You’ve won the work – then the data and privacy questionnaire arrives
Treating a security questionnaire as something to survive guarantees you’ll do it from scratch again in four months’ time. The businesses that get this right build the answers once and keep them current.
Most small businesses meet data protection properly for the first time through a customer rather than a regulator. You’re on the brink of winning the business and signing the contract when somebody in procurement sends over a spreadsheet with ninety rows, and half of them ask how you handle personal data. Around row forty there’s a request to attach your Record of Processing Activities, and that’s usually when my phone rings.
Firstly, don’t panic
If some of the questions or information being requested doesn’t always feel particularly relevant, there’s a simple reason why. Bear in mind that spreadsheet is likely to go to every supplier the client has, from a sole trader to a multinational, so none of the questions were written with you in mind. The person reading your answers is checking whether you’ve thought about this at all.
Ninety rows, four questions
Strip out the formatting and nearly every security questionnaire asks the same four things:
- ‘Do you know what data you’d hold for us’. Not in general terms, but which fields, from whose systems, for how long, and where it physically is going to be stored.
- Who else would touch it. Your subcontractors, your cloud providers, your accountant, the freelancer who covers holidays. Those are sub-processors in data protection terms and the client wants them listed by name.
- What happens when it goes wrong? How fast you’d tell them, who makes that call, and whether anybody has thought about it before the day it happens.
- Can you prove any of it? Certifications, policies, training records, insurance.
Everything else on the spreadsheet is like a version of one of those four themes.
Everything relies on trust
While it might be tempting to overclaim, in a document that is fundamentally about establishing trust, claiming a certification you don’t hold is the fastest way to end a commercial relationship. ISO 27001 and Cyber Essentials are both verifiable in about thirty seconds. ‘Working towards’ is fine and usually accepted. ‘Yes’ when the answer is ‘no’ turns a compliance question into an honesty question, and nobody recovers from that one.
Blank fields read as either ‘we didn’t understand this’ or ‘we’d rather you didn’t know’. A short honest answer scores better nearly every time. ‘We don’t hold that certification, here are the controls we have instead’.
Then there’s the temptation to answer as though you were bigger than you are. Describing a governance committee that is really you and your co-founder having a conversation on a Tuesday is both untrue and unnecessary. Procurement teams buy from small suppliers constantly. What they want is a named person who is accountable and who they know will level with them.
Things every small supplier should have
There’s a floor, and once you’re on it you can complete most of these credibly.
- A record of what you process. Article 30 of the UK GDPR calls this a Record of Processing Activities. For a business of twenty people it’s a spreadsheet rather than a system. What data, whose, why, where it’s stored, how long you keep it, who you share it with.
- A privacy notice that matches what you do. Most of the ones I read are written well enough – but too many describe a business that has since changed.
- Written agreements with your processors, meaning anybody handling personal data on your behalf. The major cloud providers publish standard ones you can point to, so you don’t have to negotiate them. You have to know they exist.
- A retention position. Not a full schedule. A defensible answer to how long you keep this and why.
- A breach process, one page long. Who gets told, in what order, and the fact that a notifiable breach has to reach the ICO within 72 hours of you becoming aware of it.
- A record of who has been trained and when.
That takes a few weeks. It stops well short of a compliance programme, and it gets you to the point where you can answer the questionnaire truthfully.
Where things can get more complicated
International transfers matter if your systems, your support desk or your backups sit outside the UK. The Data Use and Access Act 2025 (DUAA) reformulated the test for whether a country offers adequate protection, and the practical transfer tools are still the UK’s International Data Transfer Agreement (IDTA) and the UK Addendum to the EU Standard Contractual Clauses (SCC). Companies and organisations in regulated sectors such as health, legal or financial services should pay particular attention to these types of questions.
Sub-processor change notification is a real operational commitment (even if it looks like a single tick box). You may be agreeing, committing, or be required to tell the company or organisation before you change any supplier that touches the personal data that they are responsible for.
Breach notification timescales sometimes run shorter in the contract than in the regulation. A client requiring notification within 24 hours has set a bar you now have to meet, totally separate from the ICO’s deadline.
Do it once and do it well
Nearly everybody treats the first questionnaire as something to survive. Then a second one arrives from a different client, in a different format, asking the same four questions, and the whole exercise starts again from nothing.
The businesses that handle this well answer it properly once and keep the underlying documents current. The next questionnaire becomes a formatting job. That’s the difference between a week of radio silence during a procurement process and a reply that goes back the same afternoon. Procurement teams notice these things.
