What your customer’s data protection officer wants to see are signable commitments on the points of Article 28 of the GDPR: nature of the processing, sub-processors, transfers outside the EU, data subject rights, incident notification. The GDPR requires them to check that their processors offer sufficient guarantees; on the vendor side, that takes the form of a dedicated questionnaire. Here is how to prepare it.

Who is a processor under the GDPR.

If your service touches your end customer’s personal data (users, employees, prospects), you are a processor within the meaning of Article 4 of the GDPR. Typical cases:

  • A B2B SaaS vendor that stores its customers’ users.
  • An IT services company building an application that processes customer data.
  • A cybersecurity consultancy or consultant with access to logs and incidents.
  • A host, managed-services provider, or DevOps provider.
  • An analytics, tracking, CRM, or marketing-automation tool.
  • A support service that sees customer data pass through.

The customer isn’t asking for your opinion. It’s asking for signable commitments.

A GDPR processor questionnaire is not a communication exercise. Your customer’s data protection officer has to produce, for their own register, proof that your company offers the guarantees required by Article 28 of the GDPR.

That includes precise items: the nature of the data processed, retention periods, sub-processors, transfers outside the EU, a procedure for assisting with data subject rights, an incident and notification procedure. A vague answer is unusable on the customer side; worse, it costs weeks while they ask you for the same thing worded differently.

The goal on the vendor side: produce a dossier the data protection officer can reuse as is in their own compliance file, without filling gaps by email.

The unavoidable points of Article 28.

GDPR Article 28 lists precisely what a data processing agreement must contain. The questionnaire is your customer’s way of checking that these points are covered.

  • Subject matter, duration, and nature of the processing clearly described.
  • Type of data and categories of data subjects.
  • An up-to-date list of sub-processors (for example your CDN, your host).
  • Data location and transfers outside the EU (standard contractual clauses).
  • Documented technical and organizational security measures.
  • A procedure for assisting with requests to exercise rights.
  • A data breach notification procedure.
  • The fate of the data at the end of the contract: deletion or return.
  • A confidentiality undertaking from staff with access.
  • Availability for audit by the controller.

The mistakes that get a GDPR dossier rejected.

  • Having no up-to-date register of sub-processors.
  • Not explicitly citing transfers outside the EU (Google, AWS US, and so on).
  • Announcing a data protection officer who has not been officially appointed.
  • Presenting a generic information security policy with no specific GDPR scope.
  • Promising notification timelines incompatible with your processes.
  • Checking “Yes” on the data protection impact assessment without having produced one.

The GDPR document base on the processor side.

Some items can be shared with your security dossier; some are GDPR-specific.

  • Records of processing activities (Article 30), on both the controller and processor sides.
  • Register of sub-processors and their location.
  • A data map: categories, durations, purposes.
  • Data protection policy and internal procedure.
  • Procedure for exercising rights (access, rectification, erasure, and so on).
  • Breach notification procedure (within 72 hours to the controller).
  • Signed standard contractual clauses for transfers outside the EU.
  • Official appointment of the data protection officer, or justification for its absence.
  • A data protection impact assessment for high-risk processing.
  • Individual confidentiality undertakings for staff.

The same method, applied to GDPR questions.

The four moves structure every answer, from the topic identified to the final validation.

  1. Identify the real GDPR topic under the customer’s wording.
  2. Find the supporting evidence in your existing GDPR documentation.
  3. Prove it by attaching the dated document with its scope.
  4. Validate: your data protection officer or a designated point of contact reviews before sending.

Prova prepares. Your team keeps final validation.

Prova does not replace your security officer, your data protection officer, or your legal team. The service prepares structured answers with the available supporting evidence and flags the points that call for an internal decision. The final decision, the send to your customer, and any certification stay on your side.

No answer goes out without your team’s review. No promise of guaranteed compliance: Prova sets the stage, you decide what goes out.