My client sent me a DPDP security questionnaire — now what?
A step-by-step guide for IT vendors facing their first DPDP compliance request from an enterprise client.
It arrives in your inbox on a Tuesday afternoon. The subject line reads something like "Vendor Compliance Assessment — DPDP 2023" and the attachment is a 12-page spreadsheet with questions you have never seen before. Your sales lead is asking when you can return it. Your legal team has not heard of DPDP. Your CTO is in a sprint planning meeting.
This scenario is playing out across hundreds of Indian IT firms right now, as enterprise clients — particularly in banking, insurance, healthcare, and e-commerce — begin enforcing the Digital Personal Data Protection Act 2023 (DPDP Act) through their vendor supply chains. If you have received one of these questionnaires, you are not behind. But you do need to understand what is being asked and why, before you respond.
Why your client is sending this
Under the DPDP Act 2023, companies that collect and use personal data of Indian citizens are classified as Data Fiduciaries. Your enterprise client — the bank, the hospital, the e-commerce platform — is almost certainly a Data Fiduciary. The Act holds them responsible not just for their own data practices, but for the practices of every vendor they share personal data with.
This is the core reason the questionnaire landed in your inbox. Your client processes personal data — customer names, account numbers, health records, purchase histories — and at some point that data flows to your systems. Whether you run their payroll, manage their customer support tickets, store their backups, or process their invoices, your client's regulator will eventually ask them: what controls do your vendors have?
Enterprise procurement and legal teams have responded by inserting DPDP compliance requirements into vendor onboarding and renewal processes. The questionnaire is their instrument for collecting that evidence. Some clients have built their own 40-question surveys; others use standardised templates circulated by industry bodies. But the underlying logic is the same: they need to document that you, as their vendor, are not a liability.
What the questionnaire is actually asking
DPDP security questionnaires typically cluster around five themes, regardless of which client sends them:
1. Applicability and classification
Does DPDP apply to your company? Are you processing personal data of Indian residents? In what role — as a Data Fiduciary or a Data Processor? (If you are unsure of this distinction, read our post on Data Fiduciary vs Data Processor: which one is my company? before responding.) Most questionnaires ask you to self-declare your classification. Getting this wrong sets the wrong tone for everything that follows.
2. Data inventory and flows
What categories of personal data do you handle on behalf of this client? Where is it stored (India, overseas)? Who else can access it — subcontractors, cloud providers, support teams? Do you have a data flow map? Clients expect vendors to have at least a basic record of processing activities, even if it is a simple spreadsheet.
3. Security controls
This is where most of the technical questions live. Encryption at rest and in transit, access controls and least privilege, logging and monitoring, vulnerability management, penetration testing frequency, incident response procedures. If your company has ISO 27001 or SOC 2, these questions become much easier to answer. If you do not, you will need to describe your equivalent controls in plain language.
4. Breach notification
Under DPDP Rules 2025, Data Fiduciaries are required to notify the Data Protection Board within a prescribed timeframe in the event of a personal data breach. Your client needs to know that if a breach occurs in your systems that involves their data, you will tell them fast enough for them to meet their own notification obligation. Expect questions about your incident detection capability and your contractual breach notification commitment (typically 72 hours in enterprise contracts).
5. Contractual and governance readiness
Do you have a privacy policy? Do you have a Data Processing Agreement (DPA) template you can sign? Do you have a designated point of contact for data protection queries? Some questionnaires ask for the name and contact details of your Data Protection Officer or equivalent. If you have not thought about a DPA yet, see our guide on what your enterprise clients now demand from IT firms.
How to assess your position quickly
Before you fill in a single cell of that spreadsheet, spend two hours doing a rapid internal assessment. The goal is to understand where you actually stand, not to paper over gaps with optimistic answers.
Step 1 — Confirm DPDP applies to you. If you handle personal data of Indian residents in any capacity — employee data, customer data, or client data — DPDP almost certainly applies. Use the free DPDP Applicability Checker to confirm your scope in minutes.
Step 2 — List every category of personal data you touch for this client. Be specific. "Customer records" is not enough. Do you hold names, mobile numbers, PAN numbers, health data, financial transactions? The more precisely you can answer, the more credible your response looks.
Step 3 — Identify your current controls. You almost certainly have more controls than you think. Pull together your current password policy, your cloud security settings, your incident response contact chain, any compliance certifications you hold. Even basic controls, clearly documented, are better than vague claims of "industry best practices."
Step 4 — Find your gaps honestly. Are there questions you cannot answer yet? That is fine. A questionnaire response that says "we are implementing X by [date]" with a credible timeline is far better than either leaving a question blank or fabricating an answer. Most enterprise clients expect vendors to be on a compliance journey, not at the destination.
Step 5 — Decide who owns this. Compliance questionnaires stall when no one has clear ownership. Assign a named person — ideally someone who spans legal, IT, and business operations — to coordinate the response. If your company is small, that person might be the founder or the COO.
The risk of a poor or delayed response
Enterprise clients increasingly treat DPDP questionnaire responses as a qualifying criterion, not a formality. A poor response — or worse, no response at all — can trigger several consequences:
- Onboarding delays: Your contract or purchase order is put on hold until the compliance review is complete.
- Reduced scope: The client restricts what data they will share with you until you demonstrate adequate controls.
- Contract termination: For existing vendors, a failed compliance review during annual renewal can trigger a termination clause.
- Reputational signal: Procurement teams talk. A vendor who cannot answer basic DPDP questions signals operational immaturity across the relationship.
The good news is that most clients are not expecting perfection. They are looking for evidence that you take data protection seriously, that you have thought about the risks, and that you have a credible plan to close any gaps. As we cover in our post on whether DPDP compliance can actually cost you an enterprise deal, the deal risk is real but manageable if you act now.
Your immediate action plan
Here is what to do in the next five business days:
- Day 1: Acknowledge receipt to your client. Tell them you are reviewing the questionnaire and will respond by a specific date. Buying time gracefully is better than rushing a bad response.
- Day 1–2: Run the Applicability Checker and do your internal data inventory.
- Day 2–3: Map your existing security controls against the questionnaire categories. Note gaps.
- Day 3–4: Draft your responses. For gaps, write honest status updates with timelines rather than leaving blanks.
- Day 5: Have someone senior review and sign off before sending. Questionnaire responses can be contractually significant.
The DPDP questionnaire is actually an opportunity disguised as an administrative burden. Vendors who respond well and quickly often convert it into a trust signal that strengthens the relationship. Vendors who stall or respond with platitudes invite scrutiny.
Not sure if DPDP applies to your company?
Use our free Applicability Checker — answer 8 questions and get an instant assessment of your DPDP scope and obligations.
Check My Applicability — FreeFrequently Asked Questions
Is a DPDP security questionnaire legally mandatory to answer?
The questionnaire itself is a contractual or commercial requirement from your client, not a direct legal mandate under the DPDP Act. However, your underlying obligations under DPDP — to implement appropriate security measures and cooperate with the Data Fiduciary you process data for — are legally binding. Refusing to answer may breach your vendor contract and signal non-compliance to a client who has their own regulatory obligations.
What if we don't currently have a privacy policy or DPA?
Be honest about it and commit to a timeline. Many mid-size IT vendors are in early stages of DPDP compliance. Clients expect honesty and a plan. Fabricating a policy or claiming you have a DPA when you do not is far more damaging if discovered. Use the time between receiving and returning the questionnaire to draft a basic privacy policy — it does not need to be perfect to be credible.
How is DPDP different from GDPR, which we already comply with?
If you have GDPR controls in place, you have a significant head start on DPDP compliance — the frameworks share common principles around consent, data minimisation, security, and breach notification. Key DPDP differences include: no requirement for a Data Protection Officer unless you are a Significant Data Fiduciary, a different consent notice format, India-specific data localisation considerations, and a domestic enforcement body (the Data Protection Board of India) rather than EU supervisory authorities. Your GDPR documentation is strong evidence for DPDP questionnaires; just ensure you reference Indian resident data specifically.