Vendor privacy review under the DPDP Act
A practical vendor privacy review guide for Indian businesses assessing processors, SaaS tools, data flows and DPDP operating evidence.
Data>Nuance
Vendor reviews are where privacy optimism goes to meet the procurement spreadsheet.
For Indian businesses, a vendor privacy review should answer a simple question: can this supplier process personal data in a way the organisation can understand, evidence and defend? Under the DPDP Act, a Data Fiduciary remains responsible for processing undertaken by it or on its behalf, and a Data Processor processes personal data on behalf of that fiduciary. That makes vendor review an operating control, not a box in the onboarding portal.
What to review
Start with role classification. A vendor may be a Data Processor for hosting, support, payroll or analytics work, while acting as an independent Data Fiduciary for account administration or its own compliance records. The contract and data map should reflect those distinctions instead of treating every supplier as the same type of processor.
Review the purpose and data scope. The vendor should receive only the data categories, user access and retention period needed for the service. Check whether the service touches customer data, employee data, children, authentication records, support tickets, logs, backups or exported reports. The more invisible the processing is to business users, the more explicit the review should be.
Security safeguards need evidence, not adjectives. Ask how access is approved, how privileged accounts are controlled, whether logs are retained, how data is encrypted, how vulnerabilities are managed and how deletion is performed. If the answer is a brochure, ask for something that proves the control actually operates.
Also check operational fit. A vendor can have strong paperwork and still fail your workflow if notices go to the wrong inbox, deletion requires a support escalation, or exports depend on one administrator. Capture those practical limits before approval, while procurement still has leverage.
Implementation steps
- Build a vendor intake form that captures service purpose, data categories, system access, geography, subprocessors, retention and business owner.
- Classify the vendor role for each processing activity. Record whether the supplier acts as a processor, independent fiduciary or mixed-role provider.
- Compare processing scope against notices, consent flows, legitimate-use assumptions and the internal data map. Remove unnecessary fields and access before go-live.
- Review contract clauses for valid processing instructions, security safeguards, confidentiality, breach support, subprocessor control, erasure, audit evidence and exit assistance.
- Ask for security evidence proportionate to risk: assurance reports, policy extracts, access-control descriptions, incident summaries, encryption details or deletion certificates.
- Set a renewal trigger. High-risk vendors should be reviewed after major product changes, subprocessor changes, incidents, acquisition activity or material changes to data volume.
- Capture decisions in one place. The review file should show who approved the risk, what exceptions remain open, and when the next review is due.
- Feed outcomes into incident and DSAR workflows. A vendor review is incomplete if nobody knows whom to contact when records must be retrieved, corrected, erased or preserved.
Common mistakes
- Approving a vendor because the commercial owner says the tool is already in use.
- Treating a security questionnaire as evidence without checking whether answers map to the actual service.
- Forgetting subprocessors until a breach notice reveals the data took a connecting flight nobody booked.
How DataNuance can help
DataNuance helps Indian organisations turn vendor privacy review into a repeatable operating model. We assess roles, data flows, contract clauses, safeguards, breach support, subprocessor risk and evidence packs so legal, procurement and security teams can make consistent decisions. For a focused review of your vendor privacy process, contact DataNuance.
FAQs
Is every SaaS supplier a Data Processor under the DPDP Act?
No. Many SaaS suppliers process customer data on behalf of the business, but some also decide their own purposes for account, billing, analytics or compliance records. Classify the role by activity, not by vendor name.
What evidence should a low-risk vendor provide?
For a low-risk vendor, a short control description, privacy terms, retention position, contact route and confirmation of limited personal data may be enough. Higher-risk vendors need stronger security, breach and deletion evidence.
How often should vendor privacy reviews be refreshed?
Refresh critical vendors at least at renewal and whenever processing, subprocessors, geography, product features or incidents materially change. Lower-risk vendors still need a periodic check so the register does not become stale.
Who should own the vendor privacy review?
Privacy should own the method, but procurement, legal, security and the business owner must share the decision. The person buying the tool understands the purpose; privacy and security test whether the data risk is acceptable.
Sources
This publication is general information and is not legal advice for a specific organisation or matter.
