Sharing personal data with a third-party organisation?
Supplier due diligence is about the contracts between controllers and processors. As a controller you determine the purpose and means of the processing (Article 4 (7)) and are responsible for ensuring processors (i.e. suppliers and third-parties) have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk for any data processed.
