InfraVeritas360DPDPiq

DPDP Insights › The law › Section 8(1)–(2)

The law

Section 8(1)–(2): Responsibility for vendors

The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.

What it means in your sector

Questions where this section matters

Official text: Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (MeitY). The DPDP Rules were notified on 13 November 2025. Consent Manager rules start on 13 November 2026. Most duties, including notice, security, breach reporting, retention, children's data and rights, start on 13 May 2027. A proposal discussed in early 2026 to bring this date forward had not been notified when this page was last reviewed.

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.