The email usually arrives a week before the contract is due to be signed. “Before we can set you up as a supplier, please send over your data protection documentation.” No attachment, no list, sometimes a portal link that wants a PDF. You have a privacy policy, a DPA you signed with your hosting provider, a spreadsheet of tools you built two years ago, and a breach process that lives in one person's head.
The person asking is not being vague to be difficult. They have a checklist on their side and they assume you know what is on it. This post is that checklist: the nine things a procurement or information security reviewer at a larger customer expects from a small supplier, what each one is for, and where a GDPR record you already keep holds the answer.
Legal name, registered address, company number, ICO registration number, and the name and contact details of the person accountable for data protection. If you have appointed a Data Protection Officer, their details; if you have not, say who carries the role and do not invent a title. Reviewers check the ICO register. A supplier who is not on it when they should be has failed the review at line one.
Where it is hosted, whether it is encrypted in transit and at rest, who inside your company can reach it and how that access is controlled. This is the overview that answers most first-round questions on its own. It should be written from what you actually do, not from a template, because the next eight items are the evidence for it and a reviewer will cross-check.
The customer wants to know which of their people's data you will touch, for what purpose, on what lawful basis, and for how long. This is your Article 30 record of processing activities, filtered to the activities that concern them. A recruitment agency sends the candidate-sourcing and placement activities; a marketing agency sends the campaign and analytics activities; a SaaS supplier sends the activities it performs as a processor on the customer's instructions. Retention periods matter here: “until the contract ends, then 30 days” is an answer; “as long as necessary” is not.
The list a reviewer spends longest on. Every tool and service of yours that will handle the customer's personal data: the legal entity behind it (Mailchimp is Intuit Inc.; Supabase is Supabase Inc.), whether you have a data processing agreement with it, which country it hosts in, and on what basis data crosses a border if it does. Under Article 28 you need the customer's general or specific authorisation for these, so most DPAs also want to know how you will notify changes. A list that names the tool but not the entity, or claims a DPA you have not actually accepted, is the most common reason a pack goes back with questions.
If any of the sub-processors above are outside the UK or the EEA, or if you are, the reviewer needs the safeguard: an adequacy decision, the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or the EU-US Data Privacy Framework with the UK Extension for US providers certified under it. Name the mechanism per transfer. “We use SCCs” on its own will be queried.
New since 2025, and now on most questionnaires: do any of your tools process personal data using AI, which ones, for what, and is any of it used to train a model? The honest answer is specific to the account. Name each tool and purpose, then verify its training terms, retention settings and processing locations against the applicable agreement. A provider name alone does not establish zero retention or a complete answer. “We do not use AI” when your CRM has a summarisation feature switched on is not.
Your breach procedure: how an incident is detected, who assesses it, and within what time you will notify the customer. Statute gives you 72 hours to notify the ICO; customer contracts increasingly ask for 24 or 48 hours to notify them, so state the commitment you can keep. If you have disclosed any incidents publicly, link them. If you have not had any, say so.
How someone exercises their rights, access, erasure, rectification, and how quickly you respond (one calendar month, extendable in limited cases), plus your complaints procedure. In the UK the Data (Use and Access) Act has required every organisation to have a data protection complaints procedure since 19 June 2026, so a UK customer's reviewer will look for it by name. Both work best as live pages the reviewer can open, not paragraphs in a PDF.
Your current privacy policy and any procedure documents, with the date each was last published; when the record was last reviewed and when it is next due; and a statement by a named person that the pack is accurate as at the date sent. The signature is not ceremony. It is what turns a set of documents into a representation the customer can rely on, and it is the line that ends the “who is responsible for this” question before it is asked.
A SOC 2 report or an ISO 27001 certificate. Some customers will ask for one, and the honest answer for most 10-person firms is that you do not hold one and here is what you do have. A penetration test summary: same. Cyber Essentials, on the other hand, is increasingly asked for in UK supply chains and is within reach of a small firm; if you hold it, include the certificate. None of these are GDPR documentation, but the same reviewer often wants them in the same email.
Read the nine items again and notice that seven of them are your Article 30 record and the things attached to it: activities, vendors, transfers, retention, procedures, policy, review date. If that record is kept in a spreadsheet, assembling the pack means copying from it for a weekend. If it is kept in something that knows the structure, the pack is a report on the record, addressed to the asker.
That is what Rowpa's supplier pack is: the record you built from a website scan, ordered the way a reviewer reads it, with a cover for the customer and an attestation at the end, sent as a link you can revoke or a PDF. It cannot say more than the record does, which is the point; a reviewer who checks a claim against your Trust Center finds the same answer. What is in the pack, section by section.
This post is the what: the nine items the pack contains. For the how, which of the four asks you have actually received, what to leave out, the covering email and how to send it, see exactly what to send when a customer asks for your GDPR documents.
Build the pack from your record. Free to build and read every section. Pay only when you send it.
Start with a free scan