Data protection questions in a security questionnaire
Data protection questions ask what data you hold, where it lives, how it is kept apart from other clients, and what happens to it when the contract ends. They also now ask whether client data trains AI models.
What the client wants to know
The client is handing you data and wants to know the limits: which types, which country and provider, whether other customers can see it, when it is deleted, and whether you use it for anything except their project. A vague answer leaves them guessing.
The 8 questions as clients phrase them
The kit covers 8 questions in this area. The wording varies between questionnaires, the control behind it does not.
- What types of our data will you store or process?
- Where is our data stored (country and provider)?
- Is our data logically separated from other customers' data?
- How do you return or delete our data at the end of the contract?
- Do you use client data for any other purpose, such as training AI models?
- Do you classify data by sensitivity?
- How do you handle confidential client data differently from other data?
- Can you keep our data in a specific region, such as the EU?
What a good answer contains
- Data types: say what you actually hold, from only business contact details up to sensitive personal data processed on the client's behalf.
- Location: the country or region, and the providers that host it. Offer to keep data in one region per engagement where the provider supports it.
- Separation: separate projects, folders, repositories or accounts per client, with access limited to the people on that client.
- End of contract: return on request, deletion from active systems within a stated period, backups expiring on their normal schedule, written confirmation on request.
- Other purposes: client data is used only to deliver the agreed services, not sold, not used for marketing, not used to train AI models.
- Classification: if you classify data, say what the classes are. If not, say all client data is treated as confidential by default.
Watch out for
Only promise a deletion period you can keep, and only promise a region you can prove from your providers' settings.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Data: Client data is handled by sensitivity class, with stricter rules for confidential data. If not yet: Write three classes (confidential, internal, public) and the handling rule for each. Treat all client data as confidential.
Example: how a prepared answer opens
Question: How do you handle confidential client data differently from other data?
Confidential data is kept only in approved company or client systems, shared only with people on the engagement, never copied to personal accounts or removable media, and deleted at the end of the engagement.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.