DPDP NavigatorAct 2023 · Rules 2025
All templates
Internal Registers & TrackersSection 8(2)

Vendor Risk Register Template

A register to assess and monitor the DPDP-related risk posture of every data processor and sub-processor engaged.

Template
VENDOR RISK REGISTER

Organization: [Organization Name]
Maintained By: [Procurement / DPO / Legal]
Scope: All vendors and sub-processors that process personal data on behalf of [Organization Name]

1. PURPOSE

Section 8(2) of the DPDP Act, 2023 requires a Data Fiduciary to ensure a valid contract is in place before engaging a Data Processor, and holds the Data Fiduciary accountable for processing done on its behalf. This register tracks each vendor's contractual coverage, data handling scope, and risk rating so that engagements can be reviewed and re-assessed on a defined cycle.

2. INSTRUCTIONS

Add a vendor to this register before any personal data is shared with them, not after. Re-assess risk rating at renewal or whenever the scope of processing changes materially.

3. REGISTER

Column headers: Vendor Name | Service Provided | Personal Data Shared | Contract in Place (Y/N, Date, DPA Clause Ref) | Sub-Processors Used (Y/N, Named) | Cross-Border Processing (Y/N, Country) | Security Certification (e.g. ISO 27001) | Last Due-Diligence Date | Risk Rating (Low/Medium/High) | Next Review Date | Owner

Example Row 1:
Vendor Name: [Cloud Hosting Provider]
Service Provided: Application hosting and database storage
Personal Data Shared: All customer account and transaction data
Contract in Place: Y - [DD-MM-YYYY], Data Processing Addendum clause [X]
Sub-Processors Used: Y - [Named regional data center operator]
Cross-Border Processing: Y - [Country]
Security Certification: ISO 27001, SOC 2 Type II
Last Due-Diligence Date: [DD-MM-YYYY]
Risk Rating: Medium
Next Review Date: [DD-MM-YYYY]
Owner: [Vendor Manager Name]

Example Row 2:
Vendor Name: [Payroll Processor Pvt. Ltd.]
Service Provided: Payroll processing and payslip generation
Personal Data Shared: Employee bank details, PAN, salary
Contract in Place: Y - [DD-MM-YYYY], Data Processing Addendum clause [X]
Sub-Processors Used: N
Cross-Border Processing: N
Security Certification: [ISO 27001]
Last Due-Diligence Date: [DD-MM-YYYY]
Risk Rating: Low
Next Review Date: [DD-MM-YYYY]
Owner: [HR Lead]

Example Row 3:
Vendor Name: [Customer Support Chat Platform]
Service Provided: Live chat and ticketing
Personal Data Shared: Name, email, chat transcripts
Contract in Place: Y - [DD-MM-YYYY], Data Processing Addendum pending amendment for Section 8(2) alignment
Sub-Processors Used: Y - [Named AI translation vendor]
Cross-Border Processing: Y - [Country]
Security Certification: SOC 2 Type I
Last Due-Diligence Date: [DD-MM-YYYY]
Risk Rating: High - contract amendment overdue
Next Review Date: [DD-MM-YYYY]
Owner: [Vendor Manager Name]

4. DUE-DILIGENCE CHECKLIST (APPLY AT ONBOARDING AND RENEWAL)

- Written contract obligates the vendor to process only on documented instructions
- Vendor confirms security safeguards consistent with baselines under the DPDP Rules, 2025 (encryption, access logging, retention of access logs for at least one year)
- Vendor discloses any sub-processors and cross-border transfer locations
- Vendor commits to assist [Organization Name] in meeting breach intimation timelines under Section 8(6)
- Vendor commits to return or verifiably erase personal data on contract termination

5. RISK RATING DEFINITIONS

Low: Limited or non-sensitive data, no cross-border transfer, strong certification.
Medium: Broader data scope or cross-border transfer with adequate contractual coverage.
High: Sensitive data categories, unresolved contractual gaps, or unverified sub-processors - escalate to DPO for remediation plan.

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.