Your customer trusts you.You trust twenty others.

The chain is only as defensible as its least-documented link.

In one line: DPDPA does not use the term, but a processor engaging another entity to process data on the fiduciary's behalf creates a chain that the fiduciary remains responsible for. Contracts should govern each link.

The estate · SaaS & IT servicesHover to inspect

Every tool your engineers love is a link in someone else's liability.

The scene

The enterprise buyer asked for a sub-processor list. The team produced nine. Engineering found twenty-three: log aggregation, error tracking, a support widget, two email services and a translation API that had seen customer tickets for a year.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
Our cloud provider is our only sub-processor. Anything that receives client personal data counts. Map from data flows, not from invoices.
Standard terms flow down automatically. Obligations must be contracted into each link. Flow down in writing. Audit the top five.

Logs are data

Debug logs and error traces routinely capture names, emails and payloads. Treat observability tools as processors and scrub before sending.

Monday morning

  1. 01Trace one customer record through every tool it touches.
  2. 02Update the sub-processor list.
  3. 03Add scrubbing to logs.

Questions, answered plainly

What is a sub-processor under DPDPA?

DPDPA does not use the term, but a processor engaging another entity to process data on the fiduciary's behalf creates a chain that the fiduciary remains responsible for. Contracts should govern each link.

Do SaaS logs contain personal data?

Often. Logs, error traces and support tickets can capture identifiers and content. They should be minimised, secured and included in data maps.

Sector · SaaS & IT servicesYou think you're the processor. Your contract may disagree.Read → SaaS & IT services · Deep diveThe moment you decide why, you are the fiduciary.Read → SaaS & IT services · Deep diveThe DPDPA questionnaire is the new security review.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner