Tickbox Draft your answers free
Guide

Data protection questionnaire: how to answer UK GDPR questions (with examples)

Been asked to complete a data protection or GDPR questionnaire? Here is what your customer is checking, the UK GDPR idea behind each question, and example answers you can adapt.

Last updated: July 2026

A data protection questionnaire focuses on how you handle personal data: the names, emails, and other details of real people. If your customer shares personal data with you, or you process it on their behalf, UK GDPR makes them responsible for choosing suppliers who protect it, so they ask.

You do not need to be a lawyer to answer well. This guide explains the common questions in plain English, the UK GDPR idea behind each, and gives example answers.

Draft your answers free →

Controller or processor: which are you?

One question shapes many of the others: are you a controller or a processor of the customer’s personal data? A processor handles personal data on the customer’s instructions, for example when you run a service for them. A controller decides why and how data is used. Many small suppliers are a processor for their customer’s data and a controller of their own staff and account data.

Answer plainly which role you play for the data in question. If you are a processor, expect follow-up questions about following instructions, security, and sub-processors.

The questions that come up most

Data protection questionnaires circle a handful of themes:

The ICO registration question

Most UK organisations that process personal data must pay a data protection fee to the Information Commissioner’s Office and appear on its public register. Customers often ask for your registration number, so have it ready. If you are unsure whether you need to register, the ICO has a short self-assessment. Registration is inexpensive and expected, so it is worth sorting out before it costs you a deal.

Answering about data subject rights

UK GDPR gives people rights over their data, including access, correction, deletion, and portability. Your customer wants to know you can help them meet a request within the one-month deadline. Describe how someone would make a request to you, and how you would find and action the relevant data. A short, clear process is enough for a small business.

International transfers

If any personal data is stored or processed outside the UK, for example by a cloud provider, the questionnaire will ask how that transfer is protected. The honest answer for most small businesses is that you rely on reputable providers who use approved safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses. Name the providers where you can.

A faster way to answer

Tickbox drafts an answer to each data protection question in your own words, grounded in UK GDPR and in any policies you upload, and shows which requirement each answer draws on. You review and send, and it never claims you are compliant on your behalf. Your first few answers are free.

Example answers

What is your lawful basis for processing personal data?
For the personal data we process to deliver our service to customers, our lawful basis is performance of a contract. For our own marketing we rely on consent or legitimate interests, and we keep a record of the basis for each activity.
How do you handle a data subject access request?
Requests can be made to our named contact by email. We verify the requester, locate the relevant personal data across our systems, and respond within one month as required by UK GDPR, extending only where the law allows and telling the person if we do.
Are you registered with the ICO?
Yes. We are registered with the Information Commissioner’s Office and pay the annual data protection fee. Our registration reference can be verified on the ICO public register and provided on request.
How long do you retain personal data?
We keep personal data only for as long as it is needed for the purpose it was collected, or as required by law or contract, then delete it securely. We review what we hold periodically and remove data we no longer need.
Do you transfer personal data outside the UK?
Where our reputable cloud providers process data outside the UK, the transfer is covered by approved safeguards such as the UK International Data Transfer Agreement. We can provide our list of providers and their locations on request.

These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.

Frequently asked questions

What is the difference between a data protection questionnaire and a security questionnaire?

They overlap. A security questionnaire covers technical protection broadly, while a data protection questionnaire focuses on personal data and UK GDPR obligations such as lawful basis, rights, and retention. Many customers combine both in one form.

Do I need a data protection officer to answer one?

Usually not. A formal data protection officer is only required in specific cases. Most small businesses simply name whoever is responsible for data protection, often the founder.

What if I do not have written data protection policies?

Describe what you actually do, and say you are documenting it. Honest current practice with a plan to write it down is better than claiming policies you do not have.

More guides

Answer your questionnaire in minutes

Drop it in and Tickbox drafts every answer for you to review. Your first few are free.

Try it free