You can share personal data with a third party under the DPDP Act 2023 only if you have a lawful basis for that specific sharing and it is consistent with the purpose the Data Principal was told about. If the third party merely processes data on your behalf (a vendor or processor), you need a data-processing agreement and remain accountable as the data fiduciary. If the third party uses the data for its own new purpose — such as a marketing partner or a group company cross-selling — that generally needs its own specific consent. This checker tells you, for a given sharing scenario, whether it is likely permitted and what you must have in place.
Vendor, partner or group company — sharing personal data has different DPDP rules for each. Check whether your specific sharing is allowed and what you need in place.
The single most important question before sharing personal data is whether the recipient is processing it on your behalf or using it for its own purpose. A processor — a hosting provider, a support vendor, a TPA administering claims — acts under your instructions for the original purpose. Sharing with a processor is permitted provided you have a data-processing agreement binding them to purpose limitation, security and deletion, and you remain the accountable data fiduciary. No new consent is needed because the purpose has not changed.
A partner or group company that uses the data for its own new purpose — marketing, cross-selling, building its own products — is different. Here the data is being put to a purpose the Data Principal did not originally consent to, so under the DPDP Act that sharing generally needs its own specific, informed consent. The common and costly mistake is treating group companies and marketing partners as if they were mere processors, and sharing data to them on the strength of consent that was actually given for something else.
For any sharing, three things need to be true: a lawful basis for that specific sharing, disclosure to the Data Principal that this category of recipient exists, and data minimisation so only what is genuinely needed changes hands. For processor sharing, add a data-processing agreement. For external-purpose sharing, add specific consent for that purpose. For legal-demand sharing, verify the demand is valid and share only what is required. In every case, log the decision so you can show your basis if the Data Protection Board asks.
Undisclosed and over-broad data sharing is one of the most common enforcement triggers, and it is entirely avoidable with a clear internal rule. Niti Bharat helps Indian companies build a third-party sharing decision framework and the underlying data-processing agreements and consent flows, so that anyone about to share data — from a product manager to a partnerships lead — can quickly confirm whether it is allowed and on what basis, ahead of enforcement expected around May 2027.
A PDF decision tree for processor vs partner vs group vs legal sharing, plus a data-processing-agreement checklist and model consent wording for external-purpose sharing.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.