Skip to content
Question Vault?
Free to readNo accountNo email wallNo invented statisticsNo partial listsCopy or print any set and take it with you

GDPR Questions to Ask Vendors

For a data protection officer, privacy lead or procurement manager checking a vendor that will handle personal data for your company, before you sign or when that vendor's periodic review is due. These GDPR questions to ask vendors start with the vendor's role, its processing agreement and the data in scope, then move through sub-processors, where the data travels, security and breach notice, and individual rights and deletion, ending on negotiating the contract and audit rights. It is a due diligence aid and not legal advice, so take the answers that matter to your own counsel.

51 questions

Want questions from the whole vault instead? Try the random question generator.

The questions

Each question, and why to ask it

Role and scope

Will you act as a processor, a controller or a joint controller for the personal data we send you?

Why ask it

Everything else on this list depends on the answer, because a processor works on your instructions and a controller decides its own purposes. Most service vendors say processor, so ask whether there is any part of the service, such as fraud checks or their own analytics, where they consider themselves a controller. A split answer is common and fine, as long as the agreement says which data falls on which side.

Do you have a data processing agreement that covers this service, and can you send it before we go any further?

Why ask it

Processing on your behalf is meant to sit under a written contract, and most vendors have a standard one ready, often linked from the order form. Getting it on day one lets you read every later answer against what the vendor has put its name to. If you hear that there is none, or that the main terms 'cover privacy', pause the review until a real one exists.

What personal data will you process for us, and about which groups of people?

Why ask it

A usable answer is a written list: names, emails, payment details, location, and whether the people are customers, employees or the general public. That list belongs in the annex of the data processing agreement, and it should match what your own team plans to send. If the vendor cannot describe it, the scoping has not been done yet on either side.

Will you use our data for any purpose of your own, such as analytics, product improvement or training AI models?

Why ask it

A processor is meant to handle the data for your purposes, so any use of its own needs to be spelled out and agreed. 'Only in aggregated form' deserves a follow-up about how the aggregation is done and whether individuals could be picked back out. If model training comes up, ask whether you can opt out and whether opted out is the default setting.

Do you have a data protection officer or a named privacy lead, and can we talk to them?

Why ask it

Not every company has to appoint a data protection officer, so the absence of one is not a failing in itself. What you need is a named person who answers privacy questions and will be on the other end of a breach call. If every answer in this review is coming from a salesperson, ask for that person before going further.

If you have no office in the EU or the UK, have you appointed a representative there, and who is it?

Why ask it

A vendor based elsewhere that serves people in the EU or the UK may have to name a local representative, and whether it must turns on facts your counsel can weigh. In practice the answer shows whether there is anyone in the region for a regulator or an individual to contact. 'We have never looked at that', from a vendor with European customers, is worth writing down.

Does the service involve special category data, such as health or biometric information, or data about children?

Why ask it

These kinds of data raise the stakes and often the paperwork, including whether you need an impact assessment before you start. Tell the vendor plainly what you intend to send, then ask whether its terms allow it, since some standard agreements forbid sensitive data altogether. Have your own counsel confirm what counts as special category for your use.

Do you keep a record of the processing you carry out for customers, and can we see how our service would appear in it?

Why ask it

A vendor that keeps this record can usually answer the remaining questions quickly, because the purposes, data categories and transfers are already written down. Some smaller companies may be exempt from keeping one, so ask what they hold in its place. A blank look here usually predicts slow answers everywhere else.

Which optional features collect or share more personal data than the core service needs, and can we turn them off?

Why ask it

Session recording, enrichment tools, tracking pixels and usage telemetry are the usual candidates. The answer shows whether the product was built with data minimization in mind or had it added later. Come away with the settings your admin should change on day one.

Will you help us complete a data protection impact assessment, and what information can you give us for it?

Why ask it

If your processing is likely to be high risk you may need an assessment, and you cannot write it without the vendor's data flows, security measures and sub-processor list. Well-prepared vendors keep a ready-made pack for this, and some bill the help as professional services, so settle which it is before you need it.

Sub-processors

Which sub-processors would handle our data, and what does each one do?

Why ask it

The current list should come with each company's role and country, and a date, so you can tell later what changed. Hosting, email delivery, support ticketing and analytics are the usual entries. Compare the list against the data categories: a support tool that sees full customer records is a bigger exposure than a hosting provider that sees encrypted disks.

How will you tell us before adding or replacing a sub-processor, and how long do we have to object?

Why ask it

Many vendors work on a general authorization, which means you approve the idea of sub-processors up front and get notice of changes. Find out whether notice arrives by email to a named contact or only as an update to a web page you have to watch. Then get the notice period as a number of days.

What happens if we object to a new sub-processor and you want to go ahead anyway?

Why ask it

The right to object is only worth something if it leads somewhere. Typical outcomes are that the vendor offers a workaround, or that you may terminate the affected service. If termination is the only remedy, a refund of prepaid fees for the unused term is the detail to get written in.

Do your contracts with sub-processors carry the same data protection obligations you are accepting from us?

Why ask it

The obligations are supposed to flow down the chain, so the answer should be a quick yes. The useful follow-up is whether you can see a template or a summary of those terms. Hesitation tends to mean the vendor signed its suppliers' standard terms and has never compared them with its own promises.

How do you assess a sub-processor before you use it, and how often do you look again?

Why ask it

You are asking the vendor to describe the same exercise you are putting it through. A named process with a questionnaire, a review of audit reports and a repeat cycle is a good sign. 'They are a big, well-known provider' is not an assessment.

Will you stay responsible to us if one of your sub-processors fails to protect the data?

Why ask it

You have no contract with the sub-processor, so your remedy runs through the vendor. Check that the agreement says so plainly and that the liability cap does not quietly exclude third-party failures. This is a point for your lawyer to read in the document, not one to settle on a call.

Which of your affiliates or group companies can access our data, and are they on the sub-processor list?

Why ask it

Group companies are easy to overlook because they share the vendor's name. A support team in another country that belongs to a sister company is still a separate entity handling your data. If they are missing from the list, ask why and where they are located.

Transfers

In which countries will our data be stored, including backups and disaster recovery copies?

Why ask it

Primary hosting is the easy part of the answer. Backups, failover sites, log stores and email archives are where data turns up in a country nobody mentioned. Have the regions named, one by one, in the annex of the agreement.

From which countries can your staff or contractors access our data, even if it never leaves the hosting region?

Why ask it

Remote access from another country is commonly treated as a transfer, even when the database stays where it is. Follow-the-sun support and offshore engineering teams are the usual reasons. Two things to pin down: what those staff can see, and whether access can be limited to one region for your account.

Which transfer mechanism do you rely on when personal data leaves the EEA or the UK?

Why ask it

Expect to hear an adequacy decision, standard contractual clauses, binding corporate rules or a certification framework, and the answer may differ by destination. Ask which version of the clauses applies and whether the UK is covered separately. The mechanisms and their standing change, so have counsel check that the one named is current.

Have you carried out a transfer impact assessment for those destinations, and can we read it?

Why ask it

Where transfers rest on contractual clauses, the exporter is generally expected to assess whether the destination's laws undermine them. A vendor that has done the work will have a document or a summary to share. You may still need your own, and theirs is the raw material for it.

Can we choose the region where our data is hosted, and what still leaves that region if we do?

Why ask it

Regional hosting is often a paid tier, and it rarely covers everything. Support tickets, telemetry, email notifications and any AI features commonly run through a central service, so name each one. A straight list of exceptions is a better answer than a blanket promise of residency.

What do you do when a government or law enforcement body asks you for a customer's data?

Why ask it

Listen for a process: legal review, a challenge where the request is too broad, and notice to you unless the law forbids it. Some vendors publish a transparency report with counts of requests. A promise to notify you carries more weight in the agreement than in a policy the vendor can edit.

If a transfer mechanism you rely on were invalidated, what would you do and how fast?

Why ask it

This has happened before, and customers were left to sort it out on short notice. A prepared vendor can describe a fallback, such as moving to different clauses or to regional hosting. The contract point to look for is a right to suspend transfers, or to leave without penalty, if no lawful route remains.

Security and breaches

What technical and organizational measures protect our data, and are they listed in the agreement itself?

Why ask it

A link to a security page that the vendor can edit at will is weaker than an annex you both signed. The measures should read as a list: encryption, access control, logging, testing, backup and physical security. Then check whether the agreement lets the vendor change them, and whether it promises not to lower the level of protection.

What does your latest ISO 27001 certificate or SOC 2 report actually cover, and what sits outside its scope?

Why ask it

Read the scope statement before anything else, because a certificate can cover one data center or one product line and not the service you are buying. Note the report date and any exceptions the auditor recorded. These are security attestations: they support a GDPR review but do not show compliance with it on their own.

How is personal data encrypted, and could any of your staff read it in the clear?

Why ask it

Encryption at rest and in transit is the baseline answer. The follow-up about who holds the keys tells you more, since vendor-held keys mean vendor staff, and anyone who compels them, could reach the content. If customer-managed keys are offered, ask which features stop working when you switch them on.

Who at your company can access our data, and how is that access approved, logged and reviewed?

Why ask it

Good answers describe a small number of roles, access granted for a reason and removed afterwards, and a log you could ask to see. Push on what happens the day someone leaves the vendor, and on whether support staff can log in as one of your users.

Is real customer data ever copied into test, development or analytics environments?

Why ask it

Production systems get the attention in audits, and copies made for debugging get forgotten. A good answer is that test data is synthetic or masked, with a named exception process. If real data does get copied, ask how long those copies live and who can reach them.

What data protection training do your staff receive, and are they under a duty of confidentiality?

Why ask it

Confidentiality commitments for the people handling the data are a standard term of a processing agreement, so this should be easy. Contractors and temporary staff are the usual gap, so name them. Training once at onboarding and never again is a weak answer for a team that handles your records daily.

Once you become aware of a personal data breach, how many hours will it be before you tell us, and will you write that number into the agreement?

Why ask it

As the controller you may have a short window to report to a regulator, and it can start running before you have the facts. 'Without undue delay' is the language vendors prefer; a fixed number of hours is what lets you plan. Your counsel can say what number leaves you enough time, and that is the one to negotiate for.

Who decides that an incident counts as a personal data breach, and at what point does the notification clock start?

Why ask it

Some vendors count from first detection and others from the end of their own investigation, which can be days apart. Have them walk through a past or hypothetical incident with times attached. If the clock starts only once they have confirmed the cause, the promised notice period means much less than it appears to.

What will a breach notice from you contain, and who will it go to on our side?

Why ask it

You will need what happened, which data and roughly how many people, the likely consequences and what has been done about it. A vendor that sends what it knows at once and adds to it is easier to work with than one that waits for the complete picture. Give them a monitored contact address now, since a notice sent to whoever signed the order form can sit unread.

Have you had a personal data breach in the past few years, and what did you change because of it?

Why ask it

A vendor of any size that claims none at all may simply not be looking. What you are listening for is a plain account, the time it took to tell customers and a specific change that followed. Compare the story with what has been publicly reported, if anything has.

Rights and deletion

If someone asks us for a copy of their data, how would you help us find and export everything you hold on them?

Why ask it

Your time to respond is limited, often to about a month, so the vendor's part has to take days. Self-service search by your own admins beats a support ticket, and a structured export such as CSV or JSON is something the person could take elsewhere. Have them show it in a demo with a test record, including data in attachments, notes and free-text fields.

Can you erase, correct or restrict one person's data everywhere it sits, including logs, caches and search indexes?

Why ask it

Deleting a row from the main database is simple; the same person's details in audit logs, analytics events and a search index are what usually survive. A vendor that knows its product can list every place a record is copied to and say what happens in each. Restriction is the part most often missing: freezing a record, without deleting it, while a dispute is settled.

What do you do when one of our customers or employees contacts you directly with a privacy request?

Why ask it

The vendor should pass it to you promptly and not answer on its own, since the decision is yours as controller. Get the forwarding time and the address it goes to, and agree what the vendor may say to the person in the meantime, so nobody is left without a reply.

Is your help with data subject requests included in the price, and how quickly do you act on our instruction?

Why ask it

Some agreements promise 'reasonable assistance' and then bill it by the hour. Get a response time in working days and a statement of what is free. A team that receives many requests should treat a per-request fee as a cost line when comparing vendors.

Does the product make automated decisions about people or build profiles of them, and how could a person get a human to review one?

Why ask it

Scoring, ranking, fraud flags and screening tools are where this matters. If decisions with real effects on people are made with no person involved, you may have extra duties toward them, and the vendor needs a way to support that. You will also want an explanation of the logic, in plain words, that you could pass on to the person affected.

How long do you keep each type of data, and can we set those periods ourselves?

Why ask it

Look for retention by category: account records, uploaded content, logs, support tickets, call recordings. Configurable periods let you match your own policy and not inherit the vendor's. 'We keep it for as long as you are a customer' means nothing is ever deleted unless you do it by hand.

When the contract ends, will you return or delete our data, in what format and within how many days?

Why ask it

The choice between return and deletion is normally yours, so the vendor should not have decided it for you. Three details matter: the export format, the deadline, and any grace period during which you can still log in and download. Put a reminder in your own offboarding checklist, since vendors rarely chase you to collect.

How long does deleted data stay in your backups, and what stops it from being restored?

Why ask it

Most vendors cannot remove one record from a backup and rely on backups expiring on a cycle. That is commonly accepted if the cycle is stated and restored data is deleted again. Get the number of days, and ask what process reapplies deletions after a restore.

What written confirmation of deletion will we receive, and does it cover your sub-processors too?

Why ask it

A certificate or signed statement gives you something for your own records if a regulator or a customer asks later. Check that it names the systems and the date, and that sub-processors were instructed to delete as well. If the vendor says the law requires it to keep some data, ask which data, under which law and for how long.

Contract and audit

Which terms of your data processing agreement are open to negotiation, and what have you changed for other customers?

Why ask it

Raise this before price talks finish, while you still have leverage. Large vendors often refuse changes to the document itself but will add a side letter or a clause on the order form. Have your lawyer mark the points that matter before the call, so the vendor's patience is spent on those.

How do we give you documented instructions, and what do you do with a request that falls outside them?

Why ask it

In practice the agreement plus your settings in the product usually count as the instructions. The question is what happens with anything else: a one-off export, a data fix by support, a new integration. You want those requests to come from named people on your side and to leave a record.

Will you tell us if you believe one of our instructions would break data protection law?

Why ask it

Flagging an unlawful instruction is generally expected of a processor, and a vendor that knows the rule has read its own obligations. An example of a time it pushed back on a customer is the best answer you can get. A quick, confident reply suggests the privacy team is involved in day-to-day work.

What audit rights would we have, and what would exercising them cost us?

Why ask it

Many vendors satisfy audit rights with third-party reports and a questionnaire, keeping on-site visits for cases such as a breach or a regulator's request. That can be reasonable for a shared platform. Check the notice period, the frequency limit and whether you pay the vendor's costs, because an audit right priced out of reach is not much of a right.

Will you answer our privacy questionnaire and send updated audit reports every year, without us having to chase?

Why ask it

Vetting at signature goes stale quickly. A commitment to an annual refresh, with a named contact and a place to download current reports, makes your periodic review a short task. If there is a trust portal, settle who at your company gets access to it.

What liability do you accept for data protection failures, and does the general cap in the main agreement apply to them?

Why ask it

A cap set at a year of fees can be small next to the cost of notifying people and dealing with a regulator. Some vendors agree to a higher, separate cap for data protection claims. This is a negotiation for your legal team, so bring them the vendor's first answer in writing.

Has a data protection regulator investigated, warned or fined you, and are any complaints open now?

Why ask it

Ask it directly and then check public sources yourself. A past finding is not disqualifying if the vendor can say what it fixed. An evasive reply, or one that contradicts what you can find, tells you how a future incident would be communicated.

How would you tell us about a change to the service that affects our data, such as a new feature, purpose or hosting location?

Why ask it

Products change faster than contracts, and a new AI feature or a data center move can alter the answers you just collected. Advance notice to a named privacy contact is the answer to hope for; release notes alone mean you find out after the fact. Decide who on your side reads those notices.

How to run a GDPR vendor review with these questions

Practical guidance for the conversation itself

Before you send anything

Map your own data first

You cannot judge a vendor's answers until you know what you plan to send it. Write down the categories of personal data, whose data it is, roughly how many people and why the vendor needs it. That one page becomes the annex to the processing agreement and tells you which groups on this list deserve the most time.

Scale the review to the risk

A newsletter tool holding email addresses does not need the scrutiny of a payroll provider holding bank details and health notes. For a low-risk vendor, the role question, the processing agreement, the sub-processor list, the hosting location, breach notice and deletion at exit may be enough. For anything touching sensitive data or large numbers of people, work through every group.

Read what is already public

Many vendors publish their processing agreement, sub-processor list and security overview on a trust page. Read those first and send only the questions they leave open, quoting the document where you need more. A short, pointed list gets faster and more candid replies than a spreadsheet with hundreds of rows.

Decide who reads which answers

Privacy, security, procurement and legal each own part of this. Agree up front who judges the Security and breaches group, who negotiates Contract and audit and who signs off overall, so answers do not sit in one inbox. In a small company one person may do it all, in which case book counsel's time for the agreement itself.

Getting answers you can rely on

Ask for the document behind the yes

Almost every question here can be answered with 'yes, we do that'. Follow each yes with a request for the thing itself: the list, the report, the clause, the screenshot of the setting. What a vendor can send the same day is usually what it really has.

Get the privacy person on a call

Sales teams answer from a prepared sheet and tend to stall on anything outside it. Half an hour with the vendor's privacy or security lead covers the Transfers and Rights and deletion groups better than three rounds of email. Send the questions ahead so they can bring the right documents.

Turn adjectives into numbers

'Promptly', 'reasonable' and 'without undue delay' appear all through vendor paperwork. For breach notice, sub-processor notice, deletion after exit and backup expiry, ask for hours or days and for the number to go into the agreement. If the vendor will not commit to one, record that as a finding.

Test one request end to end

During a trial or demo, create a test person and then ask the vendor to export and delete that record. Watching it happen shows you the admin controls, the support process and the places data lingers, which no questionnaire answer will.

What to do with the answers

Sort every gap three ways

Each weak answer is either something to fix in the contract, something the vendor must change before go-live, or a risk your company decides to accept. Write down which, with a name beside it. A gap that nobody has classified tends to be found again at the first incident.

Keep the file

Store the answers, the reports you received, the signed agreement and your decision together. A record of how you chose and checked a processor helps you show your own compliance if you are ever asked, and it saves the next reviewer from starting over.

Set the next review now

Pick a date, often tied to the contract renewal, and list the events that should trigger an earlier look: a new sub-processor, a breach, a change of hosting region, a new feature that touches personal data, or a change in the rules on transfers. Then the periodic review is a matter of asking what has changed since the file was closed.

Take the legal points to a lawyer

Whether a transfer mechanism is valid, what your notification deadlines are and how liability should be capped depend on your jurisdiction, your sector and the facts. Rules also differ between the EU and the UK and from one national regulator to another. Bring the answers you collect to counsel as a briefing, and let counsel make those calls.

Where vendor reviews go wrong

Treating a certificate as the whole answer

ISO 27001 and SOC 2 are about security controls. They say little about lawful transfers, data subject requests, retention or the vendor's own use of your data. Count them toward the Security and breaches group and keep asking in the others.

Accepting 'our agreement is standard'

Standard means the vendor wrote it. Read the sub-processor notice period, the breach clause, the audit clause and the liability section at minimum, since those are where a vendor's template leans toward the vendor.

Forgetting the copies

Reviews concentrate on the production database. Personal data also sits in backups, logs, support tickets, email notifications, analytics tools and staff laptops. Ask about each of those when you cover location, access and deletion.

Vetting once and filing it

The sub-processor list you approved at signature will not be the one in use two years later. If nobody on your side receives and reads change notices, the right to object exists only on paper.

More on this topic