What must a vendor contract say about personal data?
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
What the law says
Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(6) · Rule 7: On becoming aware of a personal data breach, tell each affected person and the Data Protection Board without delay. Send the Board a detailed report within 72 hours, or a longer period if the Board allows on request.
Section 8(7) · Rule 8: Erase personal data when its purpose is over or consent is withdrawn, unless a law requires you to keep it, and have your processors erase it too. Rule 8(3) asks every Data Fiduciary to keep personal data, traffic data and logs for at least one year for purposes listed in the Rules.
Steps
List vendors who receive or can see personal data.
Rank them by how much and how sensitive.
Add a data-protection schedule to each contract, starting with the top ten.
Ask for evidence: certificates, test results, deletion confirmations.
Review the top vendors every year.
Evidence to keep
Vendor register
Signed data-protection schedules
Annual review notes
Common mistakes
Relying on the vendor's standard terms
No incident-notice time
No exit and deletion clause
How it plays out by sector
Banking, financial services and insurance: Collection agencies, BCs, DSAs, KYC vendors, card processors and the core banking vendor all need data schedules aligned with RBI outsourcing rules.
IT, ITeS, BPO and GCC: Sub-contractors working on client data need the same terms you signed with the client.
Manufacturing: Manpower agencies, transporters, canteen operators and dealer software vendors.
From each seat
DPO / Privacy lead: Keep the vendor register with IT and Procurement. You decide which vendors carry the most personal-data risk and need review first.
CISO / Security head: Set the technical schedule: incident notice in hours, logging, MFA, sub-contractor approval. Ask for evidence once a year.
CIO / IT head: Your architecture decisions decide which vendors see data. Prefer designs that send vendors only what they need.
CEO / MD: Ask for the top ten vendors by personal data held. If the list takes weeks to produce, that is the first gap.
Director: Ask which three vendors hold the most personal data, and when their contracts were last reviewed.
Legal & compliance: Draft one data-protection schedule and use it for every contract that involves personal data.
Chief risk officer: Vendor risk is usually the largest single item. Track the top vendors as separate risk lines.
IT department: Check vendor access is named, time-bound and logged.
Administration department: Security, housekeeping, transport and CCTV vendors all touch personal data. Their contracts need data terms.
Finance department: Payroll, payment and collection vendors hold sensitive data. Check their contracts.
Marketing department: Agencies, ad platforms and event partners receive data. Their contracts need data terms.
Legal department: Keep a standard data-protection schedule and insist on it.
Procurement department: Add the data-protection schedule to every purchase that involves personal data, and do not sign without it.
What a good answer from management sounds like
“Our top vendors have data terms with a short incident-notice time, and we review them every year.” Effort and time: Medium · 8 to 16 weeks for the top vendors.