Introduction

Modern businesses increasingly rely on third-party infrastructure to operate: cloud storage providers, artificial intelligence platforms, payment processors and HR systems now hold, transmit or process significant volumes of personal and business data on behalf of the organisations that engage them. This arrangement is efficient, but it does not change where legal responsibility for that data sits. When a vendor’s system is compromised, the resulting exposure, regulatory, contractual and reputational, is typically borne by the business that engaged the vendor, not the vendor alone.

Accountability Under the DPDP Act Is Not Contractually Transferable

Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), a Data Fiduciary, meaning the entity that determines the purpose and means of processing personal data, remains responsible for compliance with the Act in respect of processing carried out on its behalf by a Data Processor. Section 8(1) of the DPDP Act makes this responsibility non-delegable: it applies irrespective of any agreement to the contrary. In other words, a contract with a vendor may allocate operational responsibility for handling data, and may even provide for indemnities in the event of a failure, but it cannot, as a matter of law, transfer the Data Fiduciary’s own statutory accountability to the vendor.

This principle is broadly comparable to Article 24 of the General Data Protection Regulation, though the DPDP Act’s non-derogable framing leaves less room for a business to argue that contractual allocation reduces its own exposure. With the DPDP Rules, 2025 having been notified in November 2025 and substantive obligations being phased in through May 2027, businesses have a defined runway to put vendor arrangements in order before enforcement intensifies.

Risk Varies by the Type of Data Involved

Not all data carries the same level of legal or regulatory exposure, and vendor risk should be assessed accordingly. Customer and personal data attract obligations under the DPDP Act and, where applicable, other privacy regimes, including breach-notification and penalty exposure. Employee data raises additional considerations around confidentiality and potential workforce-related claims. Financial and transaction data is often subject to sector-specific requirements, such as those issued by the Reserve Bank of India or the Securities and Exchange Board of India, layered on top of contractual liability. Proprietary business data, while not personal data in the statutory sense, carries its own risks around misuse, competitive harm and breach of confidence.

A practical starting point for any business is to map which categories of data a given vendor can access, since the applicable legal obligations, and the consequences of a failure, differ meaningfully across these categories.

The Vendor Contract as the Primary Risk-Allocation Tool

A data-processing arrangement is often treated as a procurement formality, but it functions as the primary mechanism through which data-related risk is allocated between a business and its vendor. A well-drafted arrangement should address liability for data breaches, loss and misuse, with caps that are commercially meaningful rather than nominal, since a modest liability cap offers limited protection against a breach of significant scale. It should also specify minimum security standards and technical controls, rather than general or aspirational language.

Equally important are provisions on incident response, including reporting timelines, forensic cooperation and regulatory notification; visibility and consent requirements for sub-processors and onward data transfers; genuine audit and inspection rights rather than rights that exist only on paper; and clear terms on data retention, deletion and return, including what happens to the data when the relationship ends. Where these terms are absent or weak, the business engaging the vendor remains exposed even though the underlying failure occurs within the vendor’s own systems.

Governance Should Continue Beyond Contract Signature

Because accountability remains with the business regardless of what the contract says, the assessment of vendor risk should not end once an agreement is signed. Businesses would benefit from periodically reviewing which vendors can access their more sensitive categories of data, whether the contractual protections in place remain adequate as the relationship and the data involved evolve, and whether vendor compliance is being monitored through recurring audits rather than a one-time onboarding check. Incident-response mechanisms are also more useful when tested through periodic exercises, rather than left as an untested clause in a contract.

AMLEGALS Remarks

As businesses continue to rely on external vendors for core functions, it is worth remembering that the DPDP Act places non-delegable responsibility on the Data Fiduciary, regardless of contractual arrangements with a processor. Businesses should accordingly treat vendor data-processing agreements as a central risk-management tool, ensuring they contain meaningful liability provisions, defined security standards, clear breach-notification timelines, and workable audit, retention and exit mechanics, rather than standard-form terms carried over from a general procurement template.

With the DPDP Rules, 2025 being phased in through May 2027, businesses would benefit from using this period to review existing vendor arrangements, categorise the data each vendor can access, and put in place ongoing oversight mechanisms, so that vendor relationships are compliance-ready well before enforcement takes full effect.

For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com

Leave a Reply

Your email address will not be published. Required fields are marked *

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.