Skip to content

Your customer is a Flemish local authority and sends the VTC questionnaire

Do you supply software or services to a Flemish municipality, OCMW or other local authority, and process personal data while doing so? Then you may receive the information security questionnaire for processors (vragenlijst informatieveiligheid verwerkers) of the Flemish Supervisory Commission (VTC). You answer it per processing activity, with evidence.

Why you receive this questionnaire

The VTC sent the questionnaire with a letter (reference VTC/A/2023/09) to local authorities and agencies. It followed a report by Audit Vlaanderen of 13 June 2023 on ICT risk management at local authorities, and data breaches where security at suppliers turned out not to be arranged or not to be followed.

With the questionnaire, the authority checks whether you as a processor meet the minimum security obligations. That tells it whether it can keep working with you, and helps it show compliance with Articles 28, 29 and 32 of the GDPR.

Is it mandatory?

Not for the authority. But the VTC “strongly” recommends using it, expects authorities to be able to answer all of its questions, and announced that from 2025 it would ask, when a data breach is reported, whether the questionnaire was used. In practice you will receive it more and more often.

What it covers

The questions cover the basic GDPR security requirements: technical and organisational measures. They are based on simplified, consolidated ISO standards. Two things make this list different from an ordinary supplier questionnaire:

What happens with your answers

According to the letter, an authority must stop the processing in case of serious deviations or high risks. For significant or medium deviations, an alternative must be found within six months. A weak answer can cost you a customer.

How to approach it

  1. Ask which processing activities the authority links to you. Check that this matches your data processing agreement.
  2. Gather your evidence up front. Policies, access management, logging, backups, incident procedure, your sub-processors and where the data is stored.
  3. Answer per processing activity. If your measures are the same for all of them, say so, but name any differences explicitly.
  4. Refer to the evidence in every answer. A document, a setting or a report.
  5. Be honest about gaps. An open item with a plan and a date is stronger than a “yes” that turns out to be wrong after a data breach.

How Holdvero helps

We complete the questionnaire based on your own documentation, with the source for every answer. Where evidence is missing, we write an open item instead of a “yes”. Up to 150 questions this falls under Questionnaire Rescue (€695, 3–5 working days). If many processing activities are involved, it becomes a complex questionnaire with a fixed price after a short check. Holdvero does not provide certification or legal advice.

Frequently asked questions

Does this also apply to Dutch suppliers?

Yes. It depends on the customer, not on where you are based. If you supply a Flemish local authority and process personal data, you may receive the questionnaire.

Do I fill in a separate questionnaire for each processing activity?

You answer per processing activity. If your measures are the same for all of them you can say so, but the authority may ask for clarification where processing activities overlap.

What evidence should I have ready?

Documents that show your measures: policies, procedures, settings, reports and agreements with your sub-processors. The VTC expects you to have these ready.

Where can I find more information?

On the VTC page for local authorities (in Dutch) and in the accompanying letter.

Need help with the VTC questionnaire?

Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.

Get a fixed price
Cover: NIS2 checklist for suppliers
Free: NIS2 checklist for suppliersThe 7 topics that keep coming back, with the evidence to have ready for each.
Download the checklist