Merion

Vendor & Sub-Processor Due Diligence

How Merion assesses and manages third-party vendors and sub-processors who handle personal information on its behalf.

Why vendor due diligence matters

When Merion uses third-party services that process personal information, Merion remains accountable for how that information is handled. Under Australian Privacy Principle 11, Merion must take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access — and this obligation extends to the vendors and sub-processors Merion engages. Selecting vendors without appropriate scrutiny, or failing to impose contractual obligations on them, would be inconsistent with that duty.

Vendor categories that handle personal information

Merion uses vendors across the following categories in connection with personal data processing:

  • Cloud infrastructure: hosting, storage, and content delivery.
  • Error monitoring: crash reporting and application error tracking.
  • Payment processing: card and direct debit payment handling.
  • Email and SMS delivery: transactional communications to debtors and clients.
  • Identity and authentication: the OIDC single sign-on layer.

The current list of named sub-processors, including the data they process and their locations, is published at trust.merion.com.au/sub-processors/.

Vendor assessment process

Before engaging a new vendor that will process personal information, Merion conducts a pre-engagement review that covers the following areas:

  • Privacy and data processing: review of the vendor's privacy policy, data processing agreement (DPA), and sub-processor disclosures.
  • Security posture: relevant certifications (SOC 2 Type II, ISO 27001), published audit reports, or equivalent evidence of security controls. Where certifications are not available, Merion reviews publicly available security documentation.
  • Data location and cross-border transfers: whether the vendor will process data inside or outside Australia, and — where data is processed offshore — the mechanisms in place to ensure the APPs are respected (APP 8 compliance).
  • Breach notification: the vendor's obligations and timelines for notifying Merion of a security incident or data breach affecting Merion's data.
  • Sub-processor chain: whether the vendor engages further sub-processors and, if so, under what controls and with what disclosure obligations.

Data processing agreements

Merion requires a data processing agreement (DPA) or equivalent contractual commitment from any vendor that processes personal information. The DPA specifies:

  • The scope and purpose of processing — vendors may not use Merion's data for their own purposes.
  • Data security requirements appropriate to the sensitivity of the information.
  • Breach notification timelines — vendors must notify Merion promptly on becoming aware of an incident.
  • Obligations on deletion or return of data when the engagement ends.
  • The vendor's obligations with respect to their own sub-processors.

Ongoing monitoring

Vendor relationships are reviewed periodically rather than assessed once at onboarding and never revisited. Merion monitors for material changes to a vendor's privacy and security posture — including ownership changes, reported breaches, significant policy updates, or loss of certification. Where a change is material, Merion reassesses the vendor relationship and, if necessary, updates its DPA or transitions to an alternative provider.

Complaints and concerns

Merion is the primary point of contact for all privacy matters involving personal information it holds, including matters relating to sub-processors. If you have a concern about how a Merion sub-processor handles personal information that Merion has shared with them, please contact Merion directly:

Related pages

See Sub-Processors for the current list of named vendors. For Merion's APP 11 obligations, see Security of Personal Information.

Get started

Ready to talk to Merion?

Whether you have accounts to recover or a question about a notice, the first conversation is always obligation-free.