All templates
Internal Registers & TrackersSection 8(2)
Vendor Risk Register Template
A register to assess and monitor the DPDP-related risk posture of every data processor and sub-processor engaged.
Template
VENDOR RISK REGISTER Organization: [Organization Name] Maintained By: [Procurement / DPO / Legal] Scope: All vendors and sub-processors that process personal data on behalf of [Organization Name] 1. PURPOSE Section 8(2) of the DPDP Act, 2023 requires a Data Fiduciary to ensure a valid contract is in place before engaging a Data Processor, and holds the Data Fiduciary accountable for processing done on its behalf. This register tracks each vendor's contractual coverage, data handling scope, and risk rating so that engagements can be reviewed and re-assessed on a defined cycle. 2. INSTRUCTIONS Add a vendor to this register before any personal data is shared with them, not after. Re-assess risk rating at renewal or whenever the scope of processing changes materially. 3. REGISTER Column headers: Vendor Name | Service Provided | Personal Data Shared | Contract in Place (Y/N, Date, DPA Clause Ref) | Sub-Processors Used (Y/N, Named) | Cross-Border Processing (Y/N, Country) | Security Certification (e.g. ISO 27001) | Last Due-Diligence Date | Risk Rating (Low/Medium/High) | Next Review Date | Owner Example Row 1: Vendor Name: [Cloud Hosting Provider] Service Provided: Application hosting and database storage Personal Data Shared: All customer account and transaction data Contract in Place: Y - [DD-MM-YYYY], Data Processing Addendum clause [X] Sub-Processors Used: Y - [Named regional data center operator] Cross-Border Processing: Y - [Country] Security Certification: ISO 27001, SOC 2 Type II Last Due-Diligence Date: [DD-MM-YYYY] Risk Rating: Medium Next Review Date: [DD-MM-YYYY] Owner: [Vendor Manager Name] Example Row 2: Vendor Name: [Payroll Processor Pvt. Ltd.] Service Provided: Payroll processing and payslip generation Personal Data Shared: Employee bank details, PAN, salary Contract in Place: Y - [DD-MM-YYYY], Data Processing Addendum clause [X] Sub-Processors Used: N Cross-Border Processing: N Security Certification: [ISO 27001] Last Due-Diligence Date: [DD-MM-YYYY] Risk Rating: Low Next Review Date: [DD-MM-YYYY] Owner: [HR Lead] Example Row 3: Vendor Name: [Customer Support Chat Platform] Service Provided: Live chat and ticketing Personal Data Shared: Name, email, chat transcripts Contract in Place: Y - [DD-MM-YYYY], Data Processing Addendum pending amendment for Section 8(2) alignment Sub-Processors Used: Y - [Named AI translation vendor] Cross-Border Processing: Y - [Country] Security Certification: SOC 2 Type I Last Due-Diligence Date: [DD-MM-YYYY] Risk Rating: High - contract amendment overdue Next Review Date: [DD-MM-YYYY] Owner: [Vendor Manager Name] 4. DUE-DILIGENCE CHECKLIST (APPLY AT ONBOARDING AND RENEWAL) - Written contract obligates the vendor to process only on documented instructions - Vendor confirms security safeguards consistent with baselines under the DPDP Rules, 2025 (encryption, access logging, retention of access logs for at least one year) - Vendor discloses any sub-processors and cross-border transfer locations - Vendor commits to assist [Organization Name] in meeting breach intimation timelines under Section 8(6) - Vendor commits to return or verifiably erase personal data on contract termination 5. RISK RATING DEFINITIONS Low: Limited or non-sensitive data, no cross-border transfer, strong certification. Medium: Broader data scope or cross-border transfer with adequate contractual coverage. High: Sensitive data categories, unresolved contractual gaps, or unverified sub-processors - escalate to DPO for remediation plan.
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.