Service Module · Platform Spoke

Vendor & Third-Party Risk Management — Your Compliance Is Only as Strong as Your Weakest Vendor

Every payment gateway that processes your customer transactions. Every cloud provider that hosts your databases. Every CRM, email marketing tool, analytics platform, and helpdesk system that touches personal data. Every payroll vendor that handles employee records. Every logistics partner that receives delivery addresses.

Each one is a Data Processor acting on your behalf. And under Section 8 of the DPDP Act 2023, you — the Data Fiduciary — are strictly liable for what they do with that data. You cannot contract away this accountability. If your vendor suffers a breach, you notify the Board. If your vendor misuses data, you face the penalty. If your vendor ignores an erasure request, you are non-compliant.

Most organisations manage vendor risk through a shared folder of signed agreements that nobody has read since onboarding. That is not vendor risk management. That is a filing system for liability.

PrivacyOS provides a structured vendor risk programme — assessments, Data Processing Agreement tracking, ongoing compliance monitoring, risk scoring, remediation workflows, and a centralised dashboard — so your supply chain does not become your audit failure.

· DPDPA Compliance · Trust Assured
FAST TRACK APPLICATION

Apply for DPDPA Assessment

Fill the details to get started with our corporate panel.

Representative PortraitRepresentative PortraitRepresentative PortraitRepresentative Portrait
4.9/5

Trusted by 1,000+ compliance teams

Trusted by leading enterprise and mid-market brands

Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Client Logo
Section 8 Mandates

What the DPDP Act Requires for Vendor Management

Section 8(2): Valid Contract Required

The DPDP Act is explicit — a Data Fiduciary may engage a Data Processor to process personal data on its behalf only under a valid contract. This is not optional, and a standard service agreement does not satisfy this requirement. The contract must specifically address data protection obligations, security safeguards, breach notification, sub-processing restrictions, and data deletion upon contract termination.

Section 8(1) and 8(5): Non-Delegable Accountability

Section 8(1) makes compliance responsibility non-delegable. Section 8(5) goes further — the Data Fiduciary is responsible for ensuring that its Data Processors comply with the Act. This is strict liability. The Board does not care what your contract says about indemnification. If the processor fails, the fiduciary pays.

In practical terms, this means:

  • • A cloud provider that suffers a breach involving your customer data triggers your notification obligation
  • • A marketing vendor that uses your customer list for purposes beyond what was consented to makes you non-compliant
  • • A payroll processor that fails to delete former employee records after contract termination violates your retention obligations
  • • An analytics vendor that transfers data to a server in a restricted country triggers your cross-border transfer exposure

Rule 6: Security Safeguards for Processors

Rule 6 of the DPDP Rules 2025 outlines baseline technical and organisational security measures that apply to data processing. Your vendors should implement encryption, robust authentication and access controls, audit logging, breach detection mechanisms, and reliable backup protocols. Your job is to verify they actually do this — not take their marketing site's word for it.

Operational Blind Spots

The Hidden Risks Most Organisations Miss

Shadow Vendors

Your procurement team manages 15 vendors. Your actual data ecosystem involves 45. The gap is shadow vendors — SaaS tools adopted by individual teams without IT, legal, or procurement review. The marketing team signs up for an email analytics tool. Customer support starts using a new ticketing platform. A developer integrates a third-party API for address verification.

Each of these tools processes personal data. None of them have Data Processing Agreements. None have been assessed for DPDPA compliance. Each one is an unmanaged risk.

Sub-Processor Chains

Your vendor does not operate in isolation. They use their own vendors — cloud hosting, payment processing, analytics, customer support tools. Personal data you shared with your vendor may flow through a chain of sub-processors you never contracted with and never assessed.

Under the DPDP Act, you are accountable for the entire chain. If personal data leaks through a sub-processor three levels removed from your direct vendor, the notification obligation and regulatory exposure falls on you.

Consent Misalignment

Your consent notice describes the purposes for which you process data and the parties with whom you share it. If you add a new vendor or if an existing vendor changes how they process data, your consent notice may no longer accurately reflect your processing activities. Invalid consent = invalid processing.

Cross-Border Exposure

Many vendors host data or process it outside India. While the DPDP Act currently permits cross-border transfers to most countries, the framework allows the Central Government to restrict transfers to specific countries at any time. If your vendor moves data to a country that gets restricted, you have a compliance problem you did not know you had.

Retention Mismatches

Your retention policy says delete customer data after 2 years. Your CRM vendor retains backup data for 7 years. Your email marketing vendor never deletes unsubscribed contacts. These mismatches mean your retention obligations are being violated by vendors whose policies you never reviewed.

THIRD-PARTY DPA & COMPLIANCE

Do All Your Third-Party Processors Have DPDPA-Compliant DPAs?

Automate vendor security questionnaires, clause-by-clause DPA gap analysis, and ongoing risk monitoring across your entire software supply chain.

Platform Features

What PrivacyOS Vendor Risk Management Covers

Vendor Inventory and Classification

Before you can assess vendor risk, you need to know who your vendors are. PrivacyOS maintains a centralised vendor inventory that captures:

  • • Vendor name, type, and primary service
  • • What personal data they receive from you
  • • What Data Principal categories are affected
  • • What processing purposes they perform
  • • Where they host and process data (country, region)
  • • Whether they use sub-processors
  • • Contract status and renewal dates
  • • DPA status (signed, pending, not in place)

Vendors are classified by risk level based on the volume and sensitivity of personal data they process, their access to India-specific identifiers (Aadhaar, PAN), whether they process children's data, and whether they involve cross-border data transfers.

Vendor Risk Assessment Questionnaires

PrivacyOS provides pre-built assessment questionnaires aligned to DPDPA requirements. Questionnaires cover:

Data Protection Practices:

  • • How does the vendor collect, process, and store personal data?
  • • What security safeguards are in place (encryption, access controls, monitoring)?
  • • What is the vendor's breach detection and notification process?
  • • Does the vendor conduct its own security audits or penetration tests?

Contractual Compliance:

  • • Does the vendor have a valid Data Processing Agreement in place?
  • • Are sub-processing restrictions documented and enforced?
  • • Are data deletion obligations upon contract termination specified?
  • • Are breach notification timelines and procedures defined?

Technical Security (Rule 6 Alignment):

  • • Encryption at rest and in transit
  • • Multi-factor authentication and role-based access controls
  • • Audit logging and monitoring
  • • Backup and disaster recovery protocols
  • • Vulnerability management and patching

Cross-Border and Regulatory:

  • • Where is data hosted and processed?
  • • Are cross-border transfer mechanisms documented?
  • • Does the vendor comply with sector-specific regulations (RBI, IRDAI)?
  • • Has the vendor been subject to regulatory action or data breaches?

Questionnaires are sent to vendors electronically, responses are tracked, and incomplete assessments trigger follow-up reminders.

Data Processing Agreement (DPA) Tracking

A signed DPA is the legal foundation of your vendor relationship under DPDPA. PrivacyOS tracks:

  • • DPA status for every vendor (signed, under review, expired, not in place)
  • • DPA version and last update date
  • • Key clauses: processing purposes, security obligations, sub-processing restrictions, breach notification timelines, data deletion requirements, audit rights
  • • Expiry and renewal alerts
  • • Gap analysis — what clauses are missing or non-compliant

Vendors without signed DPAs are flagged as high-risk. Vendors with outdated DPAs are flagged for renewal. Your legal team sees exactly which agreements need attention.

Vendor Risk Scoring

Each vendor receives a risk score based on their assessment responses, DPA status, data processing scope, and compliance history. The scoring model considers:

  • • Volume and sensitivity of personal data processed
  • • Presence of India-specific identifiers (Aadhaar, PAN)
  • • Cross-border data transfer involvement
  • • Security posture (from assessment responses)
  • • DPA completeness and currency
  • • History of breaches or regulatory actions
  • • Sub-processor chain depth

Risk levels (Low, Medium, High, Critical) determine the frequency and depth of ongoing monitoring. Critical-risk vendors receive quarterly reassessments. Low-risk vendors receive annual reviews.

Ongoing Compliance Monitoring

Vendor risk is not a one-time assessment. Your vendor's security posture, processing activities, and compliance status change over time. PrivacyOS supports ongoing monitoring through:

  • Periodic reassessment cycles — configurable by risk level (quarterly, semi-annual, annual)
  • Incident monitoring — track publicly reported breaches, regulatory actions, and compliance failures affecting your vendors
  • DPA renewal tracking — automated alerts before DPA expiry
  • Data flow changes — if your data discovery module detects new data flows to a vendor, the vendor's assessment is triggered for update
  • Sub-processor notifications — track when vendors add or change sub-processors

Remediation Workflows

When a vendor assessment reveals gaps — missing DPA clauses, inadequate security controls, undocumented sub-processors — PrivacyOS creates remediation tasks with:

  • • Specific gap identified
  • • Required action
  • • Owner assignment (your team or vendor contact)
  • • Deadline
  • • Status tracking (open, in progress, completed, overdue)
  • • Escalation alerts for overdue items

You can track remediation progress for each vendor individually and across your entire vendor portfolio.

Centralised Vendor Compliance Dashboard

Your DPO, legal team, and procurement team need different views of vendor risk. PrivacyOS provides a centralised dashboard showing:

  • • Total vendor count with risk distribution (how many Low, Medium, High, Critical)
  • • DPA coverage (% of vendors with signed, current DPAs)
  • • Assessment completion rates
  • • Open remediation items by vendor and by priority
  • • Vendors with cross-border data transfers
  • • Vendors processing children's data
  • • Upcoming DPA renewals and reassessment deadlines

When the Board asks about your third-party risk programme, this dashboard — and the evidence behind it — is your answer.

Targeted Scrutiny

Vendor Types That Need the Most Attention

Not all vendors carry equal risk. These categories require the most rigorous assessment under DPDPA:

Cloud Infrastructure Providers (AWS, Azure, GCP, Indian hosting)

They host your databases. They hold the keys to your data. Their security posture is your security posture. Cross-border hosting locations must be documented.

Payment and Financial Processors

Handle sensitive financial and identity data. Subject to both DPDPA and RBI regulations. Breach exposure is acute.

CRM and Marketing Platforms

Process customer names, emails, phone numbers, purchase history, and behavioural data. Often retain data longer than your policy allows. Consent alignment is critical.

HR and Payroll Systems

Process employee personal data including identity documents, bank details, salary information, and health-related data. Often involve sub-processors for benefits administration, insurance, and tax filing.

Analytics and Advertising Platforms

Track user behaviour across websites and apps. Cookie consent must cover these vendors explicitly. Data sharing for ad targeting must be purpose-linked.

EdTech and Student Information Systems

If processing children's data, additional Section 9 obligations apply. Vendors must enforce restrictions on tracking and profiling minors.

Logistics and Delivery Partners

Receive customer names, addresses, phone numbers, and order details. Often overlooked in vendor assessments despite processing significant personal data volumes.

Connected Ecosystem

How Vendor Risk Connects to Your Full Compliance Programme

  • Consent Management — Your consent notice describes who you share data with. Adding or changing a vendor may require updating your notice and collecting re-consent. Vendor inventory feeds consent notice accuracy.
  • Data Discovery & Classification — Data flow mapping shows which vendors receive personal data, what data they receive, and for what purpose. New data flows to vendors trigger assessment updates.
  • DSR Automation — Erasure requests require deletion by vendors too. Vendor DPAs must include deletion obligations and timelines. PrivacyOS tracks vendor-side deletion as part of DSR fulfilment.
  • Breach Response — Vendor breaches trigger your notification obligation. Vendor DPAs must include immediate breach notification to you. PrivacyOS integrates vendor breach alerts with your incident management workflow.
  • DPIA — DPIAs assess risks from third-party processing. Vendor risk scores feed directly into DPIA risk assessments for processing activities involving external processors.
  • Compliance Dashboards — Vendor risk metrics are part of your overall compliance posture. DPA coverage, assessment completion, and remediation status are tracked alongside consent, DSR, and breach metrics.
Best Practices

Common Vendor Risk Mistakes

!

Mistake 1: Treating vendor risk as a procurement problem.

Procurement negotiates price and service terms. Vendor risk management assesses data protection compliance. These are different functions with different expertise requirements. Your privacy or compliance team must be involved in vendor assessments — not just contract negotiations.

!

Mistake 2: Assessing only at onboarding.

A vendor assessed two years ago may have changed their hosting provider, added sub-processors, suffered a breach, or changed their security practices. One-time assessment is not risk management. Ongoing monitoring is.

!

Mistake 3: Ignoring sub-processors.

Your vendor's word that they "handle everything in-house" is not verification. Request sub-processor disclosure. Verify data flows. Document the chain. A breach at a sub-processor you never assessed is still your regulatory exposure.

!

Mistake 4: Accepting self-reported security claims.

A vendor's website says "bank-grade encryption" and "ISO 27001 certified." Have you verified? Have you reviewed the certificate scope? Have you tested their API security? Self-reported claims need independent verification — through questionnaires, audit rights in DPAs, or third-party security assessments.

!

Mistake 5: No DPA or an inadequate DPA.

A signed NDA is not a DPA. A standard service agreement is not a DPA. A Data Processing Agreement must specifically cover processing purposes, security obligations, sub-processing restrictions, breach notification, data deletion, and audit rights. PrivacyOS tracks DPA completeness and flags gaps.

Frequently Asked Questions

Know Your Vendors Before the Board Asks About Them

The Data Protection Board will not ask whether you have a privacy policy. They will ask whether your vendors comply with it. They will ask for your DPAs. They will ask how you assessed your processors. They will ask what you did when a vendor fell short.

PrivacyOS builds the evidence for those answers — vendor inventory, risk assessments, DPA tracking, ongoing monitoring, and remediation documentation. Your vendor programme becomes defensible, not just documented.