Vendor Risk Management in India: Due-Diligence Steps and Sectoral Obligations
Introduction
Vendor relationships in the current digital economy have undergone significant transformation. Modern vendor contracts have evolved beyond simple operational or cost-efficient arrangements into integrated systems that serve as repositories of an organisation's critical assets, including proprietary information, digital infrastructure, and the personal data of its customers and employees. As organisational boundaries extend into cloud-hosted platforms, third-party databases, and external software integrations, vendor risk management has transitioned into an essential element of corporate governance. A structured approach to vendor due diligence is now a legal as much as a commercial necessity, inadequate or absent due diligence carries severe financial, legal, and reputational consequences.
This article examines the two principal dimensions of vendor risk in the Indian context- intellectual property (IP) due diligence, with particular focus on copyright ownership and the chain of title under the Copyright Act, 1957 (“Copyright Act”), and data protection due diligence under the Digital Personal Data Protection (DPDP) Act, 2023, read with the Digital Personal Data Protection Rules, 2025 (collectively, the "DPDPA"). It further outlines a structured lifecycle framework that organisations may adopt to govern vendor relationships from onboarding through to termination.
IP Due Diligence
While engaging vendors for developing technology or software products, it is essential for organisations to verify that such third-party service providers have unencumbered title to the deliverables and hold the authority to transfer the ownership rights of the developed work products.
Under the Copyright Act, the author of a work is its first owner. It is often assumed that since an organisation is paying the vendor, copyright automatically transfers to the paying entity upon development of the work product. However, such an assumption is risky, as the Copyright Act operates within a strict statutory framework wherein ownership only shifts under carefully defined exceptions. Primarily, in the case of a contract of service that establishes an employer-employee relationship, and secondly in the case of a contract for services, which establishes an independent contractor relationship. In the former arrangement, the copyright to any work developed by an employee within the course of their employment automatically vests with the employer, unless an agreement to the contrary exists. In the latter case, for freelancers, software vendors, and other independent contractors, the default rule stands that the contractor retains ownership of all developed works, irrespective of any commission or payment. Thus, in order to successfully transfer ownership of IP from a vendor to the commissioning organisation, the parties must execute an express, written assignment agreement. For instance, a general IP clause within a Master Services Agreement (MSA) is often insufficient to effectuate a valid transfer; a legally valid assignment must clearly identify the existing or future works being assigned and detail the specific rights being transferred.
Another frequently overlooked vulnerability arises when vendors engage personnel through third-party staffing agencies. If the agreement between the engaging organisation and the staffing agency lacks an explicit IP assignment provision, the individual may end up retaining IP ownership of all work products developed. Since ownership was never acquired from the individual by the staffing agency, and the vendor failed to acquire it from the agency, any downstream assignment to the commissioning organisation remains invalid and creates a broken, unenforceable chain of title. This could expose the organisation to copyright infringement suits and other injunctions.
Such vendor IP due diligence must also assess unregistered intellectual assets, including trade secrets, proprietary algorithms, technical know-how, and confidential business information. India lacks a dedicated statutory framework governing trade secret, and their protection depends instead on common law principles. Because this protection is entirely contractual in nature, vendor agreements must contain robust confidentiality obligations, non-disclosure covenants, and strict data access restrictions.
Data Protection Due Diligence
Under the DPDPA, primary compliance responsibility is placed on organisations qualifying as "Data Fiduciaries", defined under Section 2(i) of the DPDP Act as any person who, alone or in conjunction with others, determines the purpose and means of processing ‘personal data’, being any data about an individual who is identifiable by or in relation to such data relating to an individual (the "Data Principal"). A "Data Processor", defined under Section 2(k) of the DPDP Act, is any person who processes personal data on behalf of a Data Fiduciary. Under DPDPA, a Data Fiduciary remains responsible for compliance in respect of any processing undertaken on its behalf by a Data Processor, irrespective of any agreement to the contrary. Any operational failure, data breach, or security lapse by a vendor is therefore directly attributed to the Data Fiduciary, rendering contractual due diligence a legal necessity rather than a mere commercial obligation.
It is pertinent that Data Fiduciaries verify that vendors have implemented appropriate technical and organisational safeguards, including end-to-end encryption, multi-factor authentication, and continuous vulnerability management supported by certifications such as ISO/IEC 27001. All vendor personnel having access to personal data must be subjected to binding written confidentiality obligations with strict role-based access controls. Data Fiduciaries must also assess whether vendor systems have the technical capacity to support the fulfilment of Data Principal rights as mandated under the DPDPA, including access, correction, erasure, and consent withdrawal.
Organisations engaging third-party vendors for data processing purposes should do so under a legally binding Data Processing Agreement ("DPA") containing provisions for purpose limitation, mandatory implementation of reasonable security safeguards as prescribed under the statut, prior written consent for sub-processing, and immediate breach notification , among others. The DPA must additionally require the Data Processor to restrict access to personal data strictly on a "need-to-know" basis, limiting system access solely to those employees, contractors, or representatives whose operational duties directly require such access to perform the contracted services.
Further, the DPA must include a protective "Erasure and Return" clause, requiring the Data Processor to erase all personal data made available by the Data Fiduciary within a stipulated timeframe following the expiry or termination of the contract, or upon withdrawal of consent by the Data Principal.
Vendor Due Diligence Lifecycle Framework
Prior to onboarding a vendor, organisations must conduct a structured risk and compliance review covering the following:
- The vendor's eligibility to undertake the outsourced engagement, including its corporate registration status, financial stability, and the alignment of the proposed services with its main objects clause, which can significantly affect the vendor's legal capacity to perform and the client's recourse in the event of non-performance or breach.
- A technical assessment of the vendor's organisational safeguards, including the data security controls the vendor has in place.
- The contractual framework governing the engagement, including execution of an appropriate IP assignment agreement and a DPDPA-compliant DPA.
- The vendor's downstream compliance posture, including the audit of subcontractor agreements for flow-down of IP and confidentiality obligations, and confirmation of signed confidentiality undertakings from all data-processing personnel.
- Ongoing monitoring of the engagement's security reliability through periodic on-site and logical audits of cloud and physical database controls.
- Post-termination closure requirements, including the complete deletion of personal data and the revocation of all system access by the vendor.
Conclusion
Vendor risk management is not a one-time contractual onboarding exercise. As Indian vendor arrangements become increasingly data-intensive and IP-driven, the consequences of inadequate due diligence whether a broken chain of copyright ownership, a data breach attributable to a third-party processor, or a non-compliant DPA, can expose organisations to significant financial, legal, and reputational harm. Under DPDPA, failure to implement reasonable security safeguards can attract penalties of up to INR 250 Crore (USD 26 Million approx.), as may be adjudicated by the Data Protection Board of India, and this liability rests with the Data Fiduciary regardless of which party was operationally at fault. Organisations engaging third-party vendors should thereby move to implement a structured due diligence framework, review existing vendor agreements for IP and data protection compliance, and consult qualified counsel in this space at the earliest ahead of the full implementation of the DPDPA next year.
This content is first shared at: https://www.ahlawatassociates.com/blog/vendor-due-diligence-in-india