Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should teams check when third parties can…
Governance, Ownership & Risk

What should teams check when third parties can access EU personal data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Check whether third-party access is purpose-limited, reviewed regularly, and removed when the relationship ends or the task changes. Teams should also verify that transfer controls, processor agreements, and access records line up. If the entitlement exists outside those controls, the organisation has a governance gap, not just a vendor management issue.

What Third-Party Access Review Should Prove

When third parties can access EU personal data, the key question is not just whether access exists, but whether the access is justified, bounded, and auditable for the whole period it is active. Teams should be able to show who can access what, under which purpose, and under which legal and contractual basis. That is the practical test for lawful governance, not a static vendor checklist.

Purpose limitation matters because third-party access often expands quietly over time. The reviewer should confirm that the access granted still matches the original processing purpose and that the entitlement is narrowed to the minimum needed. If the access pattern no longer matches the stated task, the control has already drifted.

A useful supporting check is whether the access model aligns with documented privacy controls and third-party governance guidance, such as the Identity Data Privacy and Consent Guide and the Third-Party, B2B and Contractor Access Guide.

How to Judge Whether the Entitlement Is Still Legitimate

Regular review should test more than whether the account is active. Teams should confirm that the third party still needs access, the scope is still appropriate, and the access owner can explain why the entitlement exists. A good review process also checks whether the access is time-bound, whether a named sponsor remains accountable, and whether the account has been used within the intended boundaries.

Access that survives a contract change, scope change, or offboarding event is a strong signal that governance has weakened. The entitlement may look harmless if no abuse is visible, but stale access is still an exposure because it preserves a path into personal data after the original business need has disappeared. This is especially important where a third party is connected through integrations or delegated credentials that are easy to forget.

For teams working with connected services and tokens, the review should also account for the way third-party access can persist through authorization chains rather than only through a named user account. Breaches involving OAuth tokens and vendor-managed access, including Salesloft OAuth token breach and GitHub OAuth token breach 2022, show how third-party access can outlive the relationship that created it.

Records, Contracts, and Transfer Controls Must Tell the Same Story

For EU personal data, the access review should reconcile four things: the actual entitlement, the processor or vendor agreement, the transfer safeguards, and the access records. If those sources disagree, the organisation does not just have a documentation problem. It has a governance mismatch that can create unlawful processing, uncontrolled disclosure, or difficulty proving accountability later.

The strongest practice is to make the record set mutually validating. The agreement should describe the role and permitted processing, the transfer controls should match the data route and jurisdictional exposure, and the access register should show the live entitlement set. If any one of those says the access is gone but the others still show it as live, the team should treat that as an unresolved control failure, not as a clerical inconsistency.

Where third-party access is tied to broader vendor risk, it is also worth checking whether the same governance gap appears across multiple systems or credentials. A general access governance view from IAM and IGA Basics helps teams connect entitlement review, lifecycle control, and access certification into one operating model.

Risk and Threat Considerations

Third-party access to EU personal data creates a blended risk of privacy non-compliance, weak accountability, and unintended disclosure. The main failure mode is entitlement drift: access remains active after the task ends, the contract changes, or the data flow moves to a different processor path. In practice, that is where lawful access becomes stale access.

Failure mechanism: The organisation loses alignment between business purpose, access entitlement, and transfer documentation, so a third party can keep reaching personal data after the original justification has expired.

Impact: The result can be unlawful processing, overexposure of personal data, failed audit evidence, and slower containment if the third party relationship later becomes the source of a breach or dispute.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles relating to processing of personal dataThird-party access to EU personal data must stay purpose-limited and accountable.
Art. 28 — ProcessorProcessor terms govern vendor access to personal data and required controls.
Art. 32 — Security of processingAccess controls and review cadence are part of protecting personal data in practice.
Recommendation — Apply Art. 5 to keep third-party access purpose-limited, minimised, and defensible. Use Art. 28 terms to bind processor access, subprocessors, and deletion duties. Enforce Art. 32 controls to restrict, review, and remove third-party access.
ISO/IEC 27001:2022A.5.15 — Access controlThird-party access requires controlled, reviewed entitlement management.
Recommendation — Apply A.5.15 to approve, restrict, and periodically review external access.

Practitioner Guidance

What to verify: Verify that every third-party entitlement has a named business owner, a current purpose, a review date, and a clear removal trigger. If the access cannot be tied back to a current task or processor obligation, treat it as suspect even if no incident has occurred.

Decision rule: If the third party no longer needs the data to perform an agreed service, remove or narrow access first, then reconcile the contract and records. Do not leave access in place while waiting for a future review cycle.

Practitioner takeaway: The real test is whether the access, the contract, and the data-transfer path still describe the same relationship, because once they diverge, the organisation has already lost governance over that entitlement.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org