DPDP NavigatorAct 2023 · Rules 2025
All templates
PoliciesSection 8

Third-Party Data Sharing Policy Template

An internal governance policy setting the standards, approvals, and due-diligence steps required before sharing personal data externally.

Template
THIRD-PARTY DATA SHARING POLICY

[Organization Name]
Effective Date: [Effective Date] | Policy Owner: [DPO / Legal]

1. PURPOSE
This Policy governs how [Organization Name] shares personal data with external parties — processors, business partners, and other data fiduciaries — ensuring compliance with Section 8(2) of the DPDP Act, 2023, which requires that any processing on our behalf by another person be governed by a valid contract.

2. SCOPE
Applies to all business functions proposing to share personal data with any third party, whether for processing on our behalf (a "Processor" relationship) or for the third party's own independent purposes (a "Joint/Independent Fiduciary" relationship).

3. CLASSIFICATION OF THIRD-PARTY RELATIONSHIPS
   a. Processor: acts solely on our documented instructions (e.g., cloud hosting provider, payroll processor, SMS gateway). Governed by a Data Processing Agreement (DPA).
   b. Independent Data Fiduciary: determines its own purpose and means of processing shared data (e.g., an insurance partner underwriting a policy using data we share). Governed by a Data Sharing Agreement (DSA) allocating each party's DPDP Act obligations.

4. PRE-SHARING DUE DILIGENCE
Before any personal data is shared externally, the requesting Business Owner must complete a Third-Party Data Sharing Assessment covering:
   a. Necessity: is sharing this data category necessary for the stated purpose, and can a lesser (masked/aggregated) dataset achieve the same purpose?
   b. Legal basis: is the underlying processing covered by valid consent or a Section 7 legitimate use that extends to this sharing?
   c. Security posture: does the third party maintain security safeguards proportionate to the data's classification tier (see Data Classification Policy)?
   d. Cross-border factors: will the data leave India, and if so, is this consistent with Section 16 and any Government-notified restrictions?
   e. Sub-processing: does the third party intend to further share data with its own sub-processors, and if so, is a Sub-Processor Addendum required?

5. APPROVAL WORKFLOW
   a. Business Owner submits the Assessment to the Data Protection Officer and Legal.
   b. Legal drafts or reviews the applicable DPA/DSA (see Data Processing Agreement Template / Data Sharing Agreement Between Fiduciaries Template).
   c. No data is transferred until the agreement is fully executed and the DPO has recorded the third party in the Third-Party Register.

6. MANDATORY CONTRACT TERMS
Every third-party agreement must include, at minimum: purpose limitation, prohibition on further sharing without consent, security safeguard obligations, breach-notification timelines to [Organization Name], audit/inspection rights, data return or erasure upon termination, and cooperation obligations to support Data Principal rights requests.

7. ONGOING MONITORING
   a. The Third-Party Register is reviewed [quarterly] to confirm agreements remain current and third parties remain in good standing.
   b. Material changes to a third party's processing activities, sub-processors, or data-hosting location require re-approval before continuing.
   c. Security questionnaires or audit reports are refreshed at least [annually] for high-risk (Tier 4 data) third parties.

8. TERMINATION AND OFFBOARDING
Upon termination of a third-party relationship, the Business Owner must confirm data return or certified erasure within [X days], and update the Third-Party Register accordingly.

9. NON-COMPLIANCE
Sharing personal data with any third party outside this Policy's approval workflow is a policy violation subject to disciplinary action and may constitute a reportable compliance failure under the Data Breach Response Policy if it results in unauthorised disclosure.

10. REVIEW
This Policy is reviewed [annually] by the Data Protection Officer and Legal team.

Approved by: [Name, Designation] Date: [Date]

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.