A metallic cloud icon with data symbols is connected to two pillars by arrows, with a padlock underneath, against a dark background.

Passing the Vendor Security Review: What IT and InfoSec Ask Before Approving Anonymization Software

Mateusz Zimoch
Published: 9/3/2026
Updated: 9/24/2026

TL;DR: Anonymization purchases rarely fail on price or accuracy. They stall in vendor security review, waiting on answers about data flows, subprocessors and logs. Because Gallio PRO processes entirely on your own hardware and receives no footage, most of that questionnaire becomes not applicable. This guide is for DPOs, procurement leads and IT security reviewers who have to get an approval signed.

Where these purchases actually die

A team evaluates three tools, runs a pilot, picks a winner and sends it to security review. Then nothing happens for eleven weeks. The questionnaire asks where data is hosted, which subprocessors are involved, what the retention period is and whether there is a transfer mechanism outside the EEA. Nobody on the buying side can answer, because those questions assume a hosted service, and the person who can answer works for the vendor.

The fix is not a better pilot. The fix is arriving at the review with the pack already assembled, and knowing which questions genuinely do not apply to your deployment model.

A hand holding a stamp presses onto a document on a desk with a pen and stack of books. The setting is in black and white.

The processor question decides most of the questionnaire

Under GDPR Article 4(8), a processor is a party that processes personal data on behalf of the controller. Under Article 28(3), engaging one requires a written processor agreement covering instructions, confidentiality, security, subprocessors, assistance and deletion.

A hosted redaction service receives your footage and is squarely a processor. Licensed software that runs on your own machines, where the vendor never receives the footage, is a different arrangement: the vendor supplies a tool, not a processing service. The EDPB Guidelines 07/2020 on the concepts of controller and processor turn on who determines purposes and means and who actually processes the data, which is why the deployment model, not the product category, drives the answer.

Two caveats belong in your documentation rather than in an assumption. First, if vendor support can access your systems or receive sample footage for diagnostics, that access has to be governed, and it is where a limited processor relationship can arise. Second, this is a structural point about deployment models and not legal advice on your specific arrangement, so your DPO signs it off, not the vendor.

A padlock placed on a laptop keyboard with swirling light trails symbolizing cybersecurity or data protection.

What changes, section by section

Questionnaire section

Hosted service

On-premise software

Hosting location and data residency

Full answer required

Your own infrastructure

Subprocessor list

Full list and change notification

None for footage processing

International transfers, Articles 44 to 49

Transfer mechanism required

No transfer occurs

Retention and deletion at the vendor

Contractual schedule required

Vendor holds no footage

Breach notification from vendor

Timelines and channel required

Applies to your own estate

Logging and audit trail

Vendor side logs in scope

Local footprint, no detection logs

Support access to data

In scope

Must still be defined and limited

That is not a loophole. It is the reason many regulated buyers choose local processing in the first place, as covered in our checklist for purchasing video anonymization software.

Two people shaking hands across a desk with a clipboard, laptop, and plant in black and white.

The seven questions that decide the review

  1. Does any footage leave our infrastructure at any point? With Gallio PRO the answer is no, because processing is fully local.
  2. What does the software write to disk, and does it contain personal data? Gallio PRO stores no detection logs and no personal data, which closes the most awkward line of questioning.
  3. Who at the vendor can access our systems, and under what conditions? Define it before the pilot, not after an incident.
  4. How are updates delivered and verified? Ask for the channel, the signing arrangement and the notification process.
  5. What happens to our workflow if the licence lapses or the vendor disappears? Continuity of access to already processed material matters more than most buyers assume.
  6. What certifications and audit reports exist? ISO/IEC 27001 and SOC 2 are commonly requested. Ask the vendor directly and record the answer rather than inferring one.
  7. Is a DPIA required for this processing? Under GDPR Article 35(3)(c), systematic monitoring of a publicly accessible area on a large scale triggers one, and anonymization is usually a mitigating measure inside it rather than a reason to skip it.
Person using a laptop displaying a VPN screen with a map, next to a smartphone and glasses on a table.

How to prepare the review pack in six steps

  1. Write the data flow diagram first. One page: where footage originates, which machine processes it, where the export goes, who receives it, when the original is destroyed. Most questionnaire answers fall out of this diagram.
  2. Classify the deployment model explicitly. State in writing that processing is local and that the vendor receives no personal data, then have the DPO confirm the processor analysis for your case.
  3. Collect vendor documentation before you need it. System requirements, deployment options, security documentation, support access terms, update process and any certifications, gathered in one folder.
  4. Mark the non-applicable sections and say why. Do not leave them blank. "No transfer occurs, processing is local, see data flow diagram section 2" moves faster than an empty field.
  5. Run the pilot on non-sensitive footage. Use the free Gallio PRO demo, which is unlimited and watermarked at up to 720p, so the evaluation itself does not need a security approval to begin.
  6. Attach the DPIA or the reasoned decision not to run one. Reviewers accept a documented decision. They do not accept silence.

If the surveillance system itself is also new, run it alongside our DPO checklist for implementing a video surveillance system.

Person working at a desk with multiple computer screens displaying lines of code in a dimly lit room.

The part that still needs work

Local processing removes vendor side risk. It does not remove your own. The review will, correctly, look at who can access the unredacted source on your network, how exports are transmitted to recipients, and what happens to the original afterwards under GDPR Article 5(1)(e) on storage limitation. Recipients outside the EEA bring Chapter V, Articles 44 to 49 back into play regardless of how the footage was redacted, which we cover in visual data sharing with third parties and transatlantic transfers.

One scope note that belongs in the pack rather than in a later escalation: automatic detection covers faces and license plates only. Badges, screens, documents and tattoos are handled in the built in manual editor, so the procedure has to name who performs that pass and who checks it. Reviewers respond well to a control with an owner.

What Gallio PRO brings to the file

Gallio PRO runs on Windows 10 and later, macOS 10.14 and later, and Linux with glibc 2.35 or newer, with an MSI installer for managed estates, a Docker container and Linux command line interface on the Enterprise plan, and a REST API for integration. Processing is fully local, no detection logs and no personal data are stored, and the product is used by more than 2,000 customers including large transport operators and public sector bodies. Reference customers are frequently the fastest way to shorten a review. Details and deployment options are on the Gallio PRO video anonymization page.

A pencil and eraser next to a sketch of a lightbulb with a question mark inside, symbolizing a creative or innovative question.

FAQ

Do I need a data processing agreement for on-premise anonymization software?

Usually not for the processing itself, because the vendor never receives the footage. A written arrangement is still needed for any support access to your systems or sample data. Your DPO should confirm the analysis for your deployment.

Why does vendor security review take so long for redaction tools?

Because standard questionnaires assume a hosted service. Answering the hosting, subprocessor and transfer sections with a documented data flow diagram and a clear deployment statement removes most of the delay.

Does anonymization software need a DPIA?

The surveillance processing may require one under GDPR Article 35(3)(c) for systematic large scale monitoring of publicly accessible areas. Anonymization typically appears in the DPIA as a mitigating measure.

What logs does Gallio PRO keep?

Gallio PRO stores no detection logs and no personal data. Enumerate the local file footprint during the review and place those paths under the same retention rules as the footage.

Which certifications should I ask an anonymization vendor for?

ISO/IEC 27001 and SOC 2 are the most commonly requested. Ask the vendor directly, record the response in the review file, and do not infer certification status from marketing material.

Mateusz Zimoch

CEO and Co-Founder of Gallio PRO, is an engineer with extensive expertise in Computer Science, Data Science, Robotics, and Artificial Intelligence. Mateusz graduated with dual majors from the Wrocław University of Technology and launched two startups centered on developing AI-powered Computer Vision solutions and constructing Remote Operated Vehicles (ROVs).