AMLEGALS — Strategic Lawyering
Standing Register — Reviewed and Dated

The DPDPA Vendor Claims Register

India has no DPDPA certification body. No notified auditor panel. No product level conformity scheme. Yet the market is being sold certificates, readiness badges and compliance guarantees. This register tests the language against the statute.

10 Claim TypesSection 8(1)12 Diligence QuestionsClaims, Not Companies

Section 8(1) places compliance on the Data Fiduciary notwithstanding any agreement to the contrary. Every claim that a product carries your obligation runs into that sentence and stops.

The Position in One Paragraph

Why this register exists

Neither the Digital Personal Data Protection Act, 2023 nor the DPDP Rules, 2025 establishes a certification scheme for products, platforms or vendors. No accreditation body has been notified. No auditor empanelment or audit methodology has been published under Rule 13.

Compliance attaches to the Data Fiduciary. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary.

That single sentence disposes of most of the claims a procurement team will encounter this year. Products are useful. Some are excellent. None of them can hold your obligation.

This register does not name companies. It tests claim types, so that a buyer can ask a better question before signing.

The Register

Ten Claims, Tested Against the Text

DPDP Certified

No legal meaning

The Legal Position

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 do not establish a certification scheme for products or vendors, and no accreditation body has been notified. A private certificate is a statement by the issuer about the issuer's own opinion. It binds no regulator and it transfers no liability.

What to Ask

Name the certifying body, the standard applied, the scope statement and the date. Then check whether that body derives any authority from the Act or the Rules.

DPDP Compliant Software

Category error

The Legal Position

Compliance under the Act attaches to a Data Fiduciary, not to a product. Section 8(1) places the obligation on the Data Fiduciary to comply irrespective of any agreement to the contrary and irrespective of any failure of the Data Principal to perform their duties. Software can support compliance. It cannot hold it.

What to Ask

Ask the vendor to identify the section of the Act that the product discharges on the buyer's behalf. There is none.

Audit Ready

Premature

The Legal Position

The audit obligation arises for a Significant Data Fiduciary under Section 10 read with Rule 13, and applies from 13 May 2027. No auditor empanelment, methodology or reporting format has been notified. Readiness for an audit whose standard does not yet exist is an aspiration, not a specification.

What to Ask

Ask which audit, under which rule, against which published methodology. Ask for the sample report.

Consent Manager Platform

Not yet possible

The Legal Position

A Consent Manager is a person registered with the Data Protection Board under Rule 4, which commences on 13 November 2026. Until registration is granted, no entity in India is a Consent Manager. A consent management product is a product. The two are not interchangeable.

What to Ask

Ask whether the vendor holds a Rule 4 registration. If it does not, ask whether it satisfies the conflict of interest condition in Part A of the First Schedule at all.

We Take On Your DPDPA Liability

Unenforceable in substance

The Legal Position

Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a processor, notwithstanding any agreement to the contrary. A contractual indemnity may allocate cost between the parties. It cannot move the statutory obligation.

What to Ask

Read the liability cap. In most privacy technology contracts it is twelve months of fees, against a statutory ceiling of ₹250 crore.

Data Localised in India, So Compliant

Confuses two regimes

The Legal Position

Section 16 permits transfer outside India except to a country or territory restricted by the Central Government by notification, and preserves any higher restriction under another law. Localisation may be required by sectoral regulation. It is not, by itself, the test of DPDPA compliance for anything else.

What to Ask

Ask for the data flow map, including sub processors, support access, backups and analytics endpoints. Localisation of the primary database proves little on its own.

ISO 27001 and SOC 2, Therefore DPDPA Ready

Necessary, not sufficient

The Legal Position

Information security certifications evidence a security management system. Section 8(5) requires reasonable security safeguards, so they are relevant and useful. They say nothing about notice under Section 5, consent under Section 6, rights under Sections 11 to 14, retention under Rule 8 or breach intimation under Rule 7.

What to Ask

Ask the vendor to map each certification control to the specific section or rule it is said to satisfy. The gaps appear immediately.

Consent Available in 22 Languages, As Required

Misstates the obligation

The Legal Position

Section 5(3) entitles the Data Principal to access the notice in English or any language specified in the Eighth Schedule to the Constitution. The right of choice belongs to the Data Principal, which makes provision an obligation of the Data Fiduciary rather than an option. A translation library is a component of that obligation, not the discharge of it.

What to Ask

Ask how the language choice is offered, recorded and honoured on subsequent communications, not merely how many translations exist.

Automated DPDPA Gap Assessment

Useful input, not an opinion

The Legal Position

A questionnaire driven tool produces a score from the answers it is given. It does not determine lawful basis, it does not construe Section 7, and it cannot be relied on before the Board. Legal advice on the application of a statute to facts is an opinion, and it requires a person who can stand behind it.

What to Ask

Ask who signs the output, in what capacity, and whether they will appear if the position is challenged.

Government Approved

Requires proof

The Legal Position

Approval, empanelment or recognition under the Act must trace to a notified instrument. Registration under a different statute or with a different regulator is not approval under DPDPA. Neither is participation in a consultation, a sandbox or an industry body.

What to Ask

Ask for the notification number and date. If none exists, the claim should be withdrawn.

Reverse Diligence

Twelve Questions Before You Sign

Published free. Use it in your request for proposal. A vendor that answers all twelve in writing is worth talking to. A vendor that cannot answer the first three is not.

Buyer Side Question Set

  1. 01Which sections of the Act and which rules does this product actually operate on, stated one by one
  2. 02Are you a Data Processor or a Data Fiduciary in this engagement, and what determines the answer
  3. 03Produce your Section 8(2) processor terms before commercial negotiation, not after
  4. 04List every sub processor, its location, its function and the basis on which it is engaged
  5. 05Show the data flow map including support access, backups, logs, analytics and model training
  6. 06How does the product evidence consent in a form that could be produced to the Board
  7. 07How does it record and honour withdrawal, and does withdrawal propagate to sub processors
  8. 08How does it satisfy the rights response inside the Rule 14 window across all systems it touches
  9. 09How does it execute retention and erasure, and does it support a pre erasure intimation
  10. 10What is your breach notification commitment to us, and how does it sit inside the Rule 7 clock
  11. 11What is the liability cap, what is excluded, and how does that compare to the Schedule ceilings
  12. 12On exit, in what format is our data returned, and what is your certified deletion process
A Note on Fairness

This Is Not an Attack on Privacy Technology

India will not reach 13 May 2027 without good software. Consent capture, rights fulfilment, retention engines and audit logging all have to be built, and buying is usually faster than building.

The problem is not the product. It is the sentence on the landing page that tells a buyer their obligation has been discharged by a purchase order.

A vendor that describes precisely what its product does, and precisely what remains with the customer, is more valuable than one that promises compliance. The first is a partner. The second is a future dispute.

Ask for the boundary in writing. The good vendors are relieved to give it.

Vendor Assessment Under Engagement

Where a live procurement needs a legal reading of a specific claim, a Section 8(2) processor term set, or a negotiation position on liability, AMLEGALS acts for the buyer.

Request a Confidential Briefing

Our data privacy counsel will reach out within one working day.

Insights & Answers

What buyers and procurement teams are asking

Is there any DPDPA certification in India?

No. Neither the Act nor the DPDP Rules, 2025 establishes a certification scheme for products, platforms or vendors, and no accreditation body has been notified for that purpose. A private certificate reflects the opinion of the issuing body. It does not bind the Data Protection Board, and it does not move the statutory obligation, which Section 8(1) places on the Data Fiduciary notwithstanding any agreement to the contrary.

Can software make a company DPDPA compliant?

No. Compliance attaches to the Data Fiduciary. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor, irrespective of any agreement to the contrary. Software can operate consent capture, rights fulfilment, retention and logging. It cannot hold the obligation.

Does a vendor indemnity protect against a DPDPA penalty?

An indemnity allocates cost between the contracting parties. It does not alter the statutory position, and a penalty imposed for a company's own statutory breach is generally not effectively indemnifiable, since indemnity against the consequence of one's own wrong is regarded as opposed to public policy. Most privacy technology contracts also cap liability at twelve months of fees, against ceilings extending to two hundred and fifty crore rupees under the Schedule to Section 33.

What should a buyer ask a DPDP vendor before signing?

Twelve things, in this order. The sections and rules the product operates on. Whether the vendor is processor or fiduciary. The Section 8(2) terms produced before commercial negotiation. The sub processor list. The data flow map including support access and backups. How consent is evidenced. How withdrawal propagates. How rights are answered inside the Rule 14 window. How retention and erasure execute. The breach commitment inside the Rule 7 clock. The liability cap and exclusions. The exit and deletion process.

Is this register naming specific vendors?

No. The register tests claim types, not companies. The purpose is to give buyers a legal reading of the language the market uses, so that a procurement team can ask better questions. Where a specific claim needs assessment for a live procurement, that is advisory work and it is done under engagement.

Are ISO 27001 and SOC 2 useful for DPDPA?

Yes, as evidence toward the reasonable security safeguards required by Section 8(5), and they are worth having. They do not address notice under Section 5, consent under Section 6, rights under Sections 11 to 14, retention under Rule 8 or breach intimation under Rule 7. Ask the vendor to map controls to sections. The gaps become visible in one page.

When will a real audit standard exist?

Rule 13 requires a Significant Data Fiduciary to undertake a Data Protection Impact Assessment and an audit periodically, and to observe due diligence in respect of algorithmic software. The substantive obligations commence on 13 May 2027. Until an empanelment or methodology is notified, the honest description of any audit offering is that it is a private methodology, and it should be named as such.

How often is this register updated?

It is reviewed as the market language changes and as instruments are notified. Each entry states the position under the Act and the Rules as they stand. Where a notification changes the answer, the entry is revised and dated rather than quietly replaced.