Answer DPDP Questionnaire — How to Respond to Client Security Checks
A practical walkthrough of the 8 questions enterprise clients ask IT vendors about DPDP compliance — with answer frameworks for each.
The questionnaire arrives from your client's procurement or legal team. It has anywhere from 20 to 60 questions, many of them specifically about DPDP compliance. Your sales team escalates it to legal. Legal escalates it to IT. IT doesn't know what a Data Processing Agreement is. Three weeks pass. The deal is still in limbo.
This is one of the most common friction points in enterprise B2B sales in India right now, and it is almost entirely avoidable. The questions are largely predictable. The answer frameworks are learnable. What the client actually wants to see is not a flawless compliance programme — it is evidence that you have thought carefully about data protection and have coherent processes in place.
Here are the eight question categories that appear consistently across DPDP vendor questionnaires, along with the approach to answering each one effectively.
Question 1: What categories of personal data do you process on our behalf?
Answer framework: Be specific and exhaustive. Don't write "standard employee data" — write "employee names, work email addresses, payroll amounts, bank account details, leave records, and performance scores." Categorise by sensitivity: standard personal data vs. sensitive personal data (financial, health, biometric). State which categories you do NOT process. If you are a B2B SaaS and only see pseudonymised IDs, say so clearly — this is a genuinely reassuring answer.
What to avoid: Vague language like "various types of personal information as required." This signals that you haven't actually mapped your data, which is the first red flag reviewers look for.
Question 2: What is your legal basis for processing this data?
Answer framework: Under the DPDP Act, the primary legal bases are consent and legitimate use (which covers employment contracts, legal obligations, state functions, and a few other specified grounds). As a Data Processor, your legal basis is derived from your contract with the Data Fiduciary (your client). State this explicitly: "As a Data Processor, we process personal data solely on the documented instructions of the Data Fiduciary under the Data Processing Agreement. We do not determine the purpose or means of processing independently." Then note any processing you do on your own behalf (e.g., your own employee data) and the basis for that.
Question 3: Do you maintain a data inventory or Record of Processing Activities?
Answer framework: Either answer honestly — yes or in progress. If yes, describe the format briefly (a spreadsheet, a GRC tool, a data flow diagram) and what it covers: data categories, systems, data owners, legal basis, retention periods, and third-party recipients. If it is in progress, state the expected completion date and what is already covered. Do not claim a comprehensive inventory if you don't have one — auditors and due-diligence teams often follow up with requests to share excerpts. A credible "in progress" answer with a timeline beats a false "yes" that collapses under follow-up.
Question 4: What is your breach notification timeline and process?
Answer framework: This is one of the highest-weighted questions in most questionnaires. Provide a specific timeline: "We will notify you of any confirmed personal data breach within 24 hours of internal detection, providing an initial factual summary. A full incident report will follow within 72 hours." Then describe your process briefly: detection mechanism (monitoring alerts, SIEM, staff reporting), internal escalation chain, containment steps, notification to affected individuals if required. If the DPDP Rules are finalised with specific timelines by the time you answer, reference those. Clients want to know they won't read about a breach in the press before you tell them.
Question 5: Who are your sub-processors, and how do you control them?
Answer framework: Provide an actual list of your material sub-processors — cloud infrastructure (AWS, Azure, GCP), any analytics or monitoring tools that process personal data, email delivery services, support ticketing systems. For each, note what data they access and the contractual controls you have in place. State your policy on adding new sub-processors: "We notify clients at least 30 days in advance before engaging any new sub-processor that will have access to client personal data." This shows that you have thought through the supply chain, not just your own internal controls.
Question 6: What is your data retention and deletion policy?
Answer framework: State specific retention periods by data category. "Employee payroll records: 8 years post-employment (Income Tax Act requirement). Customer interaction data: 2 years post-contract termination. System logs: 90 days." Then describe your deletion mechanism: automated deletion scripts, manual review cycles, and any backups that are included. Confirm that upon contract termination you will return or securely delete all client personal data within a defined period (30–60 days is standard) and provide a certificate of deletion on request. This specificity is what separates vendors who have actually thought about this from those who haven't.
Question 7: Who is your Grievance Officer and how can data principals contact them?
Answer framework: Provide the name, title, and contact details of your Grievance Officer. If you have not formally appointed one, this question is a forcing function. The Grievance Officer does not need to be a lawyer or a dedicated privacy professional — it can be a senior leader who has been briefed on their responsibilities. State the response timeline your Grievance Officer commits to: "All grievances are acknowledged within 48 hours and resolved within 30 days." This demonstrates accountability. See our post on who should own privacy in a SaaS company for more on setting this up.
Question 8: How do you handle data subject rights requests?
Answer framework: Describe your intake process (a web form, a dedicated email address, a portal), your verification step (how do you confirm the requester's identity?), your internal workflow for locating and producing or deleting the relevant data, and your response timeline. DPDP Act timelines have not been specified for all rights, but industry practice is 30 days for most requests. As a processor, note that you will handle requests through the Data Fiduciary — you will not respond to data subjects directly unless instructed to — but you have the technical capability to locate and produce data for any individual whose data you process.
Putting It Together: Tone and Format
The best questionnaire responses share three qualities: they are specific (exact numbers, named systems, real timelines), they are honest (acknowledging gaps with a remediation timeline is better than overclaiming), and they are organised (matching the client's question numbering exactly, not offering essays where bullet points will do).
Consider creating a master "vendor security response document" that pre-answers these eight question categories. Keep it updated quarterly. When a new questionnaire arrives, 80% of the work is already done — you are adapting, not starting from scratch.
For background on the underlying compliance framework, see our post on what enterprise clients look for in DPDP vendor security questionnaires. To understand how questionnaire responses connect to your broader compliance posture, read our piece on DPA vs full DPDP readiness and the detailed vendor gap assessment methodology. A self-assessment checklist is available at our DPDP readiness checklist for IT vendors.
Frequently Asked Questions
How long does it take to complete a DPDP vendor questionnaire?
A first-time response with no existing documentation typically takes 2–4 weeks if it requires gathering information from legal, IT, and operations. With a pre-built vendor security response document covering the eight standard categories, turnaround drops to 2–5 days. Building that document is a one-time investment that pays off on every subsequent questionnaire.
What if we don't have all the controls in place yet — should we say so?
Yes, with a plan. Saying "we are implementing X, expected completion Q3 2026" is far better than overclaiming. Sophisticated procurement teams verify answers during audits. A false "yes" discovered later is deal-ending and potentially creates legal liability. An honest "in progress" with a credible timeline demonstrates maturity and builds more trust than a perfect-sounding but unsupported answer.
Do we need to answer DPDP questionnaires differently from ISO 27001 questionnaires?
Yes. ISO 27001 questionnaires focus on information security controls (technical and organisational). DPDP questionnaires focus on personal data handling specifically — legal bases, data subject rights, Grievance Officer, consent management — which ISO 27001 does not cover. You will need both types of documentation if your clients ask both types of questions, which larger enterprise clients increasingly do.
Building Your Vendor Response Document?
Our Questionnaire Response Assistant helps you build a structured, reusable vendor security response document tailored to DPDP requirements. Join the waitlist to be first in line.
Join the Waitlist