Buyer's guide

DPDP Third-Party Risk Management (2026)

Under the DPDP Act the Data Fiduciary remains answerable for personal data it hands to a processor. Outsourcing the processing does not outsource the obligation, which makes third-party risk management a DPDP problem rather than only a security one.

Jupinder Bedi

Why the obligation does not transfer

The Act places the duty on the Data Fiduciary — the entity determining the purpose and means of processing. Engaging a processor under contract is permitted, but a failure at that processor is still a failure of your obligation. That is the whole reason vendor assessment matters here.

What to assess before onboarding a processor

A DPDP-aware assessment asks narrower questions than a generic security questionnaire.

  • What categories of personal data will they hold, and is that the minimum the purpose requires?
  • Where is it stored and processed, and does any of it leave India?
  • Can they delete on instruction, and evidence the deletion — including from backups within a stated window?
  • Can they support a data principal's access or correction request routed through you, inside your statutory timeline?
  • What is their breach notification commitment to you, and is it fast enough for you to meet your own obligation?
  • Do they sub-process, and are those sub-processors disclosed and flowed down?

Contractual terms that carry the weight

Processing limited to your documented instructions; confidentiality; security measures; assistance with data principal requests; breach notification without undue delay and within a period that lets you meet yours; deletion or return on termination; disclosure and flow-down of sub-processors; and a right to audit or to receive assurance reports.

Keeping it current

A vendor assessed once at onboarding tells you about the vendor as they were that day. Reassessment on a cycle, and on trigger events such as a change of sub-processor or a reported incident, is what keeps the register meaningful. The register should tie each vendor to the processing activities in your RoPA, so the question "what happens if this vendor fails" has an answer.

Frequently asked questions

Does the DPDP Act make us responsible for our vendors?

Yes in effect. The Data Fiduciary determines the purpose and means of processing and remains answerable for the personal data, so engaging a processor does not transfer the obligation. Their failure is your exposure.

What should a DPDP vendor assessment cover?

The categories of personal data the vendor will hold, where it is processed and whether it leaves India, their ability to delete on instruction and evidence it, their support for data principal requests within your timeline, their breach notification commitment, and disclosure and flow-down of any sub-processors.

How is DPDP TPRM different from a security questionnaire?

A security questionnaire asks how well a vendor is defended. A DPDP assessment asks what personal data they hold, on what basis, where it goes, and whether they can support your statutory duties — deletion, rights requests and breach timelines.

Jupinder BediJupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →