Your First Enterprise Customer's Security Questionnaire
Landing your first enterprise customer in India means answering a security and data protection questionnaire. Here is what DPDP-related questions to expect and how to prepare.
Landing your first enterprise customer almost always means clearing a security and data protection questionnaire before the contract is signed, and for Indian vendors this increasingly includes specific questions about DPDP compliance.
Key facts at a glance
- The DPDP Act 2023 is India's data protection law; full substantive obligations (notice, consent, security safeguards, breach reporting, data-principal rights) become enforceable from 13 May 2027.
- The Consent Manager registration framework under DPDP Rules 2025 becomes operational from 13 November 2026.
- Penalties under DPDP can reach up to Rs 250 crore per instance for failing to implement reasonable security safeguards.
- Enterprise questionnaires commonly request evidence of encryption at rest and in transit, access controls, and a documented incident response process.
- A Data Processing Agreement (DPA) is the standard contract mechanism enterprise customers use to bind vendors to specific data handling terms.
- Even before DPDP's enforcement date, most enterprise buyers already expect vendors to demonstrate a credible roadmap toward compliance, not just a promise to comply later.
Why enterprise buyers ask before the law requires it
Large Indian enterprises and MNCs operating in India generally run formal vendor risk management programs regardless of what the current enforcement timeline for DPDP looks like. These programs exist to protect the buyer, not just to satisfy a regulator, so they typically ask vendors to demonstrate good data practices well ahead of any specific compliance deadline. A startup's first enterprise deal is often the first time this expectation becomes concrete and time-pressured, arriving as a formal questionnaire with a deadline attached to closing the deal.
What the questionnaire typically covers
Data inventory and flows
Expect questions about what personal data you collect, where it is stored, whether it leaves India, and which third-party sub-processors (cloud providers, analytics tools, email services) touch it.
Security controls
Questions on encryption standards, access control and authentication (including multi-factor authentication for internal systems), vulnerability management, and whether you have undergone any independent security assessment or penetration test.
Governance and policies
Whether you have a documented information security policy, a data retention and deletion policy, and a designated person responsible for data protection or security.
Incident response
Whether you have a documented breach response process and what your committed notification timeline is if a breach affecting the customer's data occurs.
Legal and contractual
Whether you will sign a Data Processing Agreement, whether you accept data residency or localisation requirements, and whether your DPDP compliance posture is documented.
Common gaps for first-time enterprise vendors
| Gap area | What is typically missing | Quick fix |
|---|---|---|
| Formal security policy | No written information security policy | Draft a baseline policy covering access, encryption, incident response |
| Sub-processor list | No documented list of third-party data processors | Compile a simple register of vendors touching customer data |
| Breach response | No defined notification timeline or process | Document a basic incident response and notification procedure |
| DPA readiness | Never reviewed or signed a Data Processing Agreement | Get standard DPA terms reviewed before the first request arrives |
| Data mapping | No clear picture of what data is collected and where it flows | Build a simple data flow map as part of DPDP readiness |
Preparing before the deal is on the table
The single most useful thing an early-stage company can do is build its security questionnaire answers before an enterprise deal creates time pressure. Procurement teams reuse similar question sets across vendors, so a well-prepared standard response, even an imperfect one that honestly flags gaps and remediation timelines, moves through review far faster than starting from a blank page under deadline pressure. It also signals maturity to the buyer, which matters as much as the specific answers themselves.
If you are not sure where your data protection practices stand ahead of an enterprise deal, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology - meity.gov.in
- Data Protection Board of India (via meity.gov.in)
- MCA - mca.gov.in (for corporate governance context)
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Why does my first enterprise customer suddenly need a security questionnaire?
- Enterprise buyers, especially larger companies and regulated industries, have formal vendor risk management processes that require every new vendor with data access to complete a security and privacy questionnaire before a contract is signed, regardless of the vendor's size.
- What is the DPDP Act and why would an enterprise customer ask about it?
- The Digital Personal Data Protection Act 2023 is India's data protection law, and enterprise customers ask about it to confirm that a vendor handling personal data on their behalf has appropriate notice, consent, security and breach-response practices in place.
- Do I need to be fully DPDP compliant to answer a security questionnaire today?
- Full substantive DPDP obligations become enforceable from 13 May 2027, so you are not yet legally required to have every mechanism in place, but enterprise customers increasingly expect vendors to show a credible compliance roadmap even before the enforcement date.
- What is a Data Processing Agreement and will I need one?
- A Data Processing Agreement, or DPA, is a contract addendum that sets out how a vendor processes personal data on a customer's behalf, including security obligations and breach notification timelines, and most enterprise customers will require one before sharing personal data with you.
- What security certifications do enterprise questionnaires typically ask about?
- Common questions cover ISO 27001 certification, SOC 2 reports, penetration testing history, and encryption standards for data at rest and in transit, though early-stage vendors are often allowed to answer with their current practices rather than a formal certification.
- What happens if I cannot answer some questions in the questionnaire?
- Most enterprise buyers expect early-stage vendors to have gaps and will work with a remediation timeline or compensating controls rather than rejecting the vendor outright, provided the gaps are disclosed honestly rather than glossed over.
- Should I create a standard security questionnaire response before I need one?
- Yes, preparing a standard response document covering your data handling, security practices and DPDP posture in advance saves significant time once a real enterprise deal reaches the procurement stage, since these questionnaires tend to repeat similar questions across customers.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.