DPDPA Vendor Questionnaires: How SaaS Companies Win Enterprise Procurement
DPDPA Vendor Questionnaires: How SaaS Companies Win Enterprise Procurement
The vendor with the answers ready is the vendor that gets signed.
The scene
The deal stalled for six weeks in vendor due diligence. Question forty-two asked for the breach intimation timeline to the customer. The honest answer was ‘it depends on who notices’. The competitor's answer was ‘six hours, contractual, rehearsed quarterly’.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Our SOC 2 report answers it.
Security attestations do not cover DPDPA roles, consent or rights handling.
Prepare a DPDPA annex to your security pack.
Legal will answer questionnaires.
The answers live in engineering, support and operations.
Build the answers once, with owners, and keep them current.
The five answers that matter
Your role per activity. Your breach notice time to the customer. Your sub-processor list. Where data is stored and transferred. How you support rights requests.
Monday morning
01 Collect the last five DPDPA questionnaires you received.
02 Write standard answers with owners.
03 Publish a trust page.
Questions, answered plainly
What DPDPA questions do enterprise buyers ask vendors? +
Common questions cover the vendor's role, breach notification timelines, sub-processors, data location and transfers, security safeguards, retention and support for Data Principal rights.
Does SOC 2 or ISO 27001 prove DPDPA compliance? +
No. They evidence security controls, which support Section 8(5), but do not address roles, consent, notice, rights or other DPDPA obligations.
Sector · SaaS & IT services You think you're the processor. Your contract may disagree. Read →
SaaS & IT services · Deep dive The moment you decide why, you are the fiduciary. Read →
SaaS & IT services · Deep dive Your customer trusts you. You trust twenty others. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).