DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Under the DPDP Act 2023, a data fiduciary stays responsible for personal data even when a processor handles it, so vendors and processors must be reviewed on a regular cadence — not just signed once and forgotten. A defensible schedule reviews higher-risk vendors more often, checks that data processing agreements are current, and confirms security and sub-processor arrangements have not drifted. This checker estimates when your next vendor review is due based on risk tier and the date of the last review, so overdue vendors do not slip through.

Vendor Review Due-Date Checker — When Are Your DPDP Vendor Reviews Due?

You are still accountable for data your vendors touch. This works out when each vendor is due for review so nothing goes stale between audits.

When is this vendor due for a DPDP review?

What a DPDP vendor review should confirm

Why vendor reviews have due dates, not just start dates

Under the DPDP Act 2023, when you engage a data processor to handle personal data on your behalf, you remain the accountable data fiduciary. That accountability does not pause between contract signing and the next audit. Vendors change their systems, add sub-processors, move data across borders and experience their own incidents — all of which affect your exposure. A one-time due-diligence check at onboarding cannot capture any of this, which is why mature programmes assign each vendor a review due date and refresh it on a cadence set by risk.

The most common failure is treating a signed data processing agreement as a permanent tick in the box. Contracts age, obligations shift as the DPDP Rules 2025 bed in, and a vendor that was low-risk two years ago may now handle far more sensitive data. Niti Bharat builds vendor-review schedules into its ongoing privacy governance programmes so that higher-risk processors are re-examined more frequently and no vendor quietly goes stale.

Setting a defensible vendor review cadence

A defensible cadence is risk-based. High-risk vendors — those handling large volumes, sensitive categories, or children's data — warrant review at least twice a year. Routine vendors can be reviewed annually, and low-touch vendors every eighteen months, provided nothing material changes in between. Each review should confirm the DPA is current, the actual data flows match what was agreed, security and sub-processor arrangements hold, and any cross-border transfers remain compliant. Crucially, each review sets the next due date, so the schedule maintains itself.

With full DPDP enforcement expected around May 2027, the ability to show a running, dated history of vendor reviews is exactly the kind of evidence that distinguishes a controlled operation from a reactive one. Niti Bharat helps Indian mid-market companies stand up this vendor-review discipline — tiering, scheduling, and evidence capture — so accountability for processors is provable rather than assumed.

Get the vendor review scheduler and checklist (free)

A risk-tiered vendor review scheduler plus a checklist of exactly what each review should confirm under the DPDP Rules 2025.

Frequently Asked Questions

How often should we review our data processors under DPDP?+
There is no single mandated interval, so use a risk-based cadence: high-risk vendors at least every six months, routine vendors annually, and low-risk vendors up to every eighteen months. The key is that each vendor has a scheduled next-review date and that reviews are evidenced.
Are we responsible if our vendor causes a breach?+
As the data fiduciary you remain accountable for personal data even when a processor handles it. A breach at your vendor can still be your regulatory exposure, which is why reviewing their controls and having a compliant DPA that requires prompt breach cooperation matters.
What should trigger an off-cycle vendor review?+
A new sub-processor, a change in the data the vendor handles, a security incident at the vendor, a move of data across borders, or a material change to their service. Any of these should trigger a review before the scheduled due date.
Does a signed DPA mean we do not need to review the vendor again?+
No. A DPA is the starting point, not the whole obligation. Contracts age and reality drifts from what was agreed, so the vendor must still be reviewed on a cadence to confirm the DPA is honoured and remains adequate.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Website Cookie & Tracker Scanner DPDP Indiaक्या DPDP अधिनियम आपके व्यवसाय पर लागू होता है?क्या आपको शिकायत अधिकारी (Grievance Officer) नियुक…EdTech DPDP Compliance PackSee all Calculators tools →📝 DPDP Compliance Pricing India📝 DPDP Compliance Deal Risk