You stay accountable for every supplier that handles data on your behalf. No contract clause moves that to them.
The list is longer than procurement’s, and you are accountable for every name on it.
The reference lab, the TPA, the pharmacy, housekeeping, and the visiting consultants who see patients weekly.
Your cloud provider, your email service, your analytics tool, and the support platform your customers write into.
The background-check agency, the payroll bureau, and the job board that receives every candidate you post.
Two obligations, one sentence of statute, and most vendor programmes satisfy neither of them properly.
A data processing agreement is the instrument. Not a purchase order, not an email agreeing terms, not a signed quotation with a confidentiality line in it.
Engaging a processor moves the work, never the duty. Their failure is assessed against you, and the Board looks at what you did about it.
When a processor is compromised, the duty to intimate the Board without delay and to notify affected people is yours. You inherit the clock, not the excuse.
There is no processor defence in the DPDP Act. “Our vendor did it” is a fact about how it happened, not an answer to whether you are liable.
Most vendor tools grade your suppliers and leave you to act. This one stops the sharing while the paperwork is wrong.
The moment an agreement moves out of active, every purpose that vendor was covering is blocked. You find out because the block is visible, not months later in an audit.
A vendor reaching beyond the purposes their link covers is a mismatch, and a mismatch blocks in exactly the same way as a missing contract.
When the agreement is renewed, every link for that vendor unblocks at once. One vendor, one contract state, however many purposes it touches.
This is the argument for governing processors in the same system that holds your consent records. A tool that only knows about vendors can tell you a contract expired. A tool that also knows what that vendor was authorised to do can stop the sharing it authorised.
One row per vendor per purpose, with the contract behind it and the state that contract is in.
A vendor is not recorded in the abstract. Each link names the notice and the specific purposes that vendor supports, so “what are they allowed to touch” has a written answer rather than an assumption.
Active, expired, or missing entirely — and missing is the honest state for the suppliers most organisations have never papered. The register shows it rather than leaving the row blank.
A still-active agreement inside thirty days of expiry is raised in the DPO’s queue, so the contract is renewed before sharing stops rather than after somebody notices it has.
Vendor registers are usually built from the accounts payable ledger, which is the wrong source for this question.
Consultants, locums and contract staff who see your customers every week and appear on no software list anywhere.
Anyone with physical access to a records room or a reception desk is processing personal data, whatever the contract calls them.
A scheduling app or a survey tool bought on a card, holding customer contact details, that nobody in compliance has heard of.
Marketing partners routinely subcontract. The chain matters, because your accountability does not stop at the party you signed with.
A former supplier still holding an export from two years ago is still a processor, and still your exposure.
If you have just recognised your own supplier list above, the drafting does not have to wait for anyone to build a feature.
Our empanelled privacy lawyers write the §8(2) processing agreements for your actual supplier list, in the language your procurement team already uses.
When a large vendor insists on their own agreement, we read it and tell you which clauses §8(2) requires that it does not contain, and what to ask for.
A questionnaire suited to what that processor will actually touch, run before onboarding rather than discovered during an incident.
We load your existing supplier list into the platform during onboarding, so nobody on your side types a hundred vendors in by hand.
If you would rather not own this at all, our DPO service holds the vendor programme and reports to you. The register stays yours either way.
Each of these is also being built into the platform, so the routine cases stop needing a person. Until then the work is done, not deferred — and where our own template library is concerned, it is drafted and with Indian privacy counsel now, which is why this page does not yet call it counsel-reviewed.
DPDP does not work like the GDPR here, and the difference changes what you have to do about a foreign vendor.
Transfer abroad is permitted except to countries the government restricts. The model is a blacklist, so there is no approval to obtain before you begin.
A cross-border transfer has to be disclosed in the notice covering that data. A silent notice with a foreign data processor behind it is the mismatch worth finding.
Where your regulator already restricts where data may sit — and several Indian regulators do — that obligation is unaffected by anything in the DPDP Act.
See the register, a blocked vendor, and a scope mismatch caught before the sharing happened — on live screens rather than slides.
The question is never whether a vendor failed. It is what you had in place before they did.
Which processors were engaged, under what contract state, covering which purposes. The answer for a date in the past, not just for today.
A scope check run, an expiry raised, sharing blocked and later restored — each recorded when it happened rather than reconstructed afterwards.
Vendor coverage is one of the sections in the compliance evidence package, hashed alongside the rest so the whole thing can be verified as one document.
You are. §8(2) keeps the Data Fiduciary accountable for every Data Processor acting on its behalf, and permits engaging one only under a valid contract. There is no processor defence in the Act. The duty to intimate the Board without delay and to notify affected people is yours as well — you inherit their incident and its clock. What the Board will weigh under §33(2) is what you had in place beforehand and what you did once you knew.
With every one that processes personal data on your behalf, which is a wider set than most procurement lists. Your payroll bureau, your reference lab, your cloud provider, your marketing agency, the housekeeping firm with access to a records room, the scheduling app one team bought on a card. A supplier who never touches personal data — a stationery vendor — does not need one. That is the practical difference between a third-party risk programme built for security questionnaires and one built for §8(2): the question is not how critical a supplier is to you, it is whether they touch personal data on your behalf.
Not today, and we would rather be straight about it than show you a number with nothing behind it. What the platform does is stricter than a score: when an agreement lapses or a vendor's access exceeds the purposes it covers, sharing is blocked rather than ranked. A score tells you which vendor to worry about. A block means the thing you were worried about cannot happen while the paperwork is wrong.
Sharing under every purpose that vendor covers is blocked, and it stays blocked until the data processing agreement is renewed. Before that point, a still-active agreement inside thirty days of expiry is raised in the DPO's queue, so the normal path is renewal rather than interruption. Renewing lifts the block across every link for that vendor at once.
Yes, unless the government has restricted that country. DPDP works as a blacklist rather than an adequacy list, so there is no prior approval to obtain. Two things still apply: the notice covering that data has to disclose the transfer, and any sector rule your own regulator imposes about where data may sit is untouched by the Act.
Our consultants do this as a service today, and the DPA builder inside the platform is on the roadmap. The templates behind it are drafted and awaiting Indian privacy counsel sign-off — which is why this page does not call them counsel-reviewed yet.
Real client quotes, attributed by role and sector — we never name a client.
Working across
A live register with a blocked vendor, an expiry raised before it bit, and a scope mismatch caught — on real screens rather than slides.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.