Documentation
A larger customer sent you a data-protection questionnaire or a DPA addendum to sign, and you need a real answer before their deadline. A generic template creates commitments you can't back up, so we review what they've actually sent, mark it up, and tell you what has to be true before you sign.
A larger customer sent you a data-protection questionnaire or a DPA addendum, and their deadline isn't waiting for May 2027. We review what they actually sent, mark it up clause by clause, and tell you what has to be true before you sign.
A Data Fiduciary can't contract away its own responsibility for what a processor does with personal data. That's what pushes enterprise buyers to hand every vendor a questionnaire or a data-processing addendum well before the DPDP Rules themselves come into force. If you've received one, the deal is already waiting on your answer, and a generic template response creates commitments you may not be able to back up later.
We work from the actual document in front of us. If the addendum asks for something you can't yet honestly commit to, or asks for more than the Rules actually require, we flag it. We don't draft language that commits you to something you haven't built yet.
Scope
The markup is checked against section 8(2)'s valid-contract requirement and the Rule 6(1) safeguard list, so you can see exactly which clauses are standard, which go beyond what the Rules ask for, and which ones you can't honestly agree to yet.
The questionnaire answers get drafted against your real security and process setup. A generic yes-to-everything response creates a paper trail that fails you the moment anyone checks it against reality.
The gap list tells you what to fix or document before signing, so the DPA doesn't lock you into a safeguard you haven't actually built. Building the underlying control, like the encryption or access logging Rule 6(1) asks for, is your engineering team's work; we specify what's needed.
Specifics
Section 8(2) lets a Data Fiduciary engage a processor only under a valid contract, and section 8(5) means the fiduciary stays responsible for what happens on its behalf regardless. Rule 6(1)(f) requires that contract to carry the reasonable-security-safeguards provision as a term. A large enterprise buying from you is one, and it has to secure that provision from every vendor touching its users' data. The pressure doesn't wait for the Rules to commence. It arrives the moment their legal team decides to get ahead of it.
| Question in the paperwork | What we check it against |
|---|---|
| Does your contract cover a processor's obligations? | Section 8(2), Rule 6(1)(f) |
| Do you encrypt, control access, and log activity? | Rule 6(1)(a)-(c) |
| Do you retain logs for a minimum period? | Rule 6(1)(e), one year |
| Do you have a breach notification process? | Section 8(6), Rule 7 |
| Can you honour a deletion request on their timeline? | Section 8(7)-(8), and Rule 8(3)'s own one-year floor, which can conflict with a customer's shorter deletion promise |
We review and mark up what's in front of you. We don't implement the security controls the addendum is asking about, and we don't represent you in a negotiation with the customer's legal team. What you get is a clear answer on what's true, what isn't yet, and what the paperwork is actually asking for, so whoever does negotiate is negotiating from an accurate position.
Process
Step 1 of 4
Send us the paperwork
The questionnaire or DPA addendum, plus what you'll actually be handling under the deal.
Common mistakes founders make
Clarifications
Turnaround depends on how much of the addendum needs work and how much of your setup we're starting from scratch on. Tell us the customer's deadline at intake and we scope against it.
That's exactly what the gap list is for. It tells you what to fix or document before signing, so you're not committing to something you can't back up.
No. We prepare the markup and the response pack so your own team, or whoever you designate, negotiates from an accurate position. We don't represent you before their legal team or before the Data Protection Board.
No single signed document makes a business compliant. It makes you contractually bound to specific commitments, which is why we check those commitments against what's actually true before you sign.
Related
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Tell us about your partners and business and we'll take it from there.
Get a Quote
Skip the hassle — have us do it for you. We do it best.