Vendor & processor governance

Their breach is your penalty

You stay accountable for every supplier that handles data on your behalf. No contract clause moves that to them.

Book a demo See what happens when a DPA lapses Or check your DPDP score first — free, five minutes, no account.
Sound familiar?

Who else touches your data?

The list is longer than procurement’s, and you are accountable for every name on it.

Hospital or clinic

The reference lab, the TPA, the pharmacy, housekeeping, and the visiting consultants who see patients weekly.

SaaS or platform

Your cloud provider, your email service, your analytics tool, and the support platform your customers write into.

HR, staffing or payroll

The background-check agency, the payroll bureau, and the job board that receives every candidate you post.

§8(2)

What the Act actually asks of you

Two obligations, one sentence of statute, and most vendor programmes satisfy neither of them properly.

01

Only under a valid contract

A data processing agreement is the instrument. Not a purchase order, not an email agreeing terms, not a signed quotation with a confidentiality line in it.

02

You remain the Data Fiduciary

Engaging a processor moves the work, never the duty. Their failure is assessed against you, and the Board looks at what you did about it.

03

Their breach is your Rule 7

When a processor is compromised, the duty to intimate the Board without delay and to notify affected people is yours. You inherit the clock, not the excuse.

There is no processor defence in the DPDP Act. “Our vendor did it” is a fact about how it happened, not an answer to whether you are liable.

The difference

A score ranks the problem. A block prevents it.

Most vendor tools grade your suppliers and leave you to act. This one stops the sharing while the paperwork is wrong.

01

The DPA lapses, sharing stops

The moment an agreement moves out of active, every purpose that vendor was covering is blocked. You find out because the block is visible, not months later in an audit.

02

Scope creep stops it too

A vendor reaching beyond the purposes their link covers is a mismatch, and a mismatch blocks in exactly the same way as a missing contract.

03

Renewal lifts it everywhere

When the agreement is renewed, every link for that vendor unblocks at once. One vendor, one contract state, however many purposes it touches.

This is the argument for governing processors in the same system that holds your consent records. A tool that only knows about vendors can tell you a contract expired. A tool that also knows what that vendor was authorised to do can stop the sharing it authorised.

The register

Every processor, and what covers them

One row per vendor per purpose, with the contract behind it and the state that contract is in.

1

Linked to what they actually do

A vendor is not recorded in the abstract. Each link names the notice and the specific purposes that vendor supports, so “what are they allowed to touch” has a written answer rather than an assumption.

2

Contract state, plainly

Active, expired, or missing entirely — and missing is the honest state for the suppliers most organisations have never papered. The register shows it rather than leaving the row blank.

3

Renewal before the block

A still-active agreement inside thirty days of expiry is raised in the DPO’s queue, so the contract is renewed before sharing stops rather than after somebody notices it has.

app.ruleexpert.in/consent/vendors
The vendor coverage screen, listing processors with their DPA status, the purposes each covers and a blocked-sharing banner.
Where the gaps are

The processors that never reach procurement

Vendor registers are usually built from the accounts payable ledger, which is the wrong source for this question.

01

Visiting professionals

Consultants, locums and contract staff who see your customers every week and appear on no software list anywhere.

02

Facilities and housekeeping

Anyone with physical access to a records room or a reception desk is processing personal data, whatever the contract calls them.

03

The tool one team signed up for

A scheduling app or a survey tool bought on a card, holding customer contact details, that nobody in compliance has heard of.

04

Your agency and their agency

Marketing partners routinely subcontract. The chain matters, because your accountability does not stop at the party you signed with.

05

The one who left

A former supplier still holding an export from two years ago is still a processor, and still your exposure.

Two ways to get this done

Your team, or our lawyers

If you have just recognised your own supplier list above, the drafting does not have to wait for anyone to build a feature.

01

Agreements drafted for you

Our empanelled privacy lawyers write the §8(2) processing agreements for your actual supplier list, in the language your procurement team already uses.

02

Their paper, reviewed

When a large vendor insists on their own agreement, we read it and tell you which clauses §8(2) requires that it does not contain, and what to ask for.

03

Due diligence before you sign

A questionnaire suited to what that processor will actually touch, run before onboarding rather than discovered during an incident.

04

Your register, populated

We load your existing supplier list into the platform during onboarding, so nobody on your side types a hundred vendors in by hand.

05

A DPO who carries it

If you would rather not own this at all, our DPO service holds the vendor programme and reports to you. The register stays yours either way.

Each of these is also being built into the platform, so the routine cases stop needing a person. Until then the work is done, not deferred — and where our own template library is concerned, it is drafted and with Indian privacy counsel now, which is why this page does not yet call it counsel-reviewed.

§16 · Rule 15

Processors outside India

DPDP does not work like the GDPR here, and the difference changes what you have to do about a foreign vendor.

01

No adequacy list to check

Transfer abroad is permitted except to countries the government restricts. The model is a blacklist, so there is no approval to obtain before you begin.

02

The notice still has to say so

A cross-border transfer has to be disclosed in the notice covering that data. A silent notice with a foreign data processor behind it is the mismatch worth finding.

03

Sector rules sit on top

Where your regulator already restricts where data may sit — and several Indian regulators do — that obligation is unaffected by anything in the DPDP Act.

Most organisations discover an unpapered processor during an incident.

See the register, a blocked vendor, and a scope mismatch caught before the sharing happened — on live screens rather than slides.

Evidence

Proving you governed them

The question is never whether a vendor failed. It is what you had in place before they did.

01

Coverage at a point in time

Which processors were engaged, under what contract state, covering which purposes. The answer for a date in the past, not just for today.

02

What you did about a gap

A scope check run, an expiry raised, sharing blocked and later restored — each recorded when it happened rather than reconstructed afterwards.

03

It feeds the audit pack

Vendor coverage is one of the sections in the compliance evidence package, hashed alongside the rest so the whole thing can be verified as one document.

Questions

About vendor and processor governance

Our vendor leaked customer data. Who is liable?

You are. §8(2) keeps the Data Fiduciary accountable for every Data Processor acting on its behalf, and permits engaging one only under a valid contract. There is no processor defence in the Act. The duty to intimate the Board without delay and to notify affected people is yours as well — you inherit their incident and its clock. What the Board will weigh under §33(2) is what you had in place beforehand and what you did once you knew.

Do we need a DPA with every single supplier?

With every one that processes personal data on your behalf, which is a wider set than most procurement lists. Your payroll bureau, your reference lab, your cloud provider, your marketing agency, the housekeeping firm with access to a records room, the scheduling app one team bought on a card. A supplier who never touches personal data — a stationery vendor — does not need one. That is the practical difference between a third-party risk programme built for security questionnaires and one built for §8(2): the question is not how critical a supplier is to you, it is whether they touch personal data on your behalf.

Do you score vendors for risk?

Not today, and we would rather be straight about it than show you a number with nothing behind it. What the platform does is stricter than a score: when an agreement lapses or a vendor's access exceeds the purposes it covers, sharing is blocked rather than ranked. A score tells you which vendor to worry about. A block means the thing you were worried about cannot happen while the paperwork is wrong.

What happens when a DPA expires?

Sharing under every purpose that vendor covers is blocked, and it stays blocked until the data processing agreement is renewed. Before that point, a still-active agreement inside thirty days of expiry is raised in the DPO's queue, so the normal path is renewal rather than interruption. Renewing lifts the block across every link for that vendor at once.

Can we use a foreign processor?

Yes, unless the government has restricted that country. DPDP works as a blacklist rather than an adequacy list, so there is no prior approval to obtain. Two things still apply: the notice covering that data has to disclose the transfer, and any sector rule your own regulator imposes about where data may sit is untouched by the Act.

Can you draft our processing agreements?

Our consultants do this as a service today, and the DPA builder inside the platform is on the roadmap. The templates behind it are drafted and awaiting Indian privacy counsel sign-off — which is why this page does not call them counsel-reviewed yet.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Find the unpapered one first.

A live register with a blocked vendor, an expiry raised before it bit, and a scope mismatch caught — on real screens rather than slides.