THD-001 · Third Parties & Integrations
Review enabled subprocessors and client authorisation
No service provider should receive Customer Data unless required, contractually protected and authorised/disclosed.
Critical
Due 15 Nov 2026, 12:00 AM
Contractual Requirement and Action Plan
BIZ-2026-00004
DSB law group
DSB law group
DPA / Subprocessor Schedule
Yash Agarwal
finwellrowth@gmail.com
Finwell
finwellrowth@gmail.com
Finwell
15 Nov 2026, 12:00 AM
Not Sent
Not uploaded
Internal Action Points
Review providers, purpose, data, location, contract, DPA and incident contact.
Evidence Required
Quarterly subprocessor register.
Prepared Client Communication
Not SentUpload Compliance Evidence
Update Control Record
Why This Is a Risk
Due in 77 day(s)Risk classification considers contractual severity, current status and time remaining. Red items require immediate action and evidence-based closure.
22 Aug 2026, 11:37 AM
—
Quarterly
2026-11-15
Complete Activity Trail
No activity recorded.
