All templates
PoliciesSection 8
Third-Party Data Sharing Policy Template
An internal governance policy setting the standards, approvals, and due-diligence steps required before sharing personal data externally.
Template
THIRD-PARTY DATA SHARING POLICY [Organization Name] Effective Date: [Effective Date] | Policy Owner: [DPO / Legal] 1. PURPOSE This Policy governs how [Organization Name] shares personal data with external parties — processors, business partners, and other data fiduciaries — ensuring compliance with Section 8(2) of the DPDP Act, 2023, which requires that any processing on our behalf by another person be governed by a valid contract. 2. SCOPE Applies to all business functions proposing to share personal data with any third party, whether for processing on our behalf (a "Processor" relationship) or for the third party's own independent purposes (a "Joint/Independent Fiduciary" relationship). 3. CLASSIFICATION OF THIRD-PARTY RELATIONSHIPS a. Processor: acts solely on our documented instructions (e.g., cloud hosting provider, payroll processor, SMS gateway). Governed by a Data Processing Agreement (DPA). b. Independent Data Fiduciary: determines its own purpose and means of processing shared data (e.g., an insurance partner underwriting a policy using data we share). Governed by a Data Sharing Agreement (DSA) allocating each party's DPDP Act obligations. 4. PRE-SHARING DUE DILIGENCE Before any personal data is shared externally, the requesting Business Owner must complete a Third-Party Data Sharing Assessment covering: a. Necessity: is sharing this data category necessary for the stated purpose, and can a lesser (masked/aggregated) dataset achieve the same purpose? b. Legal basis: is the underlying processing covered by valid consent or a Section 7 legitimate use that extends to this sharing? c. Security posture: does the third party maintain security safeguards proportionate to the data's classification tier (see Data Classification Policy)? d. Cross-border factors: will the data leave India, and if so, is this consistent with Section 16 and any Government-notified restrictions? e. Sub-processing: does the third party intend to further share data with its own sub-processors, and if so, is a Sub-Processor Addendum required? 5. APPROVAL WORKFLOW a. Business Owner submits the Assessment to the Data Protection Officer and Legal. b. Legal drafts or reviews the applicable DPA/DSA (see Data Processing Agreement Template / Data Sharing Agreement Between Fiduciaries Template). c. No data is transferred until the agreement is fully executed and the DPO has recorded the third party in the Third-Party Register. 6. MANDATORY CONTRACT TERMS Every third-party agreement must include, at minimum: purpose limitation, prohibition on further sharing without consent, security safeguard obligations, breach-notification timelines to [Organization Name], audit/inspection rights, data return or erasure upon termination, and cooperation obligations to support Data Principal rights requests. 7. ONGOING MONITORING a. The Third-Party Register is reviewed [quarterly] to confirm agreements remain current and third parties remain in good standing. b. Material changes to a third party's processing activities, sub-processors, or data-hosting location require re-approval before continuing. c. Security questionnaires or audit reports are refreshed at least [annually] for high-risk (Tier 4 data) third parties. 8. TERMINATION AND OFFBOARDING Upon termination of a third-party relationship, the Business Owner must confirm data return or certified erasure within [X days], and update the Third-Party Register accordingly. 9. NON-COMPLIANCE Sharing personal data with any third party outside this Policy's approval workflow is a policy violation subject to disciplinary action and may constitute a reportable compliance failure under the Data Breach Response Policy if it results in unauthorised disclosure. 10. REVIEW This Policy is reviewed [annually] by the Data Protection Officer and Legal team. Approved by: [Name, Designation] Date: [Date]
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.