Step 4 of 10

Question Types

Explore different question types for building effective DPIA questionnaires.

Available Question Types

The template builder supports various question types to capture different kinds of information from vendors.

Text Input

Single-line text for short answers

Use Case:Company name, contact person, brief descriptions
Risk Scoring:Manual review typically required

Text Area

Multi-line text for detailed responses

Use Case:Detailed explanations, process descriptions, justifications
Risk Scoring:Manual review typically required

Yes/No

Simple binary choice questions

Use Case:Compliance checks, policy confirmations, existence questions
Risk Scoring:Easy to assign risk scores (e.g., 'No' = 50 points)

Multiple Choice

Select one option from a list

Use Case:Frequency selections, level assessments, category choices
Risk Scoring:Different score per option

Checkboxes

Select multiple options from a list

Use Case:Multiple applicable items, feature lists, compliance areas
Risk Scoring:Aggregate scores from selected options

Dropdown

Single selection from a dropdown menu

Use Case:Country selection, department choice, category selection
Risk Scoring:Score based on selected option

Date

Date picker for date values

Use Case:Last review date, implementation timeline, expiry dates
Risk Scoring:Can trigger rules based on date ranges

File Upload

Allow document attachments

Use Case:Certificates, policies, evidence documents
Risk Scoring:Presence/absence scoring

Question Configuration Options

Each question can be configured with the following options:

Required

Mark questions as mandatory - vendors cannot submit without answering

Help Text

Add guidance text to help vendors understand what's expected

Risk Score

Assign point values to answers for automatic risk calculation

Section Assignment

Group questions into logical sections

Conditional Logic

Show/hide questions based on previous answers (via Rule Engine)

Default Value

Pre-fill with default values where appropriate

Effective Question Design

✓ Good Practice

"Does your organization have a documented data breach response plan?"

Clear, specific, answerable with Yes/No, can assign risk score

✗ Avoid

"Tell us about your security."

Too vague, hard to score, inconsistent responses

Sample Questions by Category

Data Collection

  • 1.What types of personal data do you collect?
  • 2.Do you collect any special category data?
  • 3.What is the legal basis for processing?

Security Measures

  • 1.Is data encrypted at rest and in transit?
  • 2.Do you have ISO 27001 certification?
  • 3.How often are security audits conducted?

Data Sharing

  • 1.Do you share data with third parties?
  • 2.Are data processing agreements in place?
  • 3.Do you transfer data outside the country?

Retention & Deletion

  • 1.What is your data retention period?
  • 2.Do you have a documented deletion process?
  • 3.Can you respond to deletion requests within 30 days?