Vendor risk: the DPDP Act obligations you can’t outsource
By DPDP Manager Enterprise Team · 2 April 2026 · 5 min read
Under the Act, the Data Fiduciary remains accountable for how personal data is processed, even when the actual processing happens inside a third-party vendor’s systems. A vendor breach is still your compliance event.
A practical vendor risk programme starts with an inventory: which vendors actually touch personal data, what categories, and under what contractual terms. This sounds basic and is exactly the step most organisations skip.
From there, the questions that matter are less about the vendor’s marketing claims and more about specifics: breach notification timelines, sub-processor visibility, and what happens to your data if the contract ends.
Our Compliance Consulting engagements typically start here, because vendor risk gaps are the single most common finding in an initial DPDP readiness assessment.