Skip to content

Privacy Operations · Template

Vendor Privacy Assessment Template

A tiered vendor privacy questionnaire covering 30 real questions across data handling, transfers, security, AI use and exit, with risk-rating rules and a completed example row.

Purpose

Not every vendor deserves the same scrutiny. This template gives you a tiered questionnaire so that a payroll processor handling sensitive financial data gets a full assessment, while a vendor that never touches personal data gets a quick record-and-move-on entry. The accompanying CSV contains a ready-to-use question set across ten domains, with one clearly labelled example completed row.

How to use this kit

  1. Tier the vendor before you send a single question (see criteria below).
  2. Copy only the questions relevant to the assigned tier — Tier 3 vendors typically only need Q001 and Q029 answered to confirm no personal data is involved.
  3. Send the relevant questions to the vendor, or complete them from existing documentation (SOC 2 reports, security whitepapers, existing DPAs) where available.
  4. Record the vendor's response, your finding, and a risk rating for every question — an unanswered question is a finding in itself, not a blank to skip.
  5. Where a gap is identified, log a specific action, an owner, and a due date rather than a general note to "follow up."
  6. Get sign-off from the accountable approver before the vendor goes live, and file the completed assessment as evidence.

Field definitions

ColumnDefinition
Question IDUnique reference, e.g. Q014.
Risk tierThe tier this question applies to (Tier 1 full assessment, Tier 2 short assessment, Tier 3 record-only).
DomainThe subject area (data handling, sub-processors, transfers, retention/deletion, security, access control, incident response, AI/model use, contracts/DPAs, exit).
QuestionThe question to put to the vendor or answer from documentation.
Why it mattersOne-line rationale so a non-specialist reviewer understands the risk being tested.
Evidence requestedThe specific artefact that would demonstrate the answer is true (a policy, a certificate, a contract clause), not just a verbal confirmation.
OwnerWho is responsible for obtaining and verifying the answer — often the vendor itself, with your security or legal lead verifying.
ResponseThe vendor's actual answer, summarised.
FindingYour assessment of what the response means (adequate, partial, inadequate, needs clarification).
Risk ratingLow / Medium / High / Critical, based on the decision criteria below.
ActionThe remediation or follow-up required, if any.
Due dateWhen the action must be completed.
StatusOpen, In Progress, Closed, Accepted (risk formally accepted despite a gap).

Tiering: decision criteria

TierCriteriaAssessment depth
Tier 1Special category or highly sensitive data; large volume of individuals; critical operational dependency; data leaves your primary jurisdictionFull questionnaire, all domains, renewed at least annually
Tier 2Ordinary personal data at moderate volume; no special category data; not a critical dependencyShortened questionnaire (data handling, security, retention, contracts), renewed every 12–24 months
Tier 3No personal data processed, or only fully anonymised/aggregated dataRecord the confirmation and the basis for the tiering decision; no full questionnaire needed

If you are unsure which tier applies, default to the higher tier until you can confirm otherwise.

Worked example (illustrative only)

The CSV includes this completed row as a model of the level of detail expected:

FieldValue
Question IDEX-000
DomainExample
QuestionEXAMPLE COMPLETED ROW — delete before use: Does the vendor encrypt personal data at rest and in transit?
Evidence requestedCopy of encryption policy or SOC 2 report excerpt
ResponseYes, AES-256 at rest, TLS 1.2+ in transit, confirmed in SOC 2 Type II report
FindingAdequate control in place
Risk ratingLow
StatusClosed

Note how the response cites a specific, checkable artefact rather than a general assurance — that is the standard to hold every real answer to.

Risk rating guidance

  • Low: control is documented, evidenced, and matches your requirements.
  • Medium: control exists but evidence is incomplete, outdated, or partially matches requirements.
  • High: control is missing, vague, or the vendor could not provide requested evidence for a material risk area (e.g. no DPA, no breach notification commitment, undisclosed sub-processors).
  • Critical: the vendor processes special category or high-volume data with no lawful transfer mechanism, no security certification, or an unwillingness to sign a data processing agreement — treat as a blocker until resolved or formally escalated.

Any High or Critical rating should be escalated for a documented risk-acceptance decision by the approver before onboarding proceeds, or should trigger remediation before go-live.

Ownership and maintenance

  • Assessment owner: typically the privacy or security lead who tiers new vendors and tracks open actions to closure.
  • Business sponsor: the internal team bringing on the vendor is responsible for providing context on the intended use and for engaging the vendor to answer questions promptly.
  • Approver: a named role (e.g. Head of Privacy, CISO, or a joint privacy/security committee) signs off before the vendor is approved to process personal data.
  • Review cadence: Tier 1 vendors — at least annually or on contract renewal, whichever is sooner. Tier 2 vendors — every 12–24 months. Tier 3 vendors — re-confirm the "no personal data" basis if the vendor's use changes. Any material change (new sub-processor, new data category, a reported breach) triggers an immediate reassessment regardless of the schedule.
  • Register: keep a master list of vendors, their tier, their last assessment date and their next review date — this list feeds your overall data inventory as a source of recipients.

Where this fits in your program

Vendor assessment is one of the recurring operational disciplines covered in Practical Privacy Program Implementation. For the underlying legal concepts behind processor obligations, sub-processing and international transfers, see Global Data Privacy Fundamentals. If the vendor embeds AI or model features, also work through the AI Privacy Risk Checklist before sign-off, and consider the AI Privacy and Data Readiness course for a deeper treatment. To benchmark your current vendor risk process, take the free assessment.

Contractual and transfer requirements vary significantly by jurisdiction and sector; treat this template as a starting point and confirm specific legal requirements with qualified counsel where the assessment surfaces a material gap.

Download formats

  • CSV template (.csv) — the full questionnaire with risk tier, question, evidence requested, owner, response, finding, risk rating, action, due date and status columns, plus one clearly labelled example row.
  • Guidance (Markdown .md) — this page, including scoring and escalation criteria.
  • Print / Save as PDF — a clean print view of the guidance.

Nothing here is emailed — each option downloads or prints directly from your browser.