Vendor compliance

You know your vendors. Not their register.

The UK data vendor landscape is already mapped: what each vendor trades, who they sell it to and the credentials they hold, as documented. You query the database, one name at a time, and read the record.

CredentialsWhat they tradeRegistered purposesSignals

The vendor record

What we hold on a vendor.

One record per vendor, the same fields on every name. You read it in the order that matters: what they trade and who they sell it to, then what their entry says they registered to do.

Registration

Whether the vendor is registered with the ICO, and the purposes the entry states. The purposes are the part nobody reads, and they are the part that decides whether the product on sale was ever registered for.

Security credentials

SOC 2 Type I or Type II, ISO 27001, ISO 27701, Cyber Essentials and Cyber Essentials Plus, each carried as its own field on the record.

Data protection posture

Published privacy notice, named DPO and the lawful basis the vendor states for what it trades, against UK GDPR and DPA 2018.

Phone data only

PECR relevance

Carried only where the vendor trades phone data, because that is the only place PECR reaches. Where a vendor sells none, the field stays empty.

What they trade

The data the vendor sells, the categories and verticals it covers and who they sell it to. This is the column the registered purposes get read against.

Read on the landscape

Signals

We read early movement across the vendor landscape, and that reading is carried on the analysis side rather than folded into one name here. A lookup returns what a vendor's own sources document. The signals want the whole landscape in view.

Supply chain analysis

Registered for what they sell

Where the register and the price list disagree.

An ICO entry states the purposes a vendor registered for. The price list states what they sell. The distance between the two is the one thing on the record worth reading.

Purposes
Registered

The entry states marketing and staff administration.

Selling

A credit referencing feed sits on the price list.

Data subjects
Registered

The entry names customers and employees.

Selling

The dataset on sale is built on company directors.

Data classes
Registered

Personal details and employment detail.

Selling

Financial detail is priced as a separate product.

Recipients
Registered

No disclosure to third parties is stated.

Selling

The product is resold through two named partners.

Overseas transfers
Registered

The entry states none.

Selling

Enrichment and support run outside the UK.

Illustrative fields.

How a lookup runs

Open the database. Type the name.

01

Search the name

Open the vendor database and type it. Nothing to prepare, no ticket and no onboarding call standing between you and the record. The mapping is already done.

02

Read what we hold against them

Both sides on one screen, so you read them against each other rather than across two tabs. The reading takes a minute and it is the whole job.

03

Take the record out

The vendor record leaves with you: the documented values, the sources behind them and the mismatches we named, exported as a CSV or pulled through the API. What you found on one name goes to legal, to procurement or into the file, without a screenshot.

What we return, and what we won't

What comes back is the evidence.

Every value traces to a documented public source, so your team can defend it line by line. The purposes the entry states, the thing on the price list and the distance between the two.

Returned

What we hold, per vendor

Register entry and stated purposes. Security credentials, field by field. Privacy notice, named DPO and stated lawful basis. PECR relevance where phone data is on the price list. The same fields on every name.

No pass. No fail.

We don't judge your vendor and we don't return a verdict on one. We hand you what they're registered for, what they're selling and the gap between them.

Returned

The discrepancy itself

Where the registered purposes do not reach the thing on the price list, named, with both values side by side on the field they disagree on.

No score you can't interrogate

There is no rating, no index and no number standing in for the evidence. The discrepancy itself is the output, and you read it rather than a summary of it.

Returned

Where the record is silent

Not documented comes back as not documented. A credential we cannot evidence is never written up as one the vendor does not hold.

The decision stays yours

Nothing on the record tells you to drop a vendor or keep one. You remain the controller for anything you do next, and we say so in public rather than in a footnote.

FAQ

Frequently asked questions

Where does the vendor information come from?

We map the UK data vendor landscape ourselves, so the record is there before you look. The values come from the ICO register and the purposes an entry states, the vendor's own published privacy notice and the certifications they evidence in public.

On what basis do you hold records on other data vendors?

Peach Data is registered with the ICO as a data controller and processes under Article 6(1)(f) of the UK GDPR, legitimate interests. A vendor record is built from what the vendor itself put in public. Where a record names a person, it names them in the role the vendor published. Full registration and policy detail sits on our compliance page.

How current is a vendor record?

Each value carries the date we read its source, and it traces back to the source it came from. The sources are public, so you can hold any value against the live entry yourself.

Do you return a named contact on a vendor?

A named DPO where the vendor publishes one, and the contact route their privacy notice states. Both sit on the vendor record because the vendor documented them itself, not because we sourced them for you. They are documented fields, not an instruction.

Can I see a vendor record before committing?

Yes. We open a live record on the call and walk it field by field, on a vendor you already work with rather than a sample we picked. You judge the record against a company you know before anything is signed.

Get started

Name three of your vendors.

Bring three names to the call and we'll pull what we hold against them.