Anyone introducing a SaaS solution for funding processes is processing personal data — which is why the IT or data protection team will show up sooner or later with a questionnaire. That is not an obstacle, it is part of the project. The good news: those clarifications can run alongside the functional evaluation, provided the answers are prepared.

It only gets difficult when the questions are asked after the functional decision has been made. Then every open answer blocks the start — and a go-live planned for spring becomes one in autumn.

The four standard questions

Almost every questionnaire circles the same points:

  • Hosting: Where is the data stored, who operates the data centre, which certifications are in place?
  • Data processing agreement: It governs processing on your behalf and belongs on the table together with the main agreement, not after it.
  • Retention periods: What happens to dossiers after the programme ends, and can the periods be adapted to internal requirements?
  • Access: How is authentication handled, is there MFA, and can the organisation connect via SSO?

Answers that can be prepared in advance

Most of these questions have no project-specific answer — they depend on the product and the provider. A provider who has documented hosting, certifications and standard contracts answers half the questionnaire with existing material before the project has properly begun.

The fastest rollouts are not the ones with the fewest questions — they are the ones where the answers were already written.

Do not postpone the test environment

In practice it pays not to postpone the test environment until the review is finished. While contractual and security questions are circulating, the programme team can already run through the process in a test instance. That way two settled strands meet at the end — and the launch is a formality rather than a feat.

Checklist for the first meeting with IT: hosting location and certification, draft data processing agreement, deletion concept, authentication and SSO, support and update commitments. Anyone who can evidence these five points in the first meeting is only negotiating details afterwards.