Vendor & processor governance
Their breach is your penalty
You stay accountable for every supplier that handles data on your behalf. No contract clause moves that to them.
Book a demo See what happens when a DPA lapses Or check your DPDP score first — free, five minutes, no account.
Who else touches your data?
The list is longer than procurement’s, and you are accountable for every name on it.
The reference lab, the TPA, the pharmacy, housekeeping, and the visiting consultants who see patients weekly.
Your cloud provider, your email service, your analytics tool, and the support platform your customers write into.
The background-check agency, the payroll bureau, and the job board that receives every candidate you post.
§8(2)
What the Act actually asks of you
Two obligations, one sentence of statute, and most vendor programmes satisfy neither of them properly.
01
Only under a valid contract
A data processing agreement is the instrument. Not a purchase order, not an email agreeing terms, not a signed quotation with a confidentiality line in it.
02
You remain the Data Fiduciary
Engaging a processor moves the work, never the duty. Their failure is assessed against you, and the Board looks at what you did about it.
03
Their breach is your Rule 7
When a processor is compromised, the duty to intimate the Board without delay and to notify affected people is yours. You inherit the clock, not the excuse.
There is no processor defence in the DPDP Act. “Our vendor did it” is a fact about how it happened, not an answer to whether you are liable.
The difference
A score ranks the problem. A block prevents it.
Most vendor tools grade your suppliers and leave you to act. This one stops the sharing while the paperwork is wrong.
01
The DPA lapses, sharing stops
The moment an agreement moves out of active, every purpose that vendor was covering is blocked. You find out because the block is visible, not months later in an audit.
02
Scope creep stops it too
A vendor reaching beyond the purposes their link covers is a mismatch, and a mismatch blocks in exactly the same way as a missing contract.
03
Renewal lifts it everywhere
When the agreement is renewed, every link for that vendor unblocks at once. One vendor, one contract state, however many purposes it touches.
This is the argument for governing processors in the same system that holds your consent records. A tool that only knows about vendors can tell you a contract expired. A tool that also knows what that vendor was authorised to do can stop the sharing it authorised.
The register
Every processor, and what covers them
One row per vendor per purpose, with the contract behind it and the state that contract is in.
1
Linked to what they actually do
A vendor is not recorded in the abstract. Each link names the notice and the specific purposes that vendor supports, so “what are they allowed to touch” has a written answer rather than an assumption.
2
Contract state, plainly
Active, expired, or missing entirely — and missing is the honest state for the suppliers most organisations have never papered. The register shows it rather than leaving the row blank.
3
Renewal before the block
A still-active agreement inside thirty days of expiry is raised in the DPO’s queue, so the contract is renewed before sharing stops rather than after somebody notices it has.

Where the gaps are
The processors that never reach procurement
Vendor registers are usually built from the accounts payable ledger, which is the wrong source for this question.
01
Visiting professionals
Consultants, locums and contract staff who see your customers every week and appear on no software list anywhere.
02
Facilities and housekeeping
Anyone with physical access to a records room or a reception desk is processing personal data, whatever the contract calls them.
03
The tool one team signed up for
A scheduling app or a survey tool bought on a card, holding customer contact details, that nobody in compliance has heard of.
04
Your agency and their agency
Marketing partners routinely subcontract. The chain matters, because your accountability does not stop at the party you signed with.
05
The one who left
A former supplier still holding an export from two years ago is still a processor, and still your exposure.
Two ways to get this done
Your team, or our lawyers
If you have just recognised your own supplier list above, the drafting does not have to wait for anyone to build a feature.
01
Agreements drafted for you
Our empanelled privacy lawyers write the §8(2) processing agreements for your actual supplier list, in the language your procurement team already uses.
02
Their paper, reviewed
When a large vendor insists on their own agreement, we read it and tell you which clauses §8(2) requires that it does not contain, and what to ask for.
03
Due diligence before you sign
A questionnaire suited to what that processor will actually touch, run before onboarding rather than discovered during an incident.
04
Your register, populated
We load your existing supplier list into the platform during onboarding, so nobody on your side types a hundred vendors in by hand.
05
A DPO who carries it
If you would rather not own this at all, our DPO service holds the vendor programme and reports to you. The register stays yours either way.
Each of these is also being built into the platform, so the routine cases stop needing a person. Until then the work is done, not deferred — and where our own template library is concerned, it is drafted and with Indian privacy counsel now, which is why this page does not yet call it counsel-reviewed.
§16 · Rule 15
Processors outside India
DPDP does not work like the GDPR here, and the difference changes what you have to do about a foreign vendor.
01
No adequacy list to check
Transfer abroad is permitted except to countries the government restricts. The model is a blacklist, so there is no approval to obtain before you begin.
02
The notice still has to say so
A cross-border transfer has to be disclosed in the notice covering that data. A silent notice with a foreign data processor behind it is the mismatch worth finding.
03
Sector rules sit on top
Where your regulator already restricts where data may sit — and several Indian regulators do — that obligation is unaffected by anything in the DPDP Act.
Most organisations discover an unpapered processor during an incident.
See the register, a blocked vendor, and a scope mismatch caught before the sharing happened — on live screens rather than slides.
Evidence
Proving you governed them
The question is never whether a vendor failed. It is what you had in place before they did.
01
Coverage at a point in time
Which processors were engaged, under what contract state, covering which purposes. The answer for a date in the past, not just for today.
02
What you did about a gap
A scope check run, an expiry raised, sharing blocked and later restored — each recorded when it happened rather than reconstructed afterwards.
03
It feeds the audit pack
Vendor coverage is one of the sections in the compliance evidence package, hashed alongside the rest so the whole thing can be verified as one document.
Questions
About vendor and processor governance
Our vendor leaked customer data. Who is liable?
You are. §8(2) keeps the Data Fiduciary accountable for every Data Processor acting on its behalf, and permits engaging one only under a valid contract. There is no processor defence in the Act. The duty to intimate the Board without delay and to notify affected people is yours as well — you inherit their incident and its clock. What the Board will weigh under §33(2) is what you had in place beforehand and what you did once you knew.
Do we need a DPA with every single supplier?
With every one that processes personal data on your behalf, which is a wider set than most procurement lists. Your payroll bureau, your reference lab, your cloud provider, your marketing agency, the housekeeping firm with access to a records room, the scheduling app one team bought on a card. A supplier who never touches personal data — a stationery vendor — does not need one. That is the practical difference between a third-party risk programme built for security questionnaires and one built for §8(2): the question is not how critical a supplier is to you, it is whether they touch personal data on your behalf.
Do you score vendors for risk?
Not today, and we would rather be straight about it than show you a number with nothing behind it. What the platform does is stricter than a score: when an agreement lapses or a vendor’s access exceeds the purposes it covers, sharing is blocked rather than ranked. A score tells you which vendor to worry about. A block means the thing you were worried about cannot happen while the paperwork is wrong.
What happens when a DPA expires?
Sharing under every purpose that vendor covers is blocked, and it stays blocked until the data processing agreement is renewed. Before that point, a still-active agreement inside thirty days of expiry is raised in the DPO’s queue, so the normal path is renewal rather than interruption. Renewing lifts the block across every link for that vendor at once.
Can we use a foreign processor?
Yes, unless the government has restricted that country. DPDP works as a blacklist rather than an adequacy list, so there is no prior approval to obtain. Two things still apply: the notice covering that data has to disclose the transfer, and any sector rule your own regulator imposes about where data may sit is untouched by the Act.
Can you draft our processing agreements?
Our consultants do this as a service today, and the DPA builder inside the platform is on the roadmap. The templates behind it are drafted and awaiting Indian privacy counsel sign-off — which is why this page does not call them counsel-reviewed yet.
What compliance teams tell us
Real client quotes, attributed by role and sector — we never name a client.
DPDP, explained properly
DPDP in India: The Complete Guide to Data Protection Compliance, DPDP Guidelines and Automated Compliance Management (2026)
3 September 2026 · 35 min read DPDP ActHealthcare Vendor Governance Under India’s DPDP Act: The Complete 2026–27 Compliance Framework
27 August 2026 · 32 min read DPDP ActDPDP vs GDPR Compliance Tool: What’s Actually Different, and What a Tool Needs to Handle Both
26 August 2026 · 34 min readWorking across
Find the unpapered one first.
A live register with a blocked vendor, an expiry raised before it bit, and a scope mismatch caught — on real screens rather than slides.


