AMLEGALS — Strategic Lawyering

DPDPA Data Processors: Your Vendor's Breach Is Your Breach

DPDPA Data Processors: Your Vendor's Breach Is Your Breach

Their breach. Your penalty.

The scene

The analytics SDK was added in an afternoon by a growth engineer. It collected device identifiers, location and in-app events, and sent them to a server abroad. There was no contract, only terms of service accepted with a click. Three years later it was still there, and still sending.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

The vendor's terms cover us.

Their terms protect them. Section 8(2) requires a valid contract for engaging a processor.

Your paper, your terms, your audit right.

SDKs aren't vendors.

Anything that receives personal data on your behalf is processing it.

Inventory every SDK and pixel as a processor.

Cloud is the provider's problem.

Shared responsibility still leaves configuration, access and keys with you.

Know which half of the model is yours.

Cross-border transfers

Section 16 permits transfers outside India except to countries the Government restricts by notification. Sectoral rules, such as those on payment data, can be stricter and continue to apply.

Monday morning

01 Pull the list of every vendor that touches personal data.

02 Mark which have a DPDPA-grade processing contract. Most will not.

03 Start with the ones that hold the most people, not the biggest invoice.

Questions, answered plainly

Is a Data Fiduciary liable for its Data Processor under DPDPA? +

Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.

Does DPDPA require a contract with Data Processors? +

Yes. Section 8(2) allows a Data Fiduciary to engage a Data Processor only under a valid contract.

Argument 07 Privacy is not a department. It is a board decision. Read →

Argument 08 ₹250 crore is not a line item. It is a balance-sheet event. Read →

Argument 01 Implementation ends on a date. Resilience begins on it. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).