Back to privacy assessments

Privacy assessment

Transfer Vendor and Subprocessor Assessment

Public-safe assessment of provider integrations evidenced in CIC repositories and the contractual or location facts that authorized owners must confirm.

Status
Draft for external legal and privacy review
Version
0.9
Classification
Public
Last reviewed
12 August 2026
Next review
12 November 2026
Effective date
Pending approval
Owner
Privacy and vendor-risk owners - confirmation required
Approval
Executive owner and privacy counsel - pending
Supersedes
None - initial publication
Download PDF
Document controlValue
Document IDCIC-PIA-TIA-005
Version0.9
Superseded versionNone - initial publication
StatusDraft for external legal and privacy review
Publication classificationPublic
OwnerPrivacy and vendor-risk owners - confirmation required
ApproverExecutive owner and privacy counsel - pending
Effective datePending approval
Last reviewed12 August 2026
Next review12 November 2026 or earlier after a material change

Purpose

This report assesses vendor families evidenced in CIC repositories and states what must be confirmed before a transfer can be approved. It intentionally does not publish account identifiers, credentials, private endpoints, detailed security topology, contracts, or restricted provider evidence.

An integration in source code proves capability, not production activation. A named provider must remain Confirmation required until an authorized owner reconciles source evidence with contracts, invoices, production consoles, data-flow logs, and the vendor register.

Required vendor evidence set

Every active provider must have a controlled record containing:

  • provider and contracting legal entities;
  • product, account owner, business purpose, and controller/processor role;
  • categories of data and data subjects;
  • production activation and feature configuration;
  • storage, processing, backup, support, and remote-access locations;
  • current subprocessor list and change-notification subscription;
  • executed contract, DPA, security exhibit, and deletion/return terms;
  • transfer mechanism, completed annexes, certification scope, and effective date;
  • encryption, key management, access, logging, incident, continuity, and deletion controls;
  • government-request policy and relevant transparency information;
  • inherent risk, residual risk, exceptions, approvals, and next review.

Provider-family assessment

Provider familyRepository evidencePrimary transfer concernRequired closure evidenceCurrent risk
Google Cloud hosting and storageDeployment and storage integrations confirmedGlobal submission to US-hosted services; storage, backup, support, and subprocessor locationsContracting entity, DPA, service regions, transfer terms, subprocessor record, security settings, retentionMedium-High; High for Restricted files
MongoDB-compatible databaseDatabase connectivity confirmedBroad data concentration and unknown provider, cluster, backup, and support locationsProvider identity, cluster topology, region, DPA, clauses, encryption/key evidence, access and backup controlsHigh
Google identity and APIsOAuth and API capabilities evidencedAccount, authorization, profile, media, and metadata exposure across global service locationsActive APIs, configured scopes, entity, terms, retention, transfer mechanism, revocation and deletion controlsMedium to Medium-High
Email and notificationsResend, SendGrid, and AWS SES/SNS capabilities evidenced across servicesMessage content, addresses, delivery metadata, and subprocessor routingActive provider per message type, entity, location, DPA, minimization, template review, suppression and deletion evidenceMedium-High
PaystackPayment capability evidencedIdentity, payment, reference, bank-partner, and transaction dataProduction status, provider entity, DPA, banking recipients, location, retention, mechanism, incident termsHigh
StripePayment and connected-account capability evidencedIdentity, business, bank, payment, compliance, and global subprocessor dataEnabled products, account country, entity, DPA, DPF or clauses, connected-account roles, retention and deletionHigh
EmbedlyWallet and bank-transfer capability evidencedIdentity, wallet, bank-transfer, inflow, and webhook dataProvider identity, production status, data map, contract, DPA, location, banking partners, security and transfer basisHigh
MonoFinancial-data capability evidencedLinked bank account, transactions, verification, and connected-institution rolesEnabled products, provider and bank roles, consent, retention, deletion, DPA, location, transfer mechanismHigh
PlaidFinancial-data capability evidencedBank, account, balance, transaction, identity, and token processingEnabled products/countries, entity, DPA, certification or clauses, bank roles, retention, deletion and user controlsHigh
AgoraReal-time video and cloud recording capability evidencedVoice, video, screen, identity, routing, recording, and storage locationsProduction use, routing region, recording configuration, consent, contract, DPA, subprocessors, retention, deletionHigh
Electronic signatureGeneric capability evidenced; provider identity not confirmedAgreement content, signatures, identity, and audit trailName provider, entity, service, contract, DPA, location, authentication, retention, export and deletionHigh
GitHub and ActionsUse confirmedContributor data, source/configuration, workflow logs, fixtures, issue evidence, and accidental personal dataOrganization terms, DPA, region options, retention, access review, secret scanning, evidence classificationMedium
Analytics, observability, and error monitoringMonitoring and analytics capability evidenced; active provider and payload require confirmationTelemetry can unintentionally capture identifiers, content, URLs, tokens, or errors and route them globallyProvider, payload schema, redaction, sampling, location, DPA, mechanism, retention, access, and deletionMedium-High
External counsel, auditors, and respondersControlled disclosure is contemplated by governance policiesCase-specific disclosure of governance, incident, user, transaction, or security recordsRecipient, necessity, minimization, confidentiality, location, mechanism, access duration, return/deletion recordMedium-High to High

Google Cloud-specific assessment

CIC's repository evidence confirms Google App Engine deployment and Google Cloud storage capability. The public deployment endpoint supports an inference that the hosted application is in a United States region. The exact billing entity, contractual customer, storage bucket regions, backup locations, support settings, and enabled services are not established by source code.

Owner evidence must include the service inventory, project and resource regions in a controlled export, current Google Cloud Data Processing and Security Terms, applicable Google Cloud subprocessors, transfer terms, encryption settings, privileged access controls, logging, deletion, backups, and support configuration. The public report records conclusions, while the controlled evidence repository retains sensitive exports.

Financial and identity providers

Financial and identity integrations receive enhanced scrutiny because they can combine identity, national identifier, bank, wallet, payment, transaction, and compliance information. CIC must not approve all configured rails as a group. Each enabled product and country combination requires its own recipient, purpose, data-field, retention, security, incident, onward-transfer, and mechanism decision.

Minimum conditions are:

  • production activation is explicitly approved;
  • data fields are limited to the selected product requirement;
  • user notice and consent or other legal basis are documented;
  • webhook payloads are authenticated and replay-safe;
  • provider data is not duplicated into application logs;
  • credentials and secrets remain outside source control;
  • sandbox and production data are segregated;
  • deletion, account closure, reconciliation, dispute, and incident workflows are defined;
  • provider support access is time limited and recorded where available.

Communications and recordings

Email, push, SMS, voice, video, and recording providers can expose message content and metadata to global infrastructure. CIC must maintain a channel-to-provider map. Restricted identifiers, credentials, full bank data, and identity documents must not appear in notification content. Recording must default off unless a documented workflow requires it, and consent, access, storage location, retention, and deletion must be configured before use.

Subprocessor governance

For each active provider CIC must:

  • retain the approved subprocessor list and retrieval date;
  • subscribe to change notifications where available;
  • identify each subprocessor's service and country;
  • assess material additions before the objection period expires;
  • document the decision to accept, mitigate, replace, or object;
  • ensure onward-transfer obligations are no less protective than the primary contract;
  • update notices and this assessment where the change is material.

Provider change decision

ChangeRequired response
New provider or new productComplete diligence and transfer assessment before production data.
New country or remote-support locationComplete jurisdiction assessment before new Restricted-data access.
New material subprocessorAssess, approve, mitigate, or object within the contractual window.
New Restricted data or expanded purposeReassess necessity, mechanism, security, retention, and user notice.
Contract or certification expirySuspend reliance on the affected mechanism until renewed or replaced.
Material incident or government requestReassess practical risk, safeguards, and continuation decision immediately.
Provider terminationRevoke access and credentials; verify export, return, deletion, and residual backups.

Current conclusion

Repository review provides a credible starting inventory but not enough evidence for blanket provider approval. The most material gaps are the active-provider list, database identity and location, executed transfer terms, subprocessor reconciliation, workforce access countries, and recording configuration. These are tracked in the Transfer Remediation and Review Plan.

Limitation

This report was prepared with AI assistance from repository and governance evidence. Authorized vendor, privacy, security, finance, and legal owners must validate it against production and contractual evidence.