PII flows to third-party processor (verify DPA)
Part of the GDPR & privacy check · fix arrives as a guide
What it is
Personal data flows to a third-party service — analytics, support, email, error tracking — acting as a processor.
Why it matters
Each processor needs a data processing agreement, needs to appear in your privacy notice, and if it is outside the EEA needs a transfer mechanism. Error trackers are the most commonly missed, because nobody thinks of them as holding customer data.
How to fix it
List the processors receiving personal data, confirm a DPA is in place for each, and check your privacy notice names them. For anything not strictly needed, reducing what you send is simpler than papering it.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.