Governance & Risk

Vendor and Third-Party Risk Assessment

Most personal data is processed by vendors, not by you directly. We help you build a defensible vendor risk program — risk-tiered due diligence, robust Data Processing Agreements (DPAs), sub-processor governance and ongoing oversight aligned to the DPDP Act and GDPR.

What's included

A scoped engagement with concrete deliverables — not a slide deck.

Vendor inventory & tiering

Complete inventory of personal-data processors, risk-tiered by data type, volume and criticality.

Due diligence questionnaires

Tailored questionnaires combining privacy, security and AI considerations.

DPAs & contractual safeguards

Indian and EU-style DPAs, SCCs and supplementary measures.

Sub-processor reviews

Visibility and approval workflow for downstream sub-processors.

Ongoing monitoring

Annual reassessment, change-of-scope reviews and exit planning.

Our approach

A repeatable four-stage method, calibrated to your business.

  1. 01

    Inventory

    Single source of truth for every vendor that touches personal data.

  2. 02

    Tier

    Risk tiering based on data type, volume and processing nature.

  3. 03

    Assess

    Targeted due diligence by tier; DPAs and SCCs aligned to risk.

  4. 04

    Monitor

    Annual cycle, change-driven reviews and exit playbooks.

Who it's for

Engagement profiles where we add the most value.

  • Companies with growing third-party SaaS and AI dependencies
  • Organisations consolidating vendor risk across security and privacy
  • Enterprises facing customer scrutiny over sub-processor governance

Frequently asked questions

What is a Data Processing Agreement (DPA)?+

A DPA is a contract between a Data Fiduciary/Controller and a Processor that defines the scope, purpose, security obligations, sub-processing rules and breach notification duties of the Processor. It's mandatory under GDPR and best practice under the DPDP Act.

Do we need to assess every vendor?+

No — we recommend risk-tiered assessment. High-tier vendors (large personal data volumes, special categories, critical to operations) get deep diligence; lower tiers get proportionate review.

Ready to make vendor risk a competitive advantage?

Book a free 30-minute consultation with Primitra. We'll review your current posture and outline the fastest path to a defensible, audit-ready program.