banner removal, CNIL registry removal — you receive an alert before the risk materializes.
Test the GDPR Rating on your third-party portfolio
A 30-minute demonstration with your suppliers handling personal data and a live scan.
Request a demo →expert Conitiv