Accountability, including through a Processor
The Data Fiduciary remains responsible for compliance even where processing is carried out by a Data Processor on its behalf, and may engage one only under a valid contract.
Section 8(1)–(2)DPDP Act, 2023Data Fiduciary
What this requires
The Data Fiduciary remains responsible for compliance even where processing is carried out by a Data Processor on its behalf, and may engage one only under a valid contract.
Evidence a regulator would accept
- Data Processing Agreements
- Processor register
- Sub-processor list
How this product discharges it
core (primary)assessment
Our position
Changing this recalculates the readiness score immediately.
- Current
- Gap
- Residual risk
- High
- Owner
- Vikram Saxena
- Last reviewed
- 03 Jul 2026
- Next review due
- 01 Oct 2026
Open gaps (1)
Gaps raised against this obligation. Closing one moves this clause forward.
Evidence (1)
Documents indexed against this obligation in the evidence vault.
History
- Clause status updated following remediationyesterday06 Aug 2026, 00:30Deepika Joshi
- Clause status updated following remediation4 days ago03 Aug 2026, 17:30Rohit Verma
- Clause status updated following remediation6 days ago01 Aug 2026, 10:30Naveen Kulkarni
- Clause status updated following remediation8 days ago30 Jul 2026, 06:30Vikram Saxena
- Clause status updated following remediation10 days ago28 Jul 2026, 00:30Imran Sethi
- Clause status updated following remediation13 days ago25 Jul 2026, 16:30System
- Position reviewed and recordedlast month03 Jul 2026, 11:55Vikram Saxena
Related obligations
- S.8(3)Accuracy and completenessCompliant
- S.8(9)Publish contact for the DPO or responsible personCompliant
- S.16Processing of personal data outside IndiaGap
- S.28Procedure to be followed by the BoardIn progress
- Sch.Monetary penaltiesCompliant
- R.9Contact information for questions about processingPartially compliant