Your customer trusts you.You trust twenty others.
The chain is only as defensible as its least-documented link.
In one line: DPDPA does not use the term, but a processor engaging another entity to process data on the fiduciary's behalf creates a chain that the fiduciary remains responsible for. Contracts should govern each link.
Every tool your engineers love is a link in someone else's liability.
The scene
The enterprise buyer asked for a sub-processor list. The team produced nine. Engineering found twenty-three: log aggregation, error tracking, a support widget, two email services and a translation API that had seen customer tickets for a year.
Where the thinking breaks
Logs are data
Debug logs and error traces routinely capture names, emails and payloads. Treat observability tools as processors and scrub before sending.
Monday morning
- 01Trace one customer record through every tool it touches.
- 02Update the sub-processor list.
- 03Add scrubbing to logs.
Questions, answered plainly
What is a sub-processor under DPDPA?
DPDPA does not use the term, but a processor engaging another entity to process data on the fiduciary's behalf creates a chain that the fiduciary remains responsible for. Contracts should govern each link.
Do SaaS logs contain personal data?
Often. Logs, error traces and support tickets can capture identifiers and content. They should be minimised, secured and included in data maps.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner