Cloud service provider privacy checklist for Indian businesses
A practical checklist for Indian teams reviewing cloud providers, contracts, security evidence and DPDP-ready vendor governance.
Data>Nuance
Cloud contracts can hide a privacy elephant in a very tidy dashboard.
Indian businesses rarely buy only storage or compute when they choose a cloud service provider. They also buy a chain of operational decisions about access, support, sub-processors, incident evidence, deletion and where personal data may travel. Under the Digital Personal Data Protection Act, 2023, the Data Fiduciary remains accountable for deciding why and how personal data is processed, while processors and vendors must be held to instructions that can be shown later.
A useful review therefore looks beyond glossy security pages. It asks whether the provider can support the organisation's notice, consent, retention, grievance, security and incident-response positions in practice. The checklist below is written for procurement, legal, privacy and security teams that need a joined record before onboarding, renewal or audit.
What to review
Start with the processing map. Identify which personal data will enter the cloud service, who the individuals are, why the data is processed, and which business owner approved that purpose. Confirm whether the provider is acting only on instructions or also making its own decisions about analytics, product improvement, fraud checks or support diagnostics.
Review the contract against the operational reality. The agreement should cover permitted processing, confidentiality, security measures, support access, sub-processors, location and transfer disclosures, breach notification, deletion or return, audit cooperation and assistance with rights or grievance workflows. If the provider gives only standard terms, record the gaps and decide whether compensating controls are acceptable.
Ask for evidence that privacy and security commitments can be performed. Useful evidence includes access-control descriptions, encryption positions, logging and retention information, incident escalation paths, sub-processor lists, certification reports where available, and deletion mechanics. Evidence should be current enough to support the onboarding decision.
Implementation steps
Create a vendor review file before the service goes live. Attach the data-flow note, business purpose, contract version, source materials, risk decision and control owner. This keeps the review from becoming a procurement memory exercise six months later.
Classify the service by data sensitivity and operational dependency. A low-risk collaboration tool may need a lighter review than a cloud database holding customer records, employee information or production logs. The review depth should follow the risk of harm, access breadth, data volume and incident impact.
Translate contractual commitments into controls. If the contract promises deletion within a period, assign someone to request and verify deletion at offboarding. If the provider relies on sub-processors, set a review rhythm for list changes. If breach notice depends on a portal alert, ensure the security and privacy teams know who monitors it.
Keep the decision reviewable. Note what was accepted, what was rejected and what must be checked again at renewal. A short, specific risk memo is more useful than a long checklist with every box ticked by habit.
Common mistakes
- Treating a cloud provider's public security page as a substitute for contract and implementation review.
- Accepting vague breach-notification wording without testing how alerts reach privacy, legal and security owners.
- Forgetting offboarding controls, especially export, deletion confirmation, retained backups and support-ticket data.
How DataNuance can help
DataNuance helps Indian organisations turn cloud procurement into a defensible privacy record: data-flow mapping, vendor-risk review, processor instructions, contract gap notes and renewal evidence. For a focused review of a high-risk provider or a repeatable checklist for your procurement team, speak with DataNuance.
FAQs
Is a cloud service provider always a processor under the DPDP Act?
Not always. The answer depends on what the provider does with the personal data and whether it acts only on the organisation's instructions. Standard hosting may look like processor activity, while provider-controlled analytics, product improvement or fraud decisions may require closer analysis. Record the role instead of assuming it.
What documents should we ask a cloud provider for?
Ask for the contract, data processing terms, sub-processor list, security and access-control summary, incident notification process, data-location information, deletion or return procedure and any current independent assurance reports. The goal is enough evidence to decide and monitor the risk, not a document collection contest.
How often should cloud vendor privacy reviews be refreshed?
Refresh the review before renewal, material service expansion, migration of new data categories, sub-processor changes, significant incidents or major legal updates. High-risk providers should also have a scheduled annual review so ownership does not disappear after onboarding.
Who should own the checklist internally?
Procurement can coordinate the file, but privacy, security, legal and the business system owner should each own their part. Privacy should confirm purpose and individual-facing duties, security should test safeguards, legal should review terms, and the business owner should accept residual risk.
This publication is general information and is not legal advice for a specific organisation or matter.
