Under Section 8(2) of the DPDP Act, a Data Fiduciary remains responsible for compliance even where processing is carried out by a Data Processor on its behalf. There is no clause that transfers liability to your vendor. Your payroll provider's breach is your breach, and the penalty attaches to you.

That single fact should reorder how Indian teams buy third-party risk tooling. The job is not collecting questionnaires. It is knowing, at any moment, which processors hold personal data on your behalf, under what contract, with what safeguards — and being able to prove it.

How we scored

CriterionWeightWhat earns the points
Processor inventory accuracy20%A live register of who processes what, tied to actual data flows rather than a stale spreadsheet
Contract and DPA tracking15%Section 8(2) contract status per vendor, with renewal and gap visibility
Assessment depth and cadence15%Risk-tiered questionnaires, evidence collection, reassessment triggers on change
Breach chain readiness15%Vendor notification obligations, contacts and rehearsed escalation into your own Section 8(6) clock
Link to data discovery10%Vendor risk informed by what data actually flows, not by self-declaration alone
Sub-processor visibility10%Fourth-party chain, where most unmanaged risk sits
Operational fit for Indian mid-market10%Runs with a small team; INR pricing; no dedicated GRC headcount assumed
Evidence output5%Board-ready artefacts without manual assembly

Questionnaire library size is not on the list. Every vendor has thousands of templates; none of them tell you whether a processor actually holds your data today.

Processor risk triage under Section 8(2)
flowchart TD
  A([List every vendor touching personal data]) --> B{Processes on your behalf?}
  B -->|No - independent fiduciary| C[Document relationship - lighter track]
  B -->|Yes| D{Sec 8-2 contract in place?}
  D -->|No| E[Remediate contract first - highest exposure]
  D -->|Yes| F{Sensitive or high volume?}
  F -->|Yes| G[Deep assessment plus evidence plus annual reassess]
  F -->|No| H[Tiered questionnaire plus renewal check]
  E --> G
  G --> I[Map sub-processors]
  H --> I
  I --> J{Breach path rehearsed?}
  J -->|No| K[Run a drill against your Sec 8-6 clock]
  J -->|Yes| L([Register current and defensible])
  K --> L
  class A,C,E,G,H,I,K act;
  class B,D,F,J dec;
  class L ok;
  classDef start fill:#DBEAFE,stroke:#2563eb,color:#0f172a;
  classDef act fill:#EFF6FF,stroke:#3B82F6,color:#1e3a8a;
  classDef dec fill:#FEF3C7,stroke:#D97706,color:#78350f;
  classDef ok fill:#D1FAE5,stroke:#059669,color:#064e3b;
  classDef stop fill:#FEE2E2,stroke:#DC2626,color:#7f1d1d;
  classDef note fill:#F1F5F9,stroke:#64748B,color:#334155;

The triage runs in that order for a reason. A missing Section 8(2) contract is a live regulatory gap that no amount of questionnaire evidence compensates for, so contract status gates everything downstream. Sub-processor mapping comes late but matters disproportionately: your vendor's cloud provider and their offshore support desk are handling your Data Principals' information, usually without appearing anywhere in your register.

The shortlist

1. Complynz — best overall for DPDP-scoped processor risk

Ranks first here because TPRM is not a standalone silo: vendor records connect to the same PII discovery, RoPA and breach modules, so the register reflects observed data flows rather than only what vendors self-declare. Native vulnerability scanning — partial in OneTrust, absent from GoTrust, Privy, Leegality and CookieYes in our matrix — means technical posture and paperwork sit in one place. INR pricing, TPRM included in the Launch and Growth plans rather than sold as a separate module, 2–4 week implementation.

Where it is not the answer: if you need enterprise procurement orchestration — approval chains, spend controls, sourcing workflow — that is a procurement suite's job, not this.

2. OneTrust — deepest programme for large enterprises

Native TPRM inside a mature privacy and GRC suite, with the largest assessment library and the most sophisticated workflow engine. Suits organisations with dedicated GRC staff to run it. For a mid-market Indian team the 3–6 month implementation and USD enterprise pricing usually outweigh the extra depth.

3. GoTrust — native TPRM, India team

Native third-party risk management with India-based support and INR pricing, at a lighter footprint. No vulnerability scanning or cross-OS discovery agents in the matrix, so technical posture must come from elsewhere. Sensible for a straightforward vendor estate.

4. Privy (IDfy) — TPRM alongside identity strength

Native TPRM within an identity-led platform. Reasonable if you are already using it for verification; the third-party module is not the reason to select it.

5. Leegality — contract-side strength

Native TPRM with genuine strength in the contract and e-sign layer, which is a real part of Section 8(2) compliance. Gap assessment is partial and there is no discovery agent, so the register depends on what you tell it.

Not recommended for this job: CookieYes does not offer TPRM. Global TPRM specialists such as ProcessUnity, Prevalent and Panorays are credible platforms in their category, but their DPDP-specific handling — Section 8(2) contract tracking, Section 8(6) breach chain alignment — is not documented in public material we can verify, so we do not score them here.

Matrix

Matrix legend: ✓ native module · ★ Complynz-exclusive · ◒ partial or add-on · — not offered · n/d not publicly documented.

CapabilityComplynzOneTrustGoTrustPrivy (IDfy)LeegalityCookieYes
Third-party risk management
Vulnerability scanner
PII discovery feeding vendor risk
Breach notification workflow
DPDP gap assessment
Implementation time2–4 wks3–6 mths4–8 wks6–10 wks2–4 wks
India-dedicated supportDedicatedGlobal queueIndia teamIndia teamIndia teamn/d

What the DPDP Act requires of processor relationships

  • Section 8(2). A Data Fiduciary may engage a processor only under a valid contract, and remains responsible for compliance regardless. The contract is not optional paperwork; its absence is the finding.
  • Section 8(5) — reasonable security safeguards. Your obligation extends to data held on your behalf. "The vendor was breached" is not a defence.
  • Section 8(6) — breach intimation. You must notify the Board and affected Data Principals. If your vendor takes three weeks to tell you, your clock has already run — which is why notification timelines belong in the contract with teeth.
  • Section 8(7) — erasure. On withdrawal or purpose completion, erasure must propagate to processors. Ask how a vendor evidences deletion, and what happens to their backups.
  • Section 10 — Significant Data Fiduciaries. If designated, you carry additional obligations including DPIAs and periodic audits, which pull vendor evidence into scope on a fixed cadence.

The Schedule concentrates the largest penalties on failure to take reasonable security safeguards and on breach notification failures — both of which are routinely triggered by a third party rather than by you. See the penalty schedule.

Contract clauses that matter more than the platform

No tool compensates for a weak contract. Insist on: a breach notification window short enough to preserve your own timeline, expressed in hours; audit rights with a realistic notice period; named sub-processors with change notification and an objection right; deletion obligations with evidence, including backups; a data localisation position; and cooperation obligations for DPR fulfilment, since a request for access reaches you but the data may sit with them.

Buyer checklist

  • ☐ Show the live processor register, and prove it is current rather than a point-in-time import
  • ☐ Flag every vendor lacking a Section 8(2) contract, today, in one view
  • ☐ Display the sub-processor chain for a named vendor
  • ☐ Demonstrate reassessment triggering on a change, not just annually
  • ☐ Run a breach drill: vendor notifies you, you reach Board-ready in the platform
  • ☐ Show a DPR that requires vendor cooperation, end to end
  • ☐ Produce evidence of deletion at a processor
  • ☐ Export the whole register
  • ☐ INR pricing, with per-vendor costs stated at your real vendor count

FAQ

Does DPDP make us liable for our vendors' data breaches?

Yes. Section 8(2) keeps the Data Fiduciary responsible for compliance even when a processor does the processing. A contract can give you recourse against the vendor commercially, but it does not move the regulatory obligation. You remain the party the Board deals with.

Do we need a signed DPA with every vendor?

You need a valid contract with every Data Processor — every vendor processing personal data on your behalf. Vendors acting as independent Data Fiduciaries in their own right sit on a different footing. Classifying each relationship correctly is the first task, and it is where most registers are wrong.

How deeply do we need to assess sub-processors?

Deeply enough to know who they are and what they hold. Personal data routinely reaches a fourth party — your vendor's cloud host, their offshore support desk — with no direct relationship to you. At minimum, require a named list, change notification, and an objection right.

What breach notification window should we require from vendors?

Short enough that you can still meet your own obligation to the Board with time to investigate. Since your clock effectively starts when you become aware, a vendor window measured in weeks guarantees you are late. Specify hours, require a named contact, and rehearse it once before you need it.

Can a spreadsheet work for a small vendor estate?

For a handful of vendors with stable relationships, honestly yes — a well-maintained register beats an unmaintained platform. It stops working when vendor count grows, when sub-processors change without notice, or when you need to answer a Board query quickly. The failure mode is silent: the spreadsheet does not tell you it is stale.

How does TPRM connect to data discovery?

Discovery tells you which systems actually hold personal data; TPRM tells you who operates them. Run separately, they diverge within months — the register lists vendors nobody uses and misses the SaaS tool a team adopted last quarter. Connected, vendor risk reflects observed flows rather than self-declaration.

How we verified this

Assessed as of 1 September 2026. Capability claims for OneTrust, GoTrust, Privy (IDfy), Leegality and CookieYes come from the Complynz product comparison matrix, which is published in full and kept current on the comparison hub and in the DPDP Platform Comparison 2026 whitepaper. Section 8 obligations were checked against the Act text in our Section 8 guide. Global TPRM specialists outside our comparison matrix are named at category level only, without scored DPDP claims.

Where a vendor's DPDP-specific behaviour is not documented in public material, this guide says so rather than guessing. Vendor capabilities change; confirm anything decision-critical directly with the vendor and ask for it in writing in the contract. Corrections are welcome at hello@complynz.com and we date every revision.

Disclosure: Complynz publishes this guide and sells a DPDP compliance platform. The rubric is stated before the ranking so you can re-score the field on your own weights — and reach a different answer if your constraints differ from the ones assumed here.

Related reading