Guides
Short, practical answers for the questions that show up in security reviews — written for SMBs that outgrew a spreadsheet and do not need enterprise GRC.
- Third-party risk
What is a vendor risk register? (SMB guide)
A vendor risk register is the living list of every company that processes your data, with risk, contracts, and owners attached. Here is how SMBs build one that survives the next security questionnaire.
- GDPR
How to keep a GDPR sub-processor list that you can actually export
Controllers must know which processors and sub-processors handle personal data. This guide covers what belongs on the list, Article 28 duties, and how to answer customer questionnaires without a week of Slack.
- Contracts
How to track data processing agreements without a CLM
Missing and expired DPAs are the most common vendor-risk finding for SMBs. Here is a lightweight system: statuses, owners, request letters, and alerts — without buying contract-lifecycle software.
- Data-subject rights
How SMBs track GDPR DSAR deadlines without a case tool
Access and erasure requests have a one-month clock (extendable in limited cases). This checklist shows how a small team logs DSARs, fans them out to vendors, and proves what they did.
- Sales engineering
How to answer “list your sub-processors” on a security questionnaire
Customer security reviews stall on sub-processors, AI use, and DPAs. Here is how to keep paste-ready answers — SIG-Lite and CAIQ style — without rebuilding them for every deal.
- AI governance
What is an AI vendor register?
An AI vendor register lists every AI tool and LLM provider with access to company or customer data — what it processes, where, and whether it may train on inputs. Here is how to build one.
- AI governance
How to audit shadow AI in your company (checklist)
Shadow AI is any AI tool used at work without approval. Use this one-week checklist: discover tools, assess exposure, fix contracts, and keep the register current.
- GDPR
Article 30 vs a vendor register: how SMBs keep a record of processing
A vendor register is not automatically your Article 30 record. Here is how they differ, what an SMB actually needs to keep, and how PrivyLedger helps you maintain a record of processing activities — without pretending it is a certified filing.