Use when a third-party service, SDK, script, API or dependency is about to be added to a product, when an existing integration needs a data-protection sign-off, or when someone asks whether a vendor is "GDPR compliant". Also use when a sub-processor list changes, when a vendor announces a new region or a new owner, when an AI or LLM API is wired into a product, and before any launch that ships a tag, pixel, embed or telemetry SDK.