Supplier due diligence pack

A customer asked for your GDPR documents. This is what they mean.

Procurement wants one document to file: how you handle personal data, who you share it with, where it goes, and who signs for it. Rowpa assembles it from the record you already keep, addressed to whoever asked, in about ten minutes.

Build one freeSee a sample in the demo

Free to build and read. £39 once to send, or included from Starter at £34 a month.

Why the email is so hard to answer

The ask usually arrives near contract signature: "Before we can set you up as a supplier, please send your data protection documentation." No list. No template. You have a privacy policy, a spreadsheet of tools somewhere, a DPA you signed with your own hosting provider, and a vague memory of a breach process. Turning that into one document that a compliance team can file takes a weekend, and the deal waits.

Rowpa already holds most of the answers, because the record it built from your website scan is exactly what the pack is made of. The pack is that record, ordered the way a procurement reviewer reads it, addressed to them.

What is in the pack

01
Cover, addressed to the asker
Who it is for, who it is from, the date, and which of your processing activities it covers. If you do work for the customer as a processor, only the activities that concern them are listed.
02
How we handle personal data
A narrative overview of hosting, encryption in transit and at rest, and access boundaries, written from your security overview. This is the paragraph that answers most first-round questions on its own.
03
What we do with personal data
The processing activities from your Article 30 record: purpose, lawful basis, data categories, retention, the vendors involved. Chosen per pack, default all active.
04
Sub-processors and suppliers
Every tool you use that touches personal data, with the legal entity, DPA status, hosting country and transfer mechanism, from the vendor library of 400+ sourced entries. The list procurement spends the longest on, with source health and customer confirmation still visible.
05
International transfers
Where data leaves the UK or EU, on what safeguard (adequacy, UK IDTA, EU SCCs), for which activities. Written from the transfer fields on your record, so nothing is claimed that is not recorded.
06
AI tools in use
The question procurement started asking in 2025. Which AI tools you use, for what, and whether customer data is used to train models. Shown honestly as not yet assessed if you have not recorded it.
07
Security measures
Your security posture profile, printed as you answered it: MFA and access control, updates, backups, monitoring, and the certifications you hold with their expiry dates. Rowpa does not invent controls you have not recorded, and it does not hide a no.
08
If something goes wrong
Your breach procedure and the notification commitments in it, plus any incidents you have chosen to disclose publicly on your Trust Center. Nothing else about incidents is included.
09
Complaints, and data subject rights
Your DUAA complaints procedure and intake form, and how access, rectification and erasure requests are handled within a month. Both are live pages, so the reader can check them.
10
Policies and procedures
Your current privacy policy and any procedure documents you attach, versioned, with the date each was last published, so the reader can see how fresh they are.
11
How this record is kept current
Your review cadence, when the record was last reviewed, and when the next review is due. The section that turns a document into evidence of a process.
12
Attestation
A declaration by a named accountable person that the pack is accurate as at the date it was generated. The line that ends the repudiation question before it is asked.

How it goes out

  • As a link. Anyone with the link, or gated behind the reader's email address: they are told before they type it that you will see they opened it. Links expire after 30 days by default, and you can revoke one at any time.
  • As a PDF. Print from the same page when the customer's portal wants an attachment.
  • Regenerated when it changes. Add a vendor, change a retention period, and the next generation of the same pack reflects it. A pack for one customer can be regenerated as often as you like for a year.
  • Counted. You see how many times the link was opened, from which country, and, for gated links, by whom. So you know when to stop chasing.
// Supplier due diligence pack

What it is not

It is not a certification, and it does not claim to be one. It is not a SOC 2 report or an ISO 27001 certificate; if a customer needs those, the pack says what you do have and a platform like Vanta is the right tool for the rest. It is not written for the pack: every section is drawn from your record, so the pack can never say more than the record does. That is the point. A reviewer who checks a claim against your Trust Center finds the same answer.

When the ask is a spreadsheet instead

Sometimes the customer does not want a document; they want their own 120-row security questionnaire filled in. Rowpa handles that too: upload their file, and it drafts the data protection rows from the same record and the security rows from your posture profile, shows the evidence beside each answer, marks the rows only you can answer, and writes the approved answers back into their spreadsheet. How the questionnaire answering works. Most suppliers attach the pack to the data protection section of the questionnaire anyway.

Pricing

Free to build and read the whole pack, every section, watermarked. £39 once (a Pack Pass) to send one pack to one customer, regenerations for a year and the share link included; no card kept on file, nothing to cancel, and it comes off your first subscription payment if you subscribe within 30 days. Starter £34/mo includes three packs a month; Business £79/mo and Business Plus £159/mo include unlimited packs. All prices ex VAT.

Start free See all plans

Common questions

A customer asked for our GDPR documentation. What do they actually want?
Almost always: a sub-processor list, an explanation of where data is hosted and how it is protected, your privacy policy, what happens in a breach, how people exercise their rights, and a named contact. Sometimes a signed DPA on top, which is a separate document. The pack covers everything except the DPA itself, and links your Trust Center where the DPA is published.
Can I leave sections out?
Yes. The wizard chooses sections for the purpose you pick (onboarding, tender, renewal, audit) and you can change what goes in. A section with nothing recorded behind it is shown as not yet recorded rather than filled with filler, and the readiness list tells you what to add before you send.
Does it contain any of my customers' or candidates' data?
No. It describes how you handle personal data. It never includes personal data from your systems, and it draws only from the columns of your record that the pack is allowed to read, which a guard script checks on every build.
What if the customer wants it in Polish, German or French?
Choose the language when you generate it. The pack, the share page and the visitor notice are available in English, Polish, German and French.
What does the customer see if they do not have Rowpa?
A clean page with your branding, the pack, and a small line saying it was prepared with Rowpa. They do not need an account, and nothing is asked of them unless you chose the email gate.

Further reading

Send them the pack today.

Build your whole record free. Pay only when you send something. No credit card.

Build one free