DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

A third-party review workflow is the end-to-end process for assessing, contracting, onboarding and re-reviewing every vendor or processor that touches personal data. Under the DPDP Act 2023, the data fiduciary stays accountable for data its third parties handle, so a mature workflow screens vendors before onboarding, tiers them by risk, requires a DPDP-aligned data processing agreement, tracks sub-processors and cross-border transfers, and re-reviews on a cadence. A workflow that stops at onboarding — with no re-review and no risk tiering — leaves accountability unmanaged.

Third-Party Review Workflow Guide — DPDP Vendor Review Maturity

Reviewing vendors once at onboarding is not a workflow. This checks how mature your end-to-end third-party review process is under DPDP.

How mature is your third-party review workflow?

The stages of a mature third-party review workflow

Why third-party review is a workflow, not a one-time check

Under the DPDP Act 2023, engaging a processor does not transfer your accountability — you remain the data fiduciary answerable for personal data even when a third party handles it. That reality is what makes third-party review a continuous workflow rather than a single gate at onboarding. A vendor relationship evolves: the vendor takes on more data, adds sub-processors, changes its infrastructure, or begins storing data abroad. Each change alters your exposure, and only a workflow with re-review built in can keep pace. A one-time check captures the vendor as they were on day one, not as they are today.

The maturity of the workflow is measured by how many of the stages you actually run: pre-onboarding assessment, risk tiering, DPDP-aligned contracting, sub-processor tracking, cross-border checks and scheduled re-review. Most organisations run one or two of these and call it vendor management. Niti Bharat helps companies build the full workflow, so that accountability for third parties is a managed process with evidence at each stage rather than an assumption that the vendor is fine.

Tiering and re-review: the two stages most workflows skip

The two stages that separate a mature workflow from a superficial one are risk tiering and scheduled re-review. Tiering matches the depth and frequency of scrutiny to the risk a vendor actually carries, so a processor handling sensitive or children's data is examined far more closely and often than one that touches almost no personal data. Without tiering, effort is spread evenly and the highest-risk vendors are under-examined. Scheduled re-review then keeps every vendor current, with a due date driven by its tier, so nothing silently ages out of compliance.

As the DPDP Rules 2025 bed in ahead of full enforcement around May 2027, being able to show a running, tiered, re-reviewed vendor programme is exactly the evidence that demonstrates control over your data supply chain. Niti Bharat runs privacy governance programmes that stand up this third-party workflow end to end — intake through re-review — so accountability for the vendors touching your data is provable and maintained.

Get the third-party review workflow toolkit (free)

A step-by-step third-party review workflow with an intake assessment, a risk-tiering rubric, a DPA checklist and a re-review scheduler.

Frequently Asked Questions

What is the difference between vendor management and a third-party review workflow?+
Vendor management often focuses on commercials and delivery. A DPDP third-party review workflow focuses on data protection: what personal data the vendor handles, how they protect it, whether the DPA is compliant, who their sub-processors are, and re-reviewing all of this on a cadence.
How do we decide a vendor's risk tier?+
Base it on the sensitivity and volume of personal data the vendor handles and where it is stored. A vendor processing large volumes, sensitive categories, or children's data is high tier; one that touches minimal personal data is low tier. The tier then drives how often and how deeply you re-review.
What is a sub-processor and why track them?+
A sub-processor is a third party your vendor engages to help handle your data — for example a cloud provider behind a SaaS tool. They matter because your data ends up with parties you did not directly contract, so they should be disclosed and, ideally, approved. Undisclosed sub-processors are a common blind spot.
Where does the workflow start — at onboarding or before?+
Before. The most valuable control is the pre-onboarding assessment, which happens before you share any personal data. Screening a vendor after data has already flowed to them is far weaker, because the exposure has already been created.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
TRAI–DPDP Alignment GuideUniversity Data Protection IndiaVirtual CFO DPDP IndiaIoT Device Data-Collection & Consent CheckerSee all Reference & Checklists tools →📝 DPDP Consultant India📝 What Is Cross Border Data Transfer DPDP