Answering a privacy questionnaire as a processor
Do you process personal data for a customer, for example because your software stores customer data? Then under the GDPR you are usually a processor, and your customer must be able to show it chose a processor with sufficient guarantees. That is why you get a privacy questionnaire, often together with the data processing agreement.
What is almost always in it
| Topic | Typical question |
|---|---|
| Role and DPA | Are you a processor? Is there a data processing agreement under Article 28 GDPR? |
| Sub-processors | Which sub-processors do you use, and how do you announce a new one? |
| Location and transfers | Where is the data? Does it leave the EEA, and on what basis? |
| Security | Which technical and organisational measures do you take (Article 32)? |
| Personal data breaches | How quickly do you notify the customer of a breach? |
| Data subject rights | How do you help with access, correction and deletion requests? |
| Retention and deletion | How long do you keep data, and what happens at the end of the contract? |
| Audits | May the customer check that you keep to the agreements? |
The most important rule: one story
Your privacy notice, data processing agreement, sub-processor list and questionnaire answers must say the same thing. A buyer or privacy officer will put them side by side. If the questionnaire says “data stays in the EU” and your sub-processor list shows a US service without explanation, you have a problem.
Evidence to have ready
- your standard data processing agreement
- a current sub-processor list, with service, country and transfer basis
- a description of your technical and organisational measures
- your data breach procedure and how fast you inform the customer
- your retention periods and what happens to data at the end of the contract
- your record of processing for the processing you do on behalf of customers
How to approach it
- Determine your role per processing activity. Usually you are a processor, but for some data (your own billing or product analytics, for example) you may be a controller. Say so honestly.
- Check your sub-processors. Hosting, email, support tools and AI services all count.
- Be precise about transfers. Name the country and the basis, such as standard contractual clauses or an adequacy decision.
- Only promise deadlines you can meet. The GDPR requires a processor to report a breach “without undue delay”. Agree a period you will actually meet.
- Check everything against your DPA. Answers and contract must match.
How Holdvero helps
We complete the privacy questionnaire based on your own documentation, with the source for every answer, and flag where your answers and your data processing agreement contradict each other. Up to 150 questions this falls under Questionnaire Rescue (€695, 3–5 working days). Holdvero does not provide legal advice; have your data processing agreement reviewed by a lawyer.
Frequently asked questions
Am I a processor or a controller?
If you process data on behalf of and on the instructions of your customer, you are usually a processor. If you decide the purpose yourself, you are a controller. It can differ per processing activity; get legal advice in doubtful cases.
Do I have to publish a sub-processor list?
You must inform your customer about your sub-processors and about changes. Many suppliers publish the list on their website for that reason. It saves questions.
How fast must I report a data breach to my customer?
Without undue delay, says the GDPR. Your customer must in principle report to the supervisory authority within 72 hours, so agree a short, achievable period.
Are AI services sub-processors?
If an AI service processes your customer's personal data, it is generally a sub-processor. Include it in your list.
Need help with a privacy questionnaire?
Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.
Get a fixed price