DPDP NavigatorAct 2023 · Rules 2025
All guides
Rights & Grievances

Responding to a Rights Request That Implicates a Third-Party Data Fiduciary

26 Jul 20269 min read

When a Section 11 or Section 12 request touches data another organization shared with you, or that you shared onward, the response depends on the contract behind that relationship.

Two different third-party scenarios, two different obligations

A rights request can implicate a third party in two distinct ways. The first is when you rely on a Data Processor to hold or process part of the data in question, and you need information from that processor to answer the request fully. The second is when the personal data came from, or was shared with, another Data Fiduciary entirely, which is a different relationship with different obligations attached to it.

Treating these two situations the same way is a common mistake. A processor works under your instructions and your contract; another Data Fiduciary is an independent party with its own obligations under the Act, and you cannot simply direct it the way you can direct a processor.

Getting what you need from a Data Processor

Section 8(2) gives you the basis for this: where a Data Fiduciary needs information from a Data Processor to meet its obligations, it obtains that information under the existing contract between them. That means the contract you already have in place with the processor should specify how and how quickly the processor must respond to this kind of request from you - if it does not, that is a gap worth fixing in the next contract renewal, and in the meantime, escalate directly with the processor as soon as the rights request comes in rather than waiting until close to your own deadline.

Build processor response times into your own internal timeline planning, since if a processor is slow to hand back what you need, that slowness still counts against your obligation to the Data Principal, not the processor's.

Handling a request that touches another Data Fiduciary's data

Where the data in question was shared with, or received from, another Data Fiduciary, your Section 11 obligation includes identifying that other fiduciary to the Data Principal as part of the access response - but you generally cannot unilaterally correct or erase data that the other fiduciary independently controls and processes under its own basis. The right move is to be transparent with the Data Principal about which parts of their request you can act on directly and which parts require them to also approach the other fiduciary.

If your relationship with that other fiduciary involves an ongoing data-sharing arrangement, it is worth establishing, ahead of time, a point of contact and an expected process for when a rights request touches shared data, rather than improvising that coordination the first time it actually happens.

Where to go next

The Vendor Assessment tool is a good starting point for reviewing whether your processor contracts actually specify response obligations for rights requests, which is the gap that causes the most friction in these situations.