The DPDPA questionnaireis the new security review.

Procurement has started asking the questions the Board will.

In one line: Common questions cover the vendor's role, breach notification timelines, sub-processors, data location and transfers, security safeguards, retention and support for Data Principal rights.

The estate · SaaS & IT servicesHover to inspect

The vendor with the answers ready is the vendor that gets signed.

The scene

The deal stalled for six weeks in vendor due diligence. Question forty-two asked for the breach intimation timeline to the customer. The honest answer was ‘it depends on who notices’. The competitor's answer was ‘six hours, contractual, rehearsed quarterly’.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
Our SOC 2 report answers it. Security attestations do not cover DPDPA roles, consent or rights handling. Prepare a DPDPA annex to your security pack.
Legal will answer questionnaires. The answers live in engineering, support and operations. Build the answers once, with owners, and keep them current.

The five answers that matter

Your role per activity. Your breach notice time to the customer. Your sub-processor list. Where data is stored and transferred. How you support rights requests.

Monday morning

  1. 01Collect the last five DPDPA questionnaires you received.
  2. 02Write standard answers with owners.
  3. 03Publish a trust page.

Questions, answered plainly

What DPDPA questions do enterprise buyers ask vendors?

Common questions cover the vendor's role, breach notification timelines, sub-processors, data location and transfers, security safeguards, retention and support for Data Principal rights.

Does SOC 2 or ISO 27001 prove DPDPA compliance?

No. They evidence security controls, which support Section 8(5), but do not address roles, consent, notice, rights or other DPDPA obligations.

Sector · SaaS & IT servicesYou think you're the processor. Your contract may disagree.Read → SaaS & IT services · Deep diveThe moment you decide why, you are the fiduciary.Read → SaaS & IT services · Deep diveYour customer trusts you. You trust twenty others.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner