Where legal and procurement start on DPDP third-party risk
Legal and procurement teams doing third-party privacy management for the first time can start with this eight-step sequence.
What is inside
- 01The eight steps, by functionProcurement and finance, the privacy office, legal and the business owner, each holding the steps that are theirs and handing off in order.
- 02What each step produces, and what stops itPer step, the artifact it hands to the next one and the point at which it most often stalls.
- 03What to ask before signing, and what to check afterwardsThe questions that test a vendor before signing, the provisions that go into the contract, the checks once it is live, and how often to repeat them.
- 04The chain, and where responsibility staysThe Data Fiduciary, the Data Processor and everything further down the chain, with the section that keeps the duty where it is.
Procurement holds step one, and the sheet names who holds each of the seven after it.
Free DPDP Implementation Workshop
A 90-minute session for your team, on-site or remote: the DPDP Act applied to your organization, a 90-day implementation roadmap, a consent case study, peer readiness, and the top five actions per department.
Book the workshopWant DPDP Vendor Management Guide applied to your organization?
We run a free DPDP implementation workshop for enterprise teams.
- 90 minutes
- On-site or remote
- Top 5 actions per department
Free tools
No sign-up, nothing to install.
