BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationDPDP Vendor Questionnaire & DPA Response

Documentation

DPDP Vendor Questionnaire & DPA Response

A larger customer sent you a data-protection questionnaire or a DPA addendum to sign, and you need a real answer before their deadline. A generic template creates commitments you can't back up, so we review what they've actually sent, mark it up, and tell you what has to be true before you sign.

A larger customer sent you a data-protection questionnaire or a DPA addendum, and their deadline isn't waiting for May 2027. We review what they actually sent, mark it up clause by clause, and tell you what has to be true before you sign.

A Data Fiduciary can't contract away its own responsibility for what a processor does with personal data. That's what pushes enterprise buyers to hand every vendor a questionnaire or a data-processing addendum well before the DPDP Rules themselves come into force. If you've received one, the deal is already waiting on your answer, and a generic template response creates commitments you may not be able to back up later.

We work from the actual document in front of us. If the addendum asks for something you can't yet honestly commit to, or asks for more than the Rules actually require, we flag it. We don't draft language that commits you to something you haven't built yet.

Scope

What's included

  • The markup is checked against section 8(2)'s valid-contract requirement and the Rule 6(1) safeguard list, so you can see exactly which clauses are standard, which go beyond what the Rules ask for, and which ones you can't honestly agree to yet.

  • The questionnaire answers get drafted against your real security and process setup. A generic yes-to-everything response creates a paper trail that fails you the moment anyone checks it against reality.

  • The gap list tells you what to fix or document before signing, so the DPA doesn't lock you into a safeguard you haven't actually built. Building the underlying control, like the encryption or access logging Rule 6(1) asks for, is your engineering team's work; we specify what's needed.

Specifics

The details

Why the questionnaire arrives before the deadline does

Section 8(2) lets a Data Fiduciary engage a processor only under a valid contract, and section 8(5) means the fiduciary stays responsible for what happens on its behalf regardless. Rule 6(1)(f) requires that contract to carry the reasonable-security-safeguards provision as a term. A large enterprise buying from you is one, and it has to secure that provision from every vendor touching its users' data. The pressure doesn't wait for the Rules to commence. It arrives the moment their legal team decides to get ahead of it.

What we're actually checking

Question in the paperworkWhat we check it against
Does your contract cover a processor's obligations?Section 8(2), Rule 6(1)(f)
Do you encrypt, control access, and log activity?Rule 6(1)(a)-(c)
Do you retain logs for a minimum period?Rule 6(1)(e), one year
Do you have a breach notification process?Section 8(6), Rule 7
Can you honour a deletion request on their timeline?Section 8(7)-(8), and Rule 8(3)'s own one-year floor, which can conflict with a customer's shorter deletion promise

We review and mark up what's in front of you. We don't implement the security controls the addendum is asking about, and we don't represent you in a negotiation with the customer's legal team. What you get is a clear answer on what's true, what isn't yet, and what the paperwork is actually asking for, so whoever does negotiate is negotiating from an accurate position.

Process

How it works

Step 1 of 4

Send us the paperwork

The questionnaire or DPA addendum, plus what you'll actually be handling under the deal.

Send us the paperwork

The questionnaire or DPA addendum, plus what you'll actually be handling under the deal.

Common mistakes founders make

  • Signing whatever the customer's legal team sends without checking whether it asks for more than section 8(2) and Rule 6(1) actually require.
  • Answering a questionnaire with generic yes-to-everything responses that don't match the business's real security setup.
  • Agreeing to a deletion timeline in the DPA that conflicts with Rule 8(3)'s own one-year minimum retention floor on logs and personal data.
  • Treating a signed DPA as proof of compliance, when it's one document among several the Data Fiduciary still has to build out.

Clarifications

Frequently asked questions

Turnaround depends on how much of the addendum needs work and how much of your setup we're starting from scratch on. Tell us the customer's deadline at intake and we scope against it.

That's exactly what the gap list is for. It tells you what to fix or document before signing, so you're not committing to something you can't back up.

No. We prepare the markup and the response pack so your own team, or whoever you designate, negotiates from an accurate position. We don't represent you before their legal team or before the Data Protection Board.

No single signed document makes a business compliant. It makes you contractually bound to specific commitments, which is why we check those commitments against what's actually true before you sign.

Related

Learn more

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

DPA addendum
A contract term or attachment a customer adds to bind a vendor to specific data-protection obligations, distinct from the main commercial agreement.
Data Processor
Anyone who processes personal data on behalf of a Data Fiduciary. A vendor receiving this kind of questionnaire is almost always being asked to confirm it can act as one.
Reasonable security safeguards
The Rule 6(1) list: encryption or masking, access control, logging and monitoring, backups, minimum log retention, the processor-contract clause, and organisational measures.