Skip to content
DPAFlow

vendor-risk

Vendor Privacy Questionnaire: Questions to Ask Before Contracting

Most vendor privacy questionnaires are too long and ask questions that cannot discriminate between suppliers. The questions that earn their place, why each one works, and how to read the answers you get back.

Most vendor privacy questionnaires are too long and ask the wrong things. They run to eighty questions, take a supplier's compliance team a week to answer, and produce a document nobody reads because the answers are uniformly reassuring. A shorter questionnaire built around questions that actually discriminate between suppliers is more useful and more likely to be answered honestly.

This article sets out the questions worth asking, why each one earns its place, and how to read the answers. The wider examination the questionnaire feeds into is covered in our GDPR vendor due diligence checklist.

What a questionnaire is for

Be clear about the job. A questionnaire is an efficient way to collect the supplier's own account of its processing, in a comparable format, with a named person standing behind it. It is not verification. Answers become evidence of what the supplier told you, on a date, which is genuinely useful when something later turns out to be otherwise.

Two consequences follow. Ask questions whose answers you could check if you needed to, and prefer questions that force a specific fact over questions that invite a policy statement.

Questions that discriminate

Roles and scope

  • For the service we are buying, are you acting as a processor on our instructions, or as a controller for any part of the processing?
  • If you act as a controller for any purpose, which purposes, and on what basis?
  • What categories of personal data will you process for us, and about whom?

The second question is the one suppliers most often answer revealingly. Many act as controller for a narrow adjacent purpose such as service analytics, and a supplier that has thought about this will say so precisely. One that has not will say "processor" and leave you to discover the rest.

Sub-processors

  • Where is your current sub-processor list published, and is it complete?
  • Which sub-processors process outside the European Economic Area, and in which countries?
  • Do you include your own group companies in that list?
  • What notice do you give before engaging a new sub-processor, through what channel, and to whom?
  • What is the objection window, and what happens if a customer objects?

The group-companies question is the highest-yield item in most questionnaires. Intra-group processing is where third-country access frequently sits, and it is routinely omitted from published lists. Our article on evaluating a sub-processor list covers how to read the answer.

Transfers

  • Where is the data stored, by region and country?
  • From which countries can your staff or contractors access it, including support and engineering?
  • For each destination outside the European Economic Area, what transfer mechanism applies?
  • If you rely on an adequacy decision, does it cover the specific entity and the specific data?
  • Will you provide the information we need to conduct and maintain a transfer assessment?

Separating storage from access is what makes this section useful. Data resident in an EU region that support staff elsewhere can read is a transfer, and a questionnaire that asks only about storage will miss it. Our international data transfer checklist covers the follow-through.

Security

  • What technical and organizational measures protect the data, described specifically?
  • Do you hold independent third-party assurance, and will you share the report under a confidentiality obligation?
  • How is internal access to customer data controlled and logged?
  • Is the data encrypted in transit and at rest, and who controls the keys?
  • What is your incident notification trigger and timescale to customers?

Ask for the assurance report rather than the badge. A supplier willing to share the report, including its scope and exceptions, is telling you more than one that lists an achievement.

Rights, retention, and exit

  • How do you assist with data subject access, rectification, erasure, and portability requests, and within what time?
  • What retention periods apply, and are they configurable by us?
  • On termination, do you return or delete the data, on what deadline, and how are backups handled?
  • Will you provide written confirmation of deletion?

Governance

  • Who is accountable for data protection in your organization, and how do we reach them?
  • Have you had a personal data breach affecting customer data in the last twenty-four months, and what changed as a result?
  • Have you been subject to a supervisory authority investigation relating to personal data?

The breach question works better with a defined period and a follow-up about remediation. A supplier that describes an incident and what it changed is usually a better counterparty than one that reports an unblemished record.

How to read the answers

Three patterns are worth noticing.

Specificity tracks maturity. Suppliers that answer with entity names, countries, and timescales generally operate the controls they describe. Suppliers that answer with adjectives generally do not, whatever the underlying reality.

Refusals are informative. A supplier that will not name its sub-processors or share an assurance report has told you something about how the relationship will run once you are dependent on it.

Silence on scope is a finding. If a supplier cannot describe what data it will hold for you, the problem is usually that nobody has thought about it, and that is worth resolving before signature rather than after.

Keep the answers as evidence

Store the completed questionnaire with the date, the version of the questions, and the name and role of the person who answered. Capture the supporting pages the supplier pointed you at rather than only linking to them, because those pages change. Our article on audit-ready vendor evidence covers what makes the file defensible.

Frequently asked questions

How long should the questionnaire be?

Short enough to be answered properly. Twenty to thirty questions, scaled by tier, will out-perform eighty generic ones. Reserve depth for higher-tier vendors, as set out in prioritizing vendors for privacy review.

Can we accept a supplier's standard security pack instead?

Often yes, if it answers your questions. Read it against your list and ask only about the gaps. Insisting on your own format for its own sake wastes goodwill you may need later.

Does a completed questionnaire discharge our obligations?

No. Article 28(1) of the General Data Protection Regulation (GDPR) requires the controller to use only processors providing sufficient guarantees. A questionnaire is evidence gathered towards that judgment, not the judgment itself.

Should we re-issue it periodically?

For higher-tier vendors, yes, but concentrate on what changes: the sub-processor list, the transfer position, and any incidents. Re-asking settled questions annually produces effort without information.

Where DPAFlow fits in

A questionnaire captures a moment. The answers with the shortest shelf life are the sub-processor list and the transfer position, and both change on the supplier's website rather than in your inbox. DPAFlow checks vendor sub-processor lists, Data Processing Agreement pages, and trust-center pages on a scheduled, recurring basis, records what changed with dated evidence including captured page text and change differences, and sends email alerts. Detected changes enter a review workflow where your team documents its assessment.

DPAFlow does not score suppliers, complete questionnaires, or provide legal advice. How teams in procurement and vendor risk use it is described on the vendor risk use case page.

This article proposes a questionnaire design. It is not legal advice, and the sufficiency judgment belongs to your privacy function and counsel.

DPAFlow · 2026-07-25

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow