Your vendor might be handling customer info — and you don't even know it.
Your CA has your GST files. Your HR software has salary slips. Your courier partner has customer phone numbers. These are all vendors. If any one of them misuses that information, the law can still come to YOU. Under the new DPDPA law, you are responsible for what your vendors do with people's information. Most small business owners do not even have a list of their vendors. That is a big problem.
Think about your daily work. Your accountant has PAN card and Aadhaar details. Your WhatsApp bulk message service has customer phone numbers. Your background check company has employee resumes. All of these people touch your customers' or workers' information. The DPDPA law says you must check each vendor. You must ask: what information do they have? Do they really need it? Is it safe with them? If you cannot answer these questions, you are not ready.
Write a list of all vendors who handle customer or staff information.
For each vendor, write what information they hold and why they need it.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Vendors are part of your system not outside it.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.