Buyer's guide
Under the DPDP Act the Data Fiduciary remains answerable for personal data it hands to a processor. Outsourcing the processing does not outsource the obligation, which makes third-party risk management a DPDP problem rather than only a security one.
The Act places the duty on the Data Fiduciary — the entity determining the purpose and means of processing. Engaging a processor under contract is permitted, but a failure at that processor is still a failure of your obligation. That is the whole reason vendor assessment matters here.
A DPDP-aware assessment asks narrower questions than a generic security questionnaire.
Processing limited to your documented instructions; confidentiality; security measures; assistance with data principal requests; breach notification without undue delay and within a period that lets you meet yours; deletion or return on termination; disclosure and flow-down of sub-processors; and a right to audit or to receive assurance reports.
A vendor assessed once at onboarding tells you about the vendor as they were that day. Reassessment on a cycle, and on trigger events such as a change of sub-processor or a reported incident, is what keeps the register meaningful. The register should tie each vendor to the processing activities in your RoPA, so the question "what happens if this vendor fails" has an answer.
Yes in effect. The Data Fiduciary determines the purpose and means of processing and remains answerable for the personal data, so engaging a processor does not transfer the obligation. Their failure is your exposure.
The categories of personal data the vendor will hold, where it is processed and whether it leaves India, their ability to delete on instruction and evidence it, their support for data principal requests within your timeline, their breach notification commitment, and disclosure and flow-down of any sub-processors.
A security questionnaire asks how well a vendor is defended. A DPDP assessment asks what personal data they hold, on what basis, where it goes, and whether they can support your statutory duties — deletion, rights requests and breach timelines.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →