forumNew topic

A client wants us to be «RGPD compliant» for a contract — what do we need to show them?

ZZafer Y***ExpertCommunity member
Joined
Jan 2025
Message
7
#1

We are an 8-person digital marketing and custom software agency based in Strasbourg. We submitted a proposal to a large France-based retail chain to develop in-store customer loyalty and analytics software. We agreed on commercial terms and budget, but before signing the contract, the client's procurement and legal department asked us for a comprehensive «RGPD Compliance Package» along with a technical and organizational measures document.

We are a small team; we don't have an in-house full-time lawyer or data protection officer (DPO). Until now, we just got by with putting a standard privacy policy on our website. Do we need to present an ISO certification or a state-approved certificate to the client, or are internal documents prepared by us sufficient for an enterprise-level company?

What concrete documents do we actually need on hand to convince a large client at the negotiating table, how do we include a data processing agreement (DPA) and data inventory in this package, and in what order should an agency of our scale tackle this preparation from scratch?

FFatih K***Expert
Job title
Data entry clerk
Sector
Agriculture
Organization type
medium-sized business
Joined
Jun 2022
Message
228

Doki · Penetration test · 2025

Most Helpful#2

Short answer: There is no state-approved general 'compliance certificate' or official credential for RGPD; what you need to present to a large enterprise client is a Data Processing Agreement (DPA), a Record of Processing Activities (inventory), and a concrete commitment document detailing the technical and administrative security measures you've implemented. The client's legal objective is simply to see on paper how liability is scoped on your end in the event of a data breach.

While preparing this package, you need to clarify your legal standing with the client. The retail chain is the 'data controller' (responsable de traitement), while you act as the 'data processor' (sous-traitant) processing data on their behalf. Therefore, your package must include these three core documents: 1) An RGPD Article 28-compliant Data Processing Agreement (DPA); outlining where data is stored, who can access it, and how it will be deleted upon contract termination. 2) Your company's record of data processing activities (Registre des activités de traitement); summarizing what personal data you process and under what legal basis. 3) A Technical and Organizational Measures Document (Mesures techniques et organisationnelles); itemizing concrete security steps such as server encryption, two-factor authentication, logging, backups, and employee confidentiality agreements.

As a small agency, follow this order from scratch: First, download the free open-source registry template provided on CNIL's official website and map out the data flows in your system. Next, prepare a 3-4 page technical security overview stating that your hosting infrastructure is located within EU borders and describing your encryption practices. This package will more than satisfy the expectations of enterprise compliance teams.

edit: fixed a few typos.

HHilal Z***MemberCommunity member
Joined
Dec 2024
Message
136
#3

As a first step, grab the basic registry template (modèle de registre) published by CNIL. Fill in the data fields your software collects from the client, such as name, email, phone number, along with their retention periods. Large clients' compliance teams typically look for standard templates, so using this official format builds trust right away.

OOsman K***MemberCommunity member
Joined
Mar 2024
Message
117
#4

The folder you send over to the client should contain these 4 documents: 1) A DPA contract addendum defining the rights and obligations of both parties. 2) A list of technical measures detailing your software architecture and encryption protocols. 3) A server commitment letter proving the data resides in European data centers. 4) An incident response procedure guaranteeing you'll notify the client within 48 hours of any potential data breach.

ÖÖzgür B***MemberCommunity member
Joined
Feb 2023
Message
34
#5

A logistics firm in Paris asked us for the exact same thing. Without hiring outside consultants, we put together a 5-page technical measures sheet explaining our security architecture and attached a standard DPA. Their legal department approved it within 4 days and signed off on the 65,000 Euro master contract. They don't care about official badges; they care about paperwork rigor.

AAslıhanMember
Job title
Fashion manufacturer
Joined
Apr 2024
Message
102
#6

Big clients usually have their own standard DPA templates and security questionnaires anyway. Don't waste time drafting a legal agreement from scratch; just tell them: 'If you have a standard vendor security assessment and DPA draft, send it over and our technical team will review, complete, and sign it right away.' Most of the time, they'll just hand you their own forms.

EEbru O***MemberCommunity member
Joined
Mar 2022
Message
370
#7

a retailer asked us for this once and we panicked tbh, but really they just want to pass the buck to the subcontractor if cnil ever comes knocking with fines then tell them servers are in europe, data is encrypted, sign a dpa and you're good.

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#8

Does the loyalty data your software processes include minors under 18 or special categories of sensitive data? If it's just basic contact info and purchase history, things move way faster, but if credit card details or sensitive data are involved, their compliance audit will be significantly harsher.

MMelis Y***Expert
Job title
Call center representative
Sector
Freight
Organization type
8-person team
Joined
Jun 2025
Message
256
#9

Don't waste money on so-called consultants charging thousands of Euros promising 'official RGPD compliance certification' for small businesses. There is no universally accredited corporate RGPD certificate in the European Union right now. All they really want is properly documented internal processes and contractual guarantees.

MMetin Ö***MemberCommunity member
Joined
Aug 2024
Message
356
#10

Yes, that's exactly how it is with rgpd compliance. People defend habits, not processes. Resistance comes from there.

BBarış C***New member
Job title
Supply chain manager
Sector
Tourism
Organization type
two-branch business
Joined
Jul 2026
Message
249
#11

We need to take it step by step. The biggest time-waster for us was not knowing who had the final say.

Proven by experience.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#12

Thanks, that was the answer I was looking for.

İİbrahim Y***MemberCommunity member
Joined
Dec 2024
Message
182
#13

Thanks, that was the answer I was looking for. Just because everyone does it doesn't mean it's right.

Correct me if I'm wrong.

AAyşe A***New member
Job title
IT manager
Sector
Agriculture
Organization type
regional distributor
Joined
Jul 2026
Message
40

Doki · Incident response support · 2025

#14

Saved.

OOsman E***MemberCommunity member
Joined
Jun 2024
Message
401
#15

Let me write how it's done in practice. The answer varies greatly by industry; there is no one-size-fits-all rule.

Of course, it varies if your situation is different.

VVolkan A***Veteran
Job title
Digital marketing specialist
Sector
Packaging
Organization type
chain store
Joined
Jan 2023
Message
191
#16

We experienced almost the exact same thing last year. Payment information changes are never verified through the channel they came from.

I'm also curious if anyone does it differently.

FFiliz U***Member
Job title
Social media manager
Sector
Consulting
Organization type
two-branch business
Joined
Sep 2025
Message
1
#17

Following.

ŞŞerife G***ExpertCommunity member
Joined
Jan 2023
Message
201
#18

This thread is archived.

VVildan B***MemberCommunity member
Joined
Nov 2023
Message
21
#19

I think it's hard to be that definitive about rgpd compliance. Most incidents start with a leaked password, not a vulnerability.

If I were you, I'd go this route.

MMurat K***Member
Job title
Human Resources Manager
Sector
Freight
Organization type
early-stage startup
Joined
Aug 2025
Message
333

Doki · Brand identity · 2023

#20

timly topic.

Reply