started · updated
India's DPDP Act maintains data accountability for businesses using third-party vendors
Under India’s Digital Personal Data Protection Act (DPDP Act) of 2023, businesses remain legally accountable for personal data even when processing is outsourced to third-party vendors. While companies often utilize cloud providers, SaaS platforms, and payment processors to manage data, the law stipulates that the 'Data Fiduciary'—the entity determining the purpose and means of processing—retains non-delegable statutory responsibility.
Although contracts may allocate operational duties or provide for indemnities, they cannot transfer legal accountability from the fiduciary to the 'Data Processor'. The DPDP Rules, 2025, notified by the Ministry of Electronics and Information Technology in November 2025, reinforce this by requiring fiduciaries to ensure processors implement equivalent security safeguards. Substantive obligations are expected to be phased in through May 2027, providing a window for businesses to audit and formalize vendor arrangements.