DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

A Vendor Privacy Questionnaire is sent to third-party processors before onboarding to assess their DPDP Act 2023 compliance posture. It covers security practices, data localisation, sub-processor management, breach notification capability, and existing certifications (ISO 27001, SOC 2). Vendor questionnaire responses, combined with a DPA, form the contractual and due diligence foundation for compliant third-party data sharing.

Vendor Privacy Questionnaire Pack — DPDP India

Ready-to-use vendor privacy due diligence questionnaire pack — covering security controls, DPDP compliance, breach history, and sub-processor management.

₹999 one-time · instant delivery
Quick AnswerBefore sharing personal data with vendors, send a structured questionnaire to assess their DPDP compliance posture. This pack includes the vendor questionnaire, scoring guide, and DPA review checklist.

Tell us about your organisation

Customise your document

Document Preview

Section 1: Organisation and certifications (ISO 27001, SOC 2)
Section 2: Privacy policy and governance
Section 3: Personal data handling practices
Section 4: Security controls and encryption
Section 5: Breach history and incident response
Section 6: Sub-processor management
Section 7: Cross-border data transfers
Section 8: Data deletion capabilities
Vendor scoring guide (0-100)
DPA review checklist
Complete payment to unlock full document

What you get: Professionally drafted, DPDP-compliant document emailed within minutes.

Secured by Razorpay · Instant delivery to email

Frequently Asked Questions

How often should vendor privacy assessments be repeated?+
Annually, and after any vendor security incident or material change in services. High-risk vendors handling sensitive data should be assessed more frequently.
What score should disqualify a vendor?+
Vendors scoring below 40/100 on the questionnaire should not receive personal data until gaps are remediated. Score below 20 — do not engage for personal data processing.
Can one questionnaire cover all vendor types?+
Use the standard questionnaire for all vendors, with additional sections for: cloud providers (data residency), SaaS tools (multi-tenancy security), and international vendors (cross-border transfer compliance).

Related Tools

DPDP Readiness ScorePrivacy Gap AnalysisVendor Risk ScorecardDPDP Maturity AssessmentDPA GeneratorDPIA Builder
Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Vendor Privacy Scorecard & Tiering Systemएचआर सहमति फॉर्म बंडलवेंडर जोखिम स्कोरकार्डHospital Patient Consent Flow MapperSee all Reference & Checklists tools →📝 DPDP Cookie Consent Banner India📝 DPDP for Clinical Research Cro