InfraVeritas360DPDPiq

DPDP Insights › Questions › What must a vendor contract say about personal data?

Question

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract.

Steps

  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.

Evidence to keep

Common mistakes

How it plays out by sector

From each seat

What a good answer from management sounds like

“Our top vendors have data terms with a short incident-notice time, and we review them every year.” Effort and time: Medium · 8 to 16 weeks for the top vendors.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.