Reference / Free, no signup
Security questionnaire explainer
Understand the question, find the evidence and see how to structure an honest answer.
30 of 30 questions.
The questions
What is your legal entity?
What they mean
Which organisation is responsible for the service and signs the contract?
Evidence to gather
Company registration and the service contract.
Who to ask: Business owner
An answer structure
The contracting entity is [legal name], registered in [country] under [number].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Who is responsible for data protection?
What they mean
Who can answer privacy questions and coordinate a response?
Evidence to gather
Named responsibilities and a monitored contact address.
Who to ask: Business owner
An answer structure
Our privacy contact is [role/contact]. Their responsibilities include [scope].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you maintain a record of processing activities?
What they mean
Can you explain the personal data you use and the purposes behind it?
Evidence to gather
A current processing record and its review date.
Who to ask: Privacy lead
An answer structure
We maintain [record/scope], last reviewed [date]. It covers [activities].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
What is your lawful basis for processing?
What they mean
What supports the processing you undertake as a controller? Different activities can have different answers.
Evidence to gather
Processing record and the assessment supporting each basis.
Who to ask: Privacy lead
An answer structure
For [activity] we rely on [basis], documented in [record]. For client-directed processing our role is [role].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How long do you retain personal data?
What they mean
When do you delete or anonymise data, including after a customer leaves?
Evidence to gather
Retention schedule and deletion process, including backup handling.
Who to ask: Privacy and IT leads
An answer structure
We retain [data category] for [period/reason]. Deletion is handled by [process], with [backup exceptions].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Can you provide your privacy notice?
What they mean
Where can people read how you use their personal data?
Evidence to gather
Current notice and its review date.
Who to ask: Privacy lead
An answer structure
Our notice is at [URL], reviewed [date]. It covers [scope].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Will you enter into a data processing agreement?
What they mean
How will the parties document the processing relationship and responsibilities?
Evidence to gather
Applicable agreement, roles and service scope.
Who to ask: Contract owner
An answer structure
For [service/role] we use [agreement]. The contracting entities and processing details are [details].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Who are your sub-processors?
What they mean
Which suppliers process this customer's data on your behalf?
Evidence to gather
A service-specific list with legal entities and purposes.
Who to ask: Privacy and IT leads
An answer structure
For this service we use [suppliers/purposes]. The current list is [reference].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Where is our data processed?
What they mean
Where storage, support and other processing actually happen, including remote access.
Evidence to gather
Service configuration, supplier terms and support locations.
Who to ask: IT lead
An answer structure
[Data] is stored in [locations]. Support/access occurs from [locations]. Evidence: [reference].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
What safeguards cover international transfers?
What they mean
How relevant transfers are assessed and documented for the applicable regime.
Evidence to gather
Transfer inventory, applicable terms and assessments.
Who to ask: Privacy lead
An answer structure
For [transfer] we use [applicable mechanism] and record [assessment/reference].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How do you notify sub-processor changes?
What they mean
How does the customer learn about additions or replacements under the agreed terms?
Evidence to gather
Contract terms, maintained list and notification process.
Who to ask: Contract owner
An answer structure
We notify [contact] through [channel] with [agreed notice/process].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How do you assess your suppliers?
What they mean
What do you check before sharing customer data and during the relationship?
Evidence to gather
Supplier checks, agreements and review records.
Who to ask: Privacy lead
An answer structure
We assess [criteria] before onboarding and review [trigger/cadence]. Evidence: [record].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you use AI with customer data?
What they mean
Which features or suppliers use AI and what data reaches them?
Evidence to gather
AI inventory, configured features and supplier agreements.
Who to ask: Product and privacy leads
An answer structure
We use [tool] for [purpose] with [data]. The customer can [available controls].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Is our data used to train AI models?
What they mean
What the terms and settings say for the exact AI service you use.
Evidence to gather
Current service-specific terms and account settings.
Who to ask: Product lead
An answer structure
For [service/plan], [data] is handled under [terms/settings]. Training use is [verified position].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you enforce multi-factor authentication?
What they mean
Whether a second factor is required, and on which systems and accounts.
Evidence to gather
Identity settings, coverage and exceptions.
Who to ask: IT lead
An answer structure
MFA is enforced for [scope]. Exceptions are [exceptions] and managed through [process].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How do you control access to customer data?
What they mean
Who can access data, how permission is granted and when it is reviewed.
Evidence to gather
Access policy, roles and review records.
Who to ask: IT lead
An answer structure
Access is granted by [owner/process] for [roles], reviewed [cadence] and removed [trigger].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Is data encrypted in transit and at rest?
What they mean
Which connections and storage systems use encryption and where the gaps are.
Evidence to gather
Service settings, architecture and key-management documentation.
Who to ask: IT lead
An answer structure
[Connections/storage] use [verified configuration]. Keys are managed by [owner/service]. Exceptions: [details].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you back up customer data?
What they mean
What can be recovered after loss and whether restoration has been tested.
Evidence to gather
Backup settings and a recent restore test.
Who to ask: IT lead
An answer structure
We back up [scope] every [interval], retain backups [period] and last tested restoration [date/result].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How do you manage vulnerabilities and patches?
What they mean
How issues are found, prioritised, fixed and checked.
Evidence to gather
Patch process, scan results and remediation records.
Who to ask: IT lead
An answer structure
We identify issues through [process], prioritise by [criteria] and track fixes in [record].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you perform penetration testing?
What they mean
Whether independent testing covers the service being bought.
Evidence to gather
Test scope/date and a shareable remediation summary.
Who to ask: Security lead
An answer structure
[Service] was tested by [provider] on [date]. Scope and remediation status: [summary].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
What security certifications do you hold?
What they mean
Which current certifications cover the contracting entity and service.
Evidence to gather
Valid certificates with scope and expiry dates.
Who to ask: Business owner
An answer structure
We hold [certification] covering [scope], valid until [date]. Evidence: [certificate].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do staff receive security and privacy training?
What they mean
Who is trained, when, and how completion is recorded.
Evidence to gather
Training materials and completion records.
Who to ask: People or privacy lead
An answer structure
[Staff/contractors] complete [training] at [cadence]. Completion is tracked in [record].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How do you respond to a data breach?
What they mean
How you identify, contain, investigate and communicate an incident.
Evidence to gather
Response procedure, responsibilities and exercise records.
Who to ask: Incident lead
An answer structure
Our process covers [steps]. [Role] coordinates it; the last exercise/review was [date].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How quickly will you notify us of an incident?
What they mean
The contractual notification commitment and the point from which it runs.
Evidence to gather
The applicable agreement and escalation process.
Who to ask: Contract and incident leads
An answer structure
Under [agreement], we notify [contact] within [agreed timeframe/trigger], using [channel].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How do you handle data subject requests?
What they mean
How requests are recognised and how you help the controller where you are a processor.
Evidence to gather
Request procedure, responsibilities and request log.
Who to ask: Privacy lead
An answer structure
We receive requests through [channel]. For this service we [handle/assist] through [process].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
How can someone raise a privacy complaint?
What they mean
How a person reaches you and how the complaint is handled.
Evidence to gather
Published contact route, procedure and complaint log.
Who to ask: Privacy lead
An answer structure
Complaints can be raised via [channel]. [Role] records, acknowledges and investigates them using [procedure].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you have a business continuity plan?
What they mean
How the service continues or recovers during disruption.
Evidence to gather
Current plan, dependencies and exercise results.
Who to ask: Operations lead
An answer structure
Our plan covers [scenarios/services]. It was last exercised [date], with [result/actions].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
What are your recovery objectives?
What they mean
The targeted recovery time and acceptable data loss, and whether these are contractual promises.
Evidence to gather
Service agreement, recovery plan and test evidence.
Who to ask: IT and contract leads
An answer structure
For [service] the targets are [RTO] and [RPO]. These are [targets/contractual commitments], supported by [test].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Do you hold cyber or professional indemnity insurance?
What they mean
Whether relevant cover is current and meets the buyer's requested scope.
Evidence to gather
Certificate, policy scope, limit and expiry.
Who to ask: Business owner or broker
An answer structure
We hold [cover] with [limit], valid until [date], subject to [scope/exclusions].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Who approves these questionnaire answers?
What they mean
Who is accountable for checking the response before it is sent.
Evidence to gather
Named reviewer and approval record.
Who to ask: Business owner
An answer structure
[Name/role] reviewed these answers on [date], based on [evidence]. Outstanding items: [list].
Replace the placeholders only with facts you can support. If you do not have the control, say so and describe any real mitigation.
Keep your draft when you create a Rowpa account. Already have one? Save it to my account.
A typical result
For “Do you enforce MFA?”, the explainer asks which accounts are covered, what exceptions exist and where the settings can be checked.
What to check
The answer structures contain placeholders, not claims about your business. Use your own evidence and explain any gaps.
ICO guidance: controllers, processors and contracts. Guidance checked 7 September 2026; the ICO marks it as under review following the Data (Use and Access) Act.
These tools help you prepare a draft. Review the facts and the customer's requirements before sharing it.