Passing the Vendor Security Review: What IT and InfoSec Ask Before Approving Anonymization Software
TL;DR: Anonymization purchases rarely fail on price or accuracy. They stall in vendor security review, waiting on answers about data flows, subprocessors and logs. Because Gallio PRO processes entirely on your own hardware and receives no footage, most of that questionnaire becomes not applicable. This guide is for DPOs, procurement leads and IT security reviewers who have to get an approval signed.
Where these purchases actually die
A team evaluates three tools, runs a pilot, picks a winner and sends it to security review. Then nothing happens for eleven weeks. The questionnaire asks where data is hosted, which subprocessors are involved, what the retention period is and whether there is a transfer mechanism outside the EEA. Nobody on the buying side can answer, because those questions assume a hosted service, and the person who can answer works for the vendor.
The fix is not a better pilot. The fix is arriving at the review with the pack already assembled, and knowing which questions genuinely do not apply to your deployment model.
The processor question decides most of the questionnaire
Under GDPR Article 4(8), a processor is a party that processes personal data on behalf of the controller. Under Article 28(3), engaging one requires a written processor agreement covering instructions, confidentiality, security, subprocessors, assistance and deletion.
A hosted redaction service receives your footage and is squarely a processor. Licensed software that runs on your own machines, where the vendor never receives the footage, is a different arrangement: the vendor supplies a tool, not a processing service. The EDPB Guidelines 07/2020 on the concepts of controller and processor turn on who determines purposes and means and who actually processes the data, which is why the deployment model, not the product category, drives the answer.
Two caveats belong in your documentation rather than in an assumption. First, if vendor support can access your systems or receive sample footage for diagnostics, that access has to be governed, and it is where a limited processor relationship can arise. Second, this is a structural point about deployment models and not legal advice on your specific arrangement, so your DPO signs it off, not the vendor.
What changes, section by section
Questionnaire section | Hosted service | On-premise software |
Hosting location and data residency | Full answer required | Your own infrastructure |
Subprocessor list | Full list and change notification | None for footage processing |
International transfers, Articles 44 to 49 | Transfer mechanism required | No transfer occurs |
Retention and deletion at the vendor | Contractual schedule required | Vendor holds no footage |
Breach notification from vendor | Timelines and channel required | Applies to your own estate |
Logging and audit trail | Vendor side logs in scope | Local footprint, no detection logs |
Support access to data | In scope | Must still be defined and limited |
That is not a loophole. It is the reason many regulated buyers choose local processing in the first place, as covered in our checklist for purchasing video anonymization software.
The seven questions that decide the review
- Does any footage leave our infrastructure at any point? With Gallio PRO the answer is no, because processing is fully local.
- What does the software write to disk, and does it contain personal data? Gallio PRO stores no detection logs and no personal data, which closes the most awkward line of questioning.
- Who at the vendor can access our systems, and under what conditions? Define it before the pilot, not after an incident.
- How are updates delivered and verified? Ask for the channel, the signing arrangement and the notification process.
- What happens to our workflow if the licence lapses or the vendor disappears? Continuity of access to already processed material matters more than most buyers assume.
- What certifications and audit reports exist? ISO/IEC 27001 and SOC 2 are commonly requested. Ask the vendor directly and record the answer rather than inferring one.
- Is a DPIA required for this processing? Under GDPR Article 35(3)(c), systematic monitoring of a publicly accessible area on a large scale triggers one, and anonymization is usually a mitigating measure inside it rather than a reason to skip it.
How to prepare the review pack in six steps
- Write the data flow diagram first. One page: where footage originates, which machine processes it, where the export goes, who receives it, when the original is destroyed. Most questionnaire answers fall out of this diagram.
- Classify the deployment model explicitly. State in writing that processing is local and that the vendor receives no personal data, then have the DPO confirm the processor analysis for your case.
- Collect vendor documentation before you need it. System requirements, deployment options, security documentation, support access terms, update process and any certifications, gathered in one folder.
- Mark the non-applicable sections and say why. Do not leave them blank. "No transfer occurs, processing is local, see data flow diagram section 2" moves faster than an empty field.
- Run the pilot on non-sensitive footage. Use the free Gallio PRO demo, which is unlimited and watermarked at up to 720p, so the evaluation itself does not need a security approval to begin.
- Attach the DPIA or the reasoned decision not to run one. Reviewers accept a documented decision. They do not accept silence.
If the surveillance system itself is also new, run it alongside our DPO checklist for implementing a video surveillance system.
The part that still needs work
Local processing removes vendor side risk. It does not remove your own. The review will, correctly, look at who can access the unredacted source on your network, how exports are transmitted to recipients, and what happens to the original afterwards under GDPR Article 5(1)(e) on storage limitation. Recipients outside the EEA bring Chapter V, Articles 44 to 49 back into play regardless of how the footage was redacted, which we cover in visual data sharing with third parties and transatlantic transfers.
One scope note that belongs in the pack rather than in a later escalation: automatic detection covers faces and license plates only. Badges, screens, documents and tattoos are handled in the built in manual editor, so the procedure has to name who performs that pass and who checks it. Reviewers respond well to a control with an owner.
What Gallio PRO brings to the file
Gallio PRO runs on Windows 10 and later, macOS 10.14 and later, and Linux with glibc 2.35 or newer, with an MSI installer for managed estates, a Docker container and Linux command line interface on the Enterprise plan, and a REST API for integration. Processing is fully local, no detection logs and no personal data are stored, and the product is used by more than 2,000 customers including large transport operators and public sector bodies. Reference customers are frequently the fastest way to shorten a review. Details and deployment options are on the Gallio PRO video anonymization page.
FAQ
Do I need a data processing agreement for on-premise anonymization software?
Usually not for the processing itself, because the vendor never receives the footage. A written arrangement is still needed for any support access to your systems or sample data. Your DPO should confirm the analysis for your deployment.
Why does vendor security review take so long for redaction tools?
Because standard questionnaires assume a hosted service. Answering the hosting, subprocessor and transfer sections with a documented data flow diagram and a clear deployment statement removes most of the delay.
Does anonymization software need a DPIA?
The surveillance processing may require one under GDPR Article 35(3)(c) for systematic large scale monitoring of publicly accessible areas. Anonymization typically appears in the DPIA as a mitigating measure.
What logs does Gallio PRO keep?
Gallio PRO stores no detection logs and no personal data. Enumerate the local file footprint during the review and place those paths under the same retention rules as the footage.
Which certifications should I ask an anonymization vendor for?
ISO/IEC 27001 and SOC 2 are the most commonly requested. Ask the vendor directly, record the response in the review file, and do not infer certification status from marketing material.