Sales & PartnershipsFree
DPA and Privacy Questionnaire Response
Every commitment this DPA asks for, checked against the terms you actually hold from each subprocessor, with the weakest link named on each.
A DPA response gets treated as form filling. Copy the published subprocessor page into question seven, paste the standard paragraph about transfers into question twelve, sign, send. The buyer's counsel reads the same document as a set of promises about to become contractual, which is a completely different reading of the same page. River works from theirs. It pulls every commitment the DPA asks you to make, then checks each one against the terms you actually hold from the subprocessors who would have to deliver it.
The check is arithmetic and the answer is usually uncomfortable. A twenty-four hour breach clause signed upward while a provider underneath holds seventy-two hours is not a strict commitment, it is one you cannot keep. The response names the count of commitments that are not backed all the way down, the weakest link on each, and the renewal date when that link could be renegotiated. Nothing else on the page changes, and that one count changes what you are willing to sign.
Built for whoever owns the DPA when there is no privacy counsel: the security lead, the founder, the account executive who has read Article 28 more times than anyone intended. Reach for it when the privacy annex lands alongside the security questionnaire, a week after everybody agreed the review was nearly finished. The security questionnaire response pack handles the security half, the redline review handles the markup that follows, and the tool index covers everything else in the review.
Two things a boilerplate answer cannot know
The first is what you hold underneath. Where a processor engages another processor, the same data protection obligations set out in the contract between the controller and the processor shall be imposed on that other processor. Same obligations, all the way down. So every commitment in the buyer's DPA is really a question about nine contracts, not one, and the answer is the weakest of the nine. A published subprocessor page lists the names and tells you nothing about the terms.
The second is that a transfer basis is per subprocessor, not per country. The European Commission recognises a specific list of countries as adequate, and the United States entry on that list runs only to commercial organisations participating in the EU-US Data Privacy Framework. So two American providers in the same register can have different answers, one covered and one needing clauses. A single sentence claiming the framework covers your transfers is a claim about every vendor individually.
Both facts turn the register into the answer. Each subprocessor needs four cells filled: what it processes, where it processes it, the basis for getting data there, and the term it owes you on the commitment being asked about. A row with a blank cell is a question you cannot answer, and saying so with a date beside it costs a follow-up email. Guessing at it costs the review, and later the clause.
How it works
Paste the DPA
Their agreement, their privacy annex, or the rows of the questionnaire that turned out to be privacy.
List what you use
Your subprocessors and what each one touches. Uncertainty is fine and gets recorded as uncertainty.
River checks downstream
Each commitment against the term you hold from every subprocessor who would have to deliver it.
Answer in their form
Scoped answers where a flat yes would not hold, each one traceable to a register row.
What you get
- Every commitment the DPA asks for, checked against the terms you hold downstream
- The weakest link named on each gap, with the contract and its renewal date
- A subprocessor register where a blank cell is reported rather than quietly filled
- Transfer basis resolved per subprocessor, not asserted once for the whole company
- Scoped answers where a flat yes would be a promise you could not keep
- The response written back into the buyer's own form and their own numbering
Common questions
What does it need from me?
Their DPA or privacy questionnaire, and your subprocessor list with what each one touches. The list does not have to be complete or correct. Saying you are unsure about two of them produces better answers than a tidy list with a guess in it, because the uncertainty becomes a dated follow-up rather than a claim.
We do not have signed DPAs with every subprocessor.
Almost nobody does, and clicked-through online terms still contain terms. Those get read the same way as a negotiated agreement, because a seventy-two hour notification window in a standard service agreement binds you exactly as hard as one you argued over. Where there is genuinely nothing, the row says nothing rather than assuming a default.
Isn't admitting a gap going to lose the deal?
Less often than signing it. A scoped answer with a number, a reason and a renewal date reads as a company that knows its own supply chain. A flat yes that a reviewer later disproves from your own subprocessor page turns a commercial negotiation into a question about whether your other answers were checked.
How does it handle data residency questions?
Per subprocessor, as a location and a basis rather than a slogan. An EU-only claim is only true if all nine process in the EEA, and one American error monitoring vendor breaks it. Where a location is unknown, the answer says unknown with a date to confirm, which is the one thing a boilerplate paragraph structurally cannot do.
The buyer sent this alongside a security questionnaire.
That is the normal shape, and the two halves want different treatment. Security questions are answered from evidence you can produce, which is what the security questionnaire response pack is built around. Privacy questions are answered from contracts you hold with other companies, which is a supply chain question wearing a questionnaire's clothing.
We answer these constantly. Can we reuse the answers?
Most of them, and the register is the reusable part rather than the prose. When you want the whole back catalogue turned into something reusable, the answer bank build does that and measures what it covers. Transfer bases still need rechecking per response, because framework participation and adequacy both change.
What happens to the gaps after we send the response?
They become a short list with contracts and renewal dates on them, which is the only form in which anyone ever fixes them. Four unbacked commitments across two supplier renewals is a quarter of work somebody can own. The same four discovered during the next deal's legal review is an escalation with a close date attached.
DPA and Privacy Questionnaire Response
Fill in the form and your workspace opens with the work already underway.