DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ Sector wise readiness

Sector wise readiness

Supply chain and vendor risk: outsourcing does not transfer accountability

Does sharing data with a vendor pass your responsibility to them?
No. Engaging a processor does not pass your responsibility to it. You remain answerable for processing carried on for you, and you must oversee it actively, whatever sector you are in.
Who this affects
Every organisation sharing data with a cloud provider, payroll vendor, agency or analytics tool.
What to do about it
Contract every vendor, know your sub processors, and treat this as the layer that sits on top of your sector map.

The final post in this series, and the one that applies to every organisation that has read any of the others.

Because whatever sector you are in, you share personal data with someone else. A cloud provider, a payroll vendor, an agency, an analytics tool. That makes this the cross cutting layer that sits on top of every sector map in this series.

And it starts with the principle people most often get wrong.

Outsourcing does not transfer accountability

Engaging a processor does not pass your responsibility to it. You remain answerable for processing carried on for you, and you must oversee it actively. "Our vendor handles that" is not a defence.

What this layer requires, on top of your sector baseline

The auditor's red flag, and the reason this post exists

Sub vendors several tiers down are often invisible. That is exactly where breaches hide, and where the 72 hour clock can quietly run out while nobody upstream knows anything has happened.

Across 28 sectors, one theme repeated more than any other. The gap was almost never a missing product. It was an unmapped relationship, an unwritten contract, or an assumption that someone else was handling it.

The better question, and the one this whole series has been building towards

Not "does this requirement exist in my sector?"

But "have I actually triggered it, and can I show who is accountable for it?"

Law creates obligations. Scale and risk influence implementation. Confusing the two is how organisations spend on tools they do not need while missing the basics.

That is the series. All 28 sectors, mapped, with statutory obligations separated from audit expectations and tooling suggestions.

If a sector you care about deserves a deeper look, tell us and we will take it.

#DPDP #DataProtection #SupplyChain #VendorRisk #Privacy #ThirdPartyRisk #DataGovernance

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Assess My Readiness