Vendor compliance
You know your vendors. Not their register.
The UK data vendor landscape is already mapped: what each vendor trades, who they sell it to and the credentials they hold, as documented. You query the database, one name at a time, and read the record.
The vendor record
What we hold on a vendor.
One record per vendor, the same fields on every name. You read it in the order that matters: what they trade and who they sell it to, then what their entry says they registered to do.
Registration
Whether the vendor is registered with the ICO, and the purposes the entry states. The purposes are the part nobody reads, and they are the part that decides whether the product on sale was ever registered for.
Security credentials
SOC 2 Type I or Type II, ISO 27001, ISO 27701, Cyber Essentials and Cyber Essentials Plus, each carried as its own field on the record.
Data protection posture
Published privacy notice, named DPO and the lawful basis the vendor states for what it trades, against UK GDPR and DPA 2018.
PECR relevance
Carried only where the vendor trades phone data, because that is the only place PECR reaches. Where a vendor sells none, the field stays empty.
What they trade
The data the vendor sells, the categories and verticals it covers and who they sell it to. This is the column the registered purposes get read against.
Signals
We read early movement across the vendor landscape, and that reading is carried on the analysis side rather than folded into one name here. A lookup returns what a vendor's own sources document. The signals want the whole landscape in view.
Supply chain analysis→Registered for what they sell
Where the register and the price list disagree.
An ICO entry states the purposes a vendor registered for. The price list states what they sell. The distance between the two is the one thing on the record worth reading.
The entry states marketing and staff administration.
A credit referencing feed sits on the price list.
The entry names customers and employees.
The dataset on sale is built on company directors.
Personal details and employment detail.
Financial detail is priced as a separate product.
No disclosure to third parties is stated.
The product is resold through two named partners.
The entry states none.
Enrichment and support run outside the UK.
Illustrative fields.
How a lookup runs
Open the database. Type the name.
Search the name
Open the vendor database and type it. Nothing to prepare, no ticket and no onboarding call standing between you and the record. The mapping is already done.
Read what we hold against them
Both sides on one screen, so you read them against each other rather than across two tabs. The reading takes a minute and it is the whole job.
Take the record out
The vendor record leaves with you: the documented values, the sources behind them and the mismatches we named, exported as a CSV or pulled through the API. What you found on one name goes to legal, to procurement or into the file, without a screenshot.
What we return, and what we won't
What comes back is the evidence.
Every value traces to a documented public source, so your team can defend it line by line. The purposes the entry states, the thing on the price list and the distance between the two.
What we hold, per vendor
Register entry and stated purposes. Security credentials, field by field. Privacy notice, named DPO and stated lawful basis. PECR relevance where phone data is on the price list. The same fields on every name.
No pass. No fail.
We don't judge your vendor and we don't return a verdict on one. We hand you what they're registered for, what they're selling and the gap between them.
The discrepancy itself
Where the registered purposes do not reach the thing on the price list, named, with both values side by side on the field they disagree on.
No score you can't interrogate
There is no rating, no index and no number standing in for the evidence. The discrepancy itself is the output, and you read it rather than a summary of it.
Where the record is silent
Not documented comes back as not documented. A credential we cannot evidence is never written up as one the vendor does not hold.
The decision stays yours
Nothing on the record tells you to drop a vendor or keep one. You remain the controller for anything you do next, and we say so in public rather than in a footnote.
FAQ
Frequently asked questions
Where does the vendor information come from?
We map the UK data vendor landscape ourselves, so the record is there before you look. The values come from the ICO register and the purposes an entry states, the vendor's own published privacy notice and the certifications they evidence in public.
On what basis do you hold records on other data vendors?
Peach Data is registered with the ICO as a data controller and processes under Article 6(1)(f) of the UK GDPR, legitimate interests. A vendor record is built from what the vendor itself put in public. Where a record names a person, it names them in the role the vendor published. Full registration and policy detail sits on our compliance page.
How current is a vendor record?
Each value carries the date we read its source, and it traces back to the source it came from. The sources are public, so you can hold any value against the live entry yourself.
Do you return a named contact on a vendor?
A named DPO where the vendor publishes one, and the contact route their privacy notice states. Both sit on the vendor record because the vendor documented them itself, not because we sourced them for you. They are documented fields, not an instruction.
Can I see a vendor record before committing?
Yes. We open a live record on the call and walk it field by field, on a vendor you already work with rather than a sample we picked. You judge the record against a company you know before anything is signed.
Get started
Name three of your vendors.
Bring three names to the call and we'll pull what we hold against them.