Security

    If a breach happens because of a vendor or third-party system, are we still responsible?

    Short Answer

    Yes, as the Data Fiduciary, your company remains responsible even if the breach originates from a vendor or third-party system.

    Answer

    Yes, your company remains responsible because you are the Data Fiduciary. Even if the breach originates from a vendor, the accountability does not shift.

    This is why businesses must ensure strong vendor governance, contracts, and monitoring mechanisms. You are expected to ensure that your entire ecosystem follows DPDP standards.

    Law Reference

    Section 8 – Obligations of Data Fiduciary

    Business Impact

    Vendor governance becomes critical. Businesses must enforce DPDP standards across their entire ecosystem through contracts, audits, and monitoring.

    Real-World Example

    A retailer's SMS vendor suffers a breach exposing customer phone numbers. The retailer, not the vendor, faces regulatory action as the Data Fiduciary.

    Was this answer helpful?

    Still have questions?

    Our team is here to help you with any questions about DPDP compliance.