Playbook, marketing agency

Data and security questions from the prospect's procurement team

Larger prospects ask about data handling before they ask about work, and an agency that cannot answer looks like an agency that has not thought about it. A good deal of this is publishable: what data you process for clients, which tools it passes through, how access is controlled, what your position is on subprocessors. What is not publishable is a commitment. A questionnaire is a document somebody signs on behalf of the firm, and no assistant is in a position to sign anything.

Why this is not the general answer

The handling pattern for security questionnaires holds across every trade. What follows is the part that does not.

  • The agency here is usually processing personal data on behalf of the client rather than for itself, and the roles that arrangement creates are documented rather than assumed in most data protection regimes.
  • The person asking is procurement or security rather than marketing, so the vocabulary is different and a vague answer fails immediately.
  • The subprocessor question is unavoidable in this trade, because an agency's delivery runs through third party tools that the client is effectively inheriting.
  • The output of this conversation is a signed document rather than an answer, which makes the handover a commitment rather than a routing step.

How it arrives

  • do you have a data processing agreement
  • where is our customer data stored
  • who else gets access to our data
  • can you complete our security questionnaire
  • do you have cyber insurance
  • what happens to our data when we stop working together

What has to be indexed for this to work

Material behind this answer
Your published position on client dataWhat you process on behalf of clients, why, how access is controlled inside the agency, and how long you keep it. Larger prospects ask this early, and answering from a published position makes you look like an agency that has thought about it.
Your data processing agreement and how it is executedWhether you have a standard agreement, who signs it, and how long the process takes. Procurement teams want to know the document exists before they want to read it.
The categories of tool your delivery runs throughAnalytics, advertising platforms, scheduling, reporting and storage, described by category and by what each holds. Prospects are inheriting these, and refusing to describe them at a category level reads worse than describing them.
How work in progress and data are handled at the endWhat is returned, what is deleted, over what period, and who holds the accounts afterwards. This is asked by the same procurement team that asked about the agreement, and it belongs in the same document.

The reply

A reply worth copying
We do have a standard data processing agreement and our published position sets out what we process on behalf of clients, how access is controlled internally and how long we retain it. Our delivery runs through analytics, advertising and reporting platforms, and the categories are listed there too. A formal questionnaire needs somebody who can commit the agency rather than a summary from me, so if you send it over to the address on that page it will reach the right person. Leave your name and email and I will flag it so it is picked up.

It answers at the level of substance procurement actually needs first, because a security reviewer who gets only a deflection escalates. Describing the tool categories is honest without naming anything that changes, and refusing to name the change is worse than the naming. The last two sentences separate answering from committing, which is the boundary that matters in this pair.

Where it stops

The trigger. The prospect asks for a document to be completed, signed or confirmed, or asks a question whose answer would bind the agency.

The handover, worded
A questionnaire has to be answered by somebody who can commit the agency, so I am not going to fill in any part of it here. Leave your name and email with the document and it will go to the person who handles these.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Never answer an individual questionnaire item as though the answer were the agency's formal response.
  • Never confirm a certification, an accreditation or an insurance position that is not published.
  • Never say where data is stored beyond what your published position states.
  • Never agree to a contractual term, a notice period or a liability position.

Questions

Is a published data position worth writing just for this?
It is, because it is also the thing that keeps a large prospect in the process while procurement does its work. Every question here comes back repeatedly, and an agency that answers them in the first conversation looks materially different from one that goes quiet for a week.
How specific should the tooling answer be?
Category level is the right altitude, because it is honest, useful and does not go stale every time you change a platform. Anything more specific belongs in the document a person signs, not in a chat reply.
Can it attach or send the agreement?
No. It cannot send or receive files. It points at where the document lives and takes a name, an email and a message so the person who handles these picks it up, which is the correct outcome for something that has to be signed anyway.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.