Source code Security & compliance Code quality

PII flows to third-party processor (verify DPA)

Part of the GDPR & privacy check · fix arrives as a guide

What it is

Personal data flows to a third-party service — analytics, support, email, error tracking — acting as a processor.

Why it matters

Each processor needs a data processing agreement, needs to appear in your privacy notice, and if it is outside the EEA needs a transfer mechanism. Error trackers are the most commonly missed, because nobody thinks of them as holding customer data.

How to fix it

List the processors receiving personal data, confirm a DPA is in place for each, and check your privacy notice names them. For anything not strictly needed, reducing what you send is simpler than papering it.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.