Questionnaire answers · Privacy and data

How to answer customer data isolation questions in a supplier questionnaire

The short answer

Say how one customer's data is kept apart from another's, who can reach it and whether any model is trained on it, and show the control. The closest article is the GDPR's security duty: measures appropriate to the risk, including the ongoing confidentiality, integrity, availability and resilience of processing systems (GDPR Article 32(1), point (b)). Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“Is our data logically separated from other customers' data?”
  2. Q2“Is our data used to train AI models?”
  3. Q3“Who at your company can access our data?”
  4. Q4“Can one customer's data reach another customer through the AI feature?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Is our data used to train AI models?

Direct answerYes, partly or no first
No. Neither we nor our model provider train on your data.
ControlWhat you actually do
The model provider's terms exclude training on API inputs and outputs, and our own models are trained only on public data.
ScopeWhich AI systems
Every AI feature in the product.
EvidenceWhat you can show
The model provider's training clause with the date it was read, and our training data sheet.
ExceptionsBe honest
Feedback you choose to send us is used to improve prompts, never to train a model.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The control that keeps customers apart: the access policy, the configuration or the test that proves it.
  • The access list: who can reach customer data, and why.
  • The training clause in each AI provider's terms, with the date it was read.

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

  • GDPR Article 32(1): taking into account the state of the art, the costs, the nature, scope, context and purposes of processing and the risk, the controller and the processor implement appropriate technical and organisational measures, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access after an incident, and a process for regularly testing the measures.
  • Under Article 32(4), a person acting under their authority with access to personal data processes it only on the controller's instructions, unless Union or Member State law requires otherwise.

GDPR Article 28(3), point (b): the processor ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Read from the Official Journal text of the GDPR (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.

What Complipath does

  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
  • Two-factor sign-in A code from your phone after the email link, which the owner can require for everyone

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Audit pack Coming soon One file for an auditor: every system, its classification, evidence, the audit log and a fingerprint. Not available yet.

Questions

Does Complipath keep our customers' data apart for us?

No. Complipath does not do your security work. It keeps the evidence and answers with a source: the control you describe, the file that proves it with the passage and its page, and the audit log of who did what and when.

Is training on customer data an AI Act question?

Partly. For a high-risk system, Article 10 of the AI Act, as amended, sets data governance and quality criteria for its training, validation and testing data, or only for its testing data where no model is trained; the training data page covers it. Whether a customer's data may be used at all is settled by your contract and the GDPR.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.