If you process personal data for a client, you must make available to it all information necessary to demonstrate that you meet your obligations under Article 28 GDPR and allow for audits and inspections – this is a mandatory term of the data processing agreement (Article 28(3)(h) GDPR). So you must answer the questionnaire to the extent it concerns that information. But this duty covers the processing on that client’s behalf, not everything the questionnaire asks for. You may offer other evidence in place of security-sensitive documents, but whether that is enough is for the client to decide. The biggest risk is not refusing to answer, but answering inaccurately. When a data processing agreement is required is covered in Data processing agreement: when required and the risk without one.
Questionnaires arrive before the contract is signed, during the client’s annual supplier review, or when the client is itself being checked by its auditors or its supervisory authority. Before the contract is signed there is no such duty yet, but without answers the client cannot assess your guarantees (Article 28(1) GDPR) and will usually not sign. Here we cover what the law actually requires you to answer, what you may limit, and why a confirmation given too easily later becomes a commitment.
Why the client is asking
The client is the controller. It must ensure that data is processed in line with the GDPR and be able to demonstrate it (Article 24(1) GDPR). It may choose only a processor that provides sufficient guarantees of appropriate technical and organisational measures (Article 28(1) GDPR).
In its Guidelines 07/2020 on the concepts of controller and processor, the European Data Protection Board (EDPB) states that the guarantees that count are those the processor can demonstrate to the controller. This usually means exchanging documents: privacy policy, terms of service, records of processing, information security policy, external audit reports and international certifications such as the ISO 27000 series.
The EDPB also states that there is no exhaustive list of documents: the assessment depends on the nature and risk of the processing. This is why questionnaires vary so much depending on what data you see. The duty is also ongoing. The EDPB recommends checking the guarantees at appropriate intervals, including through audits where needed, so the same questionnaire may come back every year.
What you must answer
The EDPB spells out what information is usually needed under Article 28(3)(h) GDPR: how the systems used work, what the security measures are, how retention requirements are met, where the data is located, whether it is transferred, who has access, who the recipients are and which sub-processors are used. You may share the relevant part of your own records of processing with the client. A processor must keep such records for each controller on whose behalf it acts (Article 30(2) GDPR). The exemption for organisations with fewer than 250 employees is narrow: among other things, it does not apply where the processing is not occasional (Article 30(5) GDPR). A processor providing an ongoing service to a client usually processes data regularly. What the security duty requires is covered in GDPR security measures: what Article 32 actually requires.
Sub-processors are the most common and most sensitive question. They may not be engaged without the controller’s written authorisation (Article 28(2) GDPR), and each must be bound by the same data protection obligations (Article 28(4) GDPR). The EDPB states that the controller needs a list of sub-processors with each one’s location, activity and the safeguards implemented. A client’s questionnaire often asks you to confirm that the list is complete and that every agreement in the chain meets Article 28. If the chain includes entities outside the European Economic Area, you will also be asked about the transfer basis. More in our article on transferring personal data outside the EEA.
Breaches come up almost every time. A processor that becomes aware of a personal data breach must notify the controller without undue delay (Article 33(2) GDPR). Answer not with a general phrase but with how it works in practice: who notifies, through which channel and within what time. How much time the client itself then has is covered in our article on when to notify VDAI and people.
What you may limit
The duty has limits. It concerns the processing on behalf of this client and the obligations under Article 28. Questions about other clients’ data, your commercial terms with subcontractors, or activities unrelated to the client fall outside it. You cannot disclose other clients’ personal data, because you process it only on those clients’ documented instructions (Articles 28(3)(a) and 29 GDPR). Other information about them is usually protected by your confidentiality commitments.
You can try to protect security-sensitive documents. One supplier declined to hand over its internal ISO 27001 statement of applicability and relied instead on a valid certificate issued by an accredited body. It is worth proposing that position, especially if the certificate’s scope covers the very service provided to the client. But if the client reasonably considers the statement necessary, the processor must provide all information necessary to demonstrate compliance with Article 28 (Article 28(3)(h) GDPR). The EDPB states that the parties should cooperate in good faith and decide whether an on-site audit is needed and which form of inspection is suitable, taking security into account as well. But the final decision lies with the controller.
So a refusal needs an alternative: a summary, a viewing of the document without a copy, disclosure under a confidentiality agreement, or an independent auditor’s report. Staying silent altogether is not an option. If a processor does not provide the information, the client cannot demonstrate that it chose a suitable processor, and it will usually have to look for another one.
The GDPR does not allocate the costs of audits. The EDPB warns that an agreement should not contain clauses on clearly excessive or disproportionate costs, because they would turn the right to audit into a theoretical one.
The risk: an inaccurate answer
An answer to a questionnaire is not an informal email. It often becomes part of the contract. In one project, when negotiating a data processing agreement drafted by the client, we proposed that the security measures annex should rely on the questionnaires the supplier had already completed for that client. From then on, every answer is a contractual commitment.
That is why the most dangerous thing is to confirm too much. Questionnaires ask you to confirm that the sub-processor list is complete, that every agreement in the chain meets Article 28 and that all vendors have been assessed. If you have not checked, do not confirm. State what you checked, as of what date and with what qualifications. An inaccuracy discovered later can mean a breach of contract and a loss of the client’s trust.
The legal risk does not stop there. The supervisory authority may order a processor too to provide any information it needs for its tasks (Article 58(1)(a) GDPR), and the processor must cooperate with it on request (Article 31 GDPR). The answers given to the client will then be compared with reality. Breaches of a processor’s obligations under Articles 25 to 39 may be subject to an administrative fine of up to ten million euros or, in the case of an undertaking, up to 2 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). If people suffer damage, the processor is liable where it did not comply with the obligations placed on processors or acted outside or contrary to the controller’s lawful instructions (Article 82(2) GDPR).
When to call a lawyer
- when the questionnaire comes together with the client’s data processing agreement or audit terms;
- when you are asked to confirm the whole sub-processor chain or transfers outside the European Economic Area;
- when the client asks for security documents you do not want to disclose;
- when the client wants to audit your premises;
- when you realise that an answer you gave earlier was inaccurate.
Frequently asked questions
Do we have to allow the client an on-site audit?
Article 28(3)(h) GDPR requires you to allow for audits and inspections but does not set their form. The EDPB states that the parties should assess in good faith whether an on-site audit is needed or whether a remote check or another way of collecting the information is enough. The final decision lies with the controller, so it is worth agreeing the form in the contract in advance.
Can we ask for a confidentiality agreement?
Yes. It is the usual way to pass on security-sensitive information without weakening your own protection. But a confidentiality requirement cannot become a pretext for withholding information needed to demonstrate that you meet your obligations under Article 28.
Do we have to disclose our list of sub-processors?
Yes, to the client whose data they process. Without the list the controller cannot give authorisation under Article 28(2) GDPR or assess the guarantees. You do not have to disclose your commercial terms with the sub-processors.
Who pays for the audit?
The GDPR does not decide this; it is for the parties to agree. The EDPB warns that clearly excessive or disproportionate costs placed on one party would in practice defeat the right to audit, so the agreement should not contain such clauses.
How to start
Send us the questionnaire, your contract with the client and the answers you have given before. We will tell you what you must answer, what you may limit and which answers need rewording before you send them.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and consultations.