You can outsource the processing.You cannot outsource the liability.
Section 8(1) keeps the Data Fiduciary responsible, whoever does the work.
In one line: Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.
Their breach. Your penalty.
The scene
The analytics SDK was added in an afternoon by a growth engineer. It collected device identifiers, location and in-app events, and sent them to a server abroad. There was no contract, only terms of service accepted with a click. Three years later it was still there, and still sending.
Where the thinking breaks
Cross-border transfers
Section 16 permits transfers outside India except to countries the Government restricts by notification. Sectoral rules, such as those on payment data, can be stricter and continue to apply.
Monday morning
- 01Pull the list of every vendor that touches personal data.
- 02Mark which have a DPDPA-grade processing contract. Most will not.
- 03Start with the ones that hold the most people, not the biggest invoice.
Questions, answered plainly
Is a Data Fiduciary liable for its Data Processor under DPDPA?
Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.
Does DPDPA require a contract with Data Processors?
Yes. Section 8(2) allows a Data Fiduciary to engage a Data Processor only under a valid contract.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner