Sending your GDPR documents

A customer asked for your GDPR documents. Here is exactly what to send.

The email is four lines long and names nothing. Somewhere behind it is a procurement checklist you cannot see, and a contract that does not move until you answer it. This page shows how to tell which of four asks you have received, what to send for each, what to leave out, and how to write the covering email so you are not answering three follow-ups next week.

Build your pack freeSee a finished pack

Read the whole thing. Nothing here needs an account.

First, work out which ask you have

"Please send your data protection documentation" means four different things depending on who typed it, and sending the wrong one is what starts the back-and-forth.

The onboarding ask. From procurement, near contract signature, usually a named list or no list at all. They need one document to attach to your supplier record. This is the common one, and the one this page is mostly about.

The questionnaire. A spreadsheet with rows. Different job: you answer their form rather than send your document. That has its own guide. Most suppliers attach the pack to its data protection section anyway.

The signature ask. "Please sign the attached DPA." A contract, not a disclosure. Read it, negotiate the sub-processor and audit clauses if you need to, and send your documents alongside it so the reviewer can check the two agree.

The tender ask. A framework or public sector bid with a scored data protection section and a word limit. Same content, different packaging: they want short, quotable answers, not a forty-page attachment.

If the email does not make it obvious, ask. One reply, "happy to send this over, is this for supplier onboarding or do you have a form you'd like completed?", saves a week.

What to send for the onboarding ask

01
One document, not a folder of attachments
The single most common mistake is replying with six files and letting the reviewer assemble them. They will not. Send one document with the sections in it, and attach the separate artefacts, certificates and signed agreements, to that.
02
Who you are, and who is accountable
Legal entity, company number, registered address, and a named person with an email for data protection questions. Not a role inbox with nobody behind it. This is the first thing checked and the easiest to get right.
03
What you do with their data specifically
Not everything your company does. The processing activities that concern the service you are selling them, with purpose, lawful basis, data categories and retention. Scope this properly and half the follow-up questions never happen.
04
Your sub-processors, with countries
Every service that touches the data, the legal entity, the country it is processed in, and whether an agreement is in place. If you publish this list at a fixed address, say so and give the URL: it answers this now and every future change without another email.
05
Transfers, and the basis for each
Where data leaves the UK or the EEA, to whom, and on what mechanism. This section and the sub-processor list are the same facts, so a reviewer will check them against each other. Generate both from one source or they will drift.
06
Security measures, honestly
What you actually do: sign-in and MFA, device encryption, access control, updates, backups, and any certification with its expiry date. A partly with a note reads better than a yes a reviewer disproves. Do not paste in a control framework you do not operate.
07
Breach and complaints procedures
Your notification commitment in hours, and how someone raises a request or a complaint. If both live at a public address the reviewer can open, that is stronger than describing them, because it shows they exist outside the document you just wrote.
08
A review date and a signature
When this was last reviewed, when it is next due, and a named person attesting it is accurate as at today. This is the line that turns a description into evidence of a process, and it is why the same content signed reads better than the same content unsigned.

What they ask, and what actually answers it

"Please send your data protection documentation."
The pack: activities, sub-processors, transfers, security measures, procedures, signed and dated.
Your record, rendered
"Who are your sub-processors and where is our data held?"
The sub-processor table with entity, purpose, country and agreement, plus the public URL if you publish one.
Your vendor register
"Confirm whether data leaves the UK or EEA."
Recipient, country and mechanism for each transfer, agreeing with the sub-processor list.
Your record: transfers
"What is your breach notification timeline?"
The number of hours and what starts the clock, from the procedure you actually operate.
Your breach procedure
"Do you have a DPO?"
Whether you are required to appoint one, and if not, the named person accountable instead.
Your record: accountability
"Send us your privacy policy."
The current version with its publication date, included in the pack rather than sent alone.
Your published policy
"Attach your penetration test summary."
Nothing to send yet. This one is a fact about your business, not a document.
Only you can answer this
"What are your data retention periods?"
The period per activity, with what starts the clock, rather than one number for the whole company.
Your record: retention
"Confirm your cyber insurance cover."
Nothing to send yet. This one is a fact about your business, not a document.
Only you can answer this

The wording on the left is what small suppliers are sent. The right column is where the answer comes from once you keep a record, rather than something you write from scratch each time.

What to leave out

  • Personal data. Your record describes how you handle personal data. It never contains any. No customer lists, no employee records, no examples with real names in them.
  • Your internal risk notes. The register you keep for yourself has judgements in it, chasing notes, things you know need fixing. That is your working document, not theirs.
  • Everything about your other clients. Naming who else you work for is a confidentiality problem for you and tells the reviewer nothing about this contract.
  • Your full network diagram or system inventory. If asked, offer a summary or an attestation instead and say why. Reviewers accept this routinely.
  • Anything you cannot evidence. If a claim is not backed by something you actually do, leave it out. One disproved sentence makes the whole document get read again with suspicion.

The covering email

Four sentences, and it does more work than the document.

Hi [name], attached is our data protection pack for [the service], covering our processing activities, sub-processors and transfers, security measures, and our breach and complaints procedures. Our sub-processor list is published at [url] and is kept current, so you can check it any time rather than asking us. Our data protection contact is [name, email]. If your onboarding needs a specific form completed instead, send it over and I will return it this week.

That last sentence is the one that matters: it pre-empts the questionnaire arriving a fortnight later, and it tells the reviewer you are not going to be difficult.

How to send it

  • A link beats an attachment, where their process allows it, because a link stays current and you can see it was opened. Set an expiry, and revoke it when the contract ends.
  • A PDF when the portal wants a file. Many supplier portals will not accept a URL. Print the same document rather than writing a second one.
  • Never a shared drive folder. Access breaks, permissions get audited, and you will have no idea a year from now who still has it.
  • Send it to the person who asked, and copy the commercial contact, so the person waiting on the contract can see it moved.

What happens after it lands

Three outcomes, all normal. It is accepted and the contract moves, and you hear nothing more. It comes back with two or three specific questions, which is the reviewer doing their job and usually means it was read properly; answer them in the same document and resend it rather than by email, so there is one current version. Or it comes back with a questionnaire attached, because the reviewer's process requires their form regardless of what you sent. In that last case you have not wasted the work: the pack answers most of the data protection rows, and you attach it to them.

How to make the next one cost an hour

Most suppliers get asked more than once a year and rebuild the document each time, from a privacy policy written years ago and whatever the last email said. The alternative is to keep the record once, and treat the pack as a rendering of it rather than a document you author. Then a change of provider updates every future pack, a new customer costs an hour, and the answer you give in March cannot contradict the answer you gave in January. That is the whole reason Rowpa builds the pack from a record instead of giving you a template.

Pricing

This guide is free and needs no account. If you would rather not assemble it by hand: Rowpa reads your website, drafts the record, and turns it into the pack addressed to whoever asked, with your sub-processors, transfers, security measures, procedures and a named signatory, as a revocable link or a PDF. Free to build and read the whole thing, every section. £39 once (a Pack Pass) to send one pack to one customer, regenerations for a year included, no card kept on file. Or from Starter £34/mo for three a month. All prices ex VAT.

Start free See all plans

Common questions

They asked for our GDPR certificate. We do not have one.
There is no such thing as a GDPR certificate, and the reviewer usually knows: it is shorthand for "show me you take this seriously". Send the pack, and if you hold Cyber Essentials or ISO 27001 include it with its expiry date. If you hold nothing, say what you do instead. Nobody is rejected for the absence of a certificate that does not exist.
Should we send our privacy policy?
Include it, but not as the answer. A privacy policy is written for the public about their data. The ask is about your operations and their data. Sending the policy alone is the most common reason a pack comes straight back with questions.
How long should the document be?
Long enough to answer, short enough to be read. For a small supplier that is a handful of pages, most of it tables. Length is not the signal; specificity is.
Do we need a lawyer to review it before sending?
For the pack, usually not: it describes what you do, and you are the authority on that. For a DPA you are being asked to sign, which is a contract with liability in it, a review is worth the money if the contract is.
The customer is in the EU and we are in the UK. Does that change anything?
It changes the transfers section, for their data coming to you, and it may mean they ask about the UK adequacy position. Say where the data sits and on what basis. It does not change the shape of the pack.
Can we reuse the same pack for the next customer?
The content, yes; the document, no. A pack is addressed to a named customer and scoped to what you do for them, and sending customer A's document to customer B is both sloppy and a small confidentiality leak. Regenerate it from the same record instead, which takes minutes.

Further reading

Send it today, not next weekend.

Build your whole record free. Pay only when you send something. No credit card.

Build your pack free