DPDP NavigatorAct 2023 · Rules 2025
All guides
Role-Based Playbooks

DPDP for Procurement Teams: Vetting New Vendors Before They Touch Personal Data

18 Jul 20268 min read

Procurement is the choke point where a bad vendor relationship can be stopped cheaply, or waved through expensively. A practical intake checklist.

Procurement is the earliest checkpoint you have

By the time a business team has already started using a new tool and asks procurement to 'formalise the contract,' the leverage to negotiate proper data-protection terms has mostly evaporated — and personal data may already be flowing to the vendor. The highest-value moment for a DPDP check is at intake, before a purchase order or trial account exists.

This doesn't mean procurement needs to become a legal or security team. It means adding a small number of standard questions to every new-vendor intake form, so that vendors touching personal data are flagged and routed for deeper review automatically, rather than depending on someone remembering to ask.

Questions worth adding to intake

Will this vendor receive, store, or process personal data belonging to our employees, customers, or candidates? If yes, what categories — this single question, asked consistently, does most of the triage work.

Where is the vendor's infrastructure hosted, and does the vendor use its own sub-processors? Section 16 gives the government power to restrict transfers to specific notified countries, so vendors with unclear or shifting hosting locations deserve a closer look.

Does the vendor have its own security certifications or, at minimum, a documented security practice you can review? This doesn't need to be a lengthy audit at intake — it needs to exist as a gate before onboarding, not a retrofit after an incident.

Contracting before onboarding, not after

Make Section 8(2)-consistent contract terms — purpose limitation, security commitments, breach notification, sub-processor visibility, deletion at termination — a standard rider attached to any vendor agreement flagged as touching personal data, rather than something legal drafts from scratch each time.

Resist pressure to activate a vendor's production access before the contract is signed 'because the team needs it this week.' Trial accounts and pilots often turn into de facto production use without ever going back through procurement, which is exactly how personal data ends up with an unvetted vendor.

Keeping the vendor list honest over time

Vendors get re-evaluated at renewal in most procurement processes — use that moment to re-check whether the vendor's data-handling footprint has changed (new sub-processors, new features that pull more data) rather than auto-renewing based purely on price and service level.

Maintain a simple flag in your vendor management system distinguishing vendors that touch personal data from those that don't, so audits and incident response don't have to start from zero every time.

Where to go next

Route flagged vendors through the Vendor Assessment as a standard part of intake, and keep contract and review evidence current in the Evidence Tracker.