The DPDP checks a data processor has to pass
A processor runs through seven gates in order, and the tree gives the action to take whenever an answer comes back no.
What is inside
- 01The decision treeFrom whether the vendor processes personal data at all to whether every finding is registered, owned and dated. A vendor comes out of the tree either cleared or with the risk recorded, owned and accepted.
- 02The clauses a processor contract has to carryThe provisions the Act and the Rules name, grouped by the question each answers: the contract itself, what the processor does with the data, where it goes next, and when it ends.
- 03What sends a vendor to the front of the queueA fork on the three kinds of processing that go first whatever the volume, and the order for everything else.
- 04What a completed vendor record looks likeFour vendors run through the seven gates, as the register would show them a quarter in.
Start with the contract on your desk and run it through the seven gates.
Free DPDP Implementation Workshop
A 90-minute session for your team, on-site or remote: the DPDP Act applied to your organization, a 90-day implementation roadmap, a consent case study, peer readiness, and the top five actions per department.
Book the workshopWant DPDP Vendor Risk Tree applied to your organization?
We run a free DPDP implementation workshop for enterprise teams.
- 90 minutes
- On-site or remote
- Top 5 actions per department
Free tools
No sign-up, nothing to install.
