Vendor and processor liability under DPDP
Under the DPDP Act, you remain responsible for personal data even when a third party processes it for you. Every analytics tool, payment provider, email service, and cloud vendor that touches your users' data is your liability as the Data Fiduciary. You need an inventory of these processors and a data processing agreement with each one.
The liability does not pass down
Modern products are assembled from other people's services. Each integration that receives personal data extends your responsibility without extending your control. The Act does not let you push liability down the chain. If a processor mishandles data you handed it, the obligation traces back to you.
Two parts to compliance
The first is visibility. You cannot govern processors you have not listed, and most companies underestimate how many they use. Analytics, session recording, customer support, marketing automation, payment, shipping, cloud hosting, and a long tail of smaller tools all qualify if they receive personal data. The inventory has to be complete.
The second is contract. Each processor relationship needs a data processing agreement that binds the vendor to the same standards the Act holds you to, covering purpose limitation, security, breach notification back to you, and deletion on request. An agreement you signed years ago for a different purpose rarely covers this.
The engineering dimension
When a user erases their data, that erasure has to reach your processors, which means your rights portal needs to propagate deletion outward, not just clean your own database.
"Map every vendor, paper every relationship, and wire deletion to flow through all of them."
Next step
Find out how compliant your product is.
Ten questions covering consent, data rights, security, and breach readiness. Takes two minutes.
Start the readiness check →Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.