Short Answer
Yes, users must be informed about which third-party vendors process their data and for what purpose.
Yes, transparency is a key requirement. Users should be informed about who is processing their data and for what purpose, especially when third parties are involved.
This builds trust and ensures that users are making informed decisions while giving consent.
Law Reference
Section 5 – Notice
"A notice… describing personal data and purpose of processing."
Transparency builds customer trust and ensures informed consent. Hidden vendor relationships can invalidate consent and trigger complaints.
A health app using a third-party analytics platform must disclose in its consent notice that user health data is processed by the analytics vendor for usage insights.
Was this answer helpful?
Our team is here to help you with any questions about DPDP compliance.