OneConsent TPGP · Third Party Risk Management
AD
Admin

Risk Findings & Recommendations

Two views — across all contracts per vendor, or contract-by-contract.

Back to hub

MedInsights AI

3 total
2 critical
1 high
across 1 contracts
Critical
DPDP
F-501 · § 7.2 Sub-processors
Open

No explicit prior consent for sub-processor changes

Contract · MedInsights AI Data Processing Agreement

Compliance impact

DPDP Sec. 8(2) — Data Fiduciary remains accountable for sub-processor processing; Data Principals lose visibility.

Suggested replacement

Add 30-day prior notice obligation with right to object for any sub-processor onboarding.

Owner · S. Iyer

Critical
DPDP
F-502 · § 11 Breach Notification
Open

Breach notification window not aligned with DPDP timelines

Contract · MedInsights AI Data Processing Agreement

Compliance impact

DPDP Sec. 8(6) requires intimation to the Data Protection Board and affected Data Principals 'as may be prescribed' — clause uses vague 'reasonable time'.

Suggested replacement

Replace 'within reasonable time' with 'without undue delay and in any case within 72 hours of becoming aware', aligned to DPDP rules.

Owner · S. Iyer

High
DPDP
F-503 · § 4.1 Data Transfers
Open

Cross-border transfer lacks DPDP notified-country safeguard

Contract · MedInsights AI Data Processing Agreement

Compliance impact

DPDP Sec. 16 — transfers permitted only to countries not restricted by the Central Government; clause does not reference notified-country list.

Suggested replacement

Restrict transfers to countries permitted under DPDP Sec. 16 and reference the Central Government's notified list.

Owner · Legal

Salesforce CRM

2 total
across 1 contracts
Medium
DPDP
F-504 · § 9 Audit Rights
Open

Audit cadence limited to once every 24 months

Contract · Salesforce CRM DPA 2026

Compliance impact

Below recommended annual audit for Significant Data Fiduciary processors under DPDP Sec. 10.

Suggested replacement

Allow annual third-party audit and unlimited audits post-incident.

Owner · K. Rao

Compliant
DPDP
F-508 · § 5 Security Controls
Remediated

Encryption clause meets DPDP reasonable security safeguards

Contract · Salesforce CRM DPA 2026

Compliance impact

DPDP Sec. 8(5) — encryption at rest (AES-256) and in transit (TLS 1.3) satisfies 'reasonable security safeguards'.

Suggested replacement

Owner · Security

KidsLearn EdTech

1 total
1 critical
across 1 contracts
Critical
DPDP
F-505 · § 3 Data Categories
Open

Children's data processing without verifiable parental consent clause

Contract · KidsLearn EdTech NDA

Compliance impact

DPDP Sec. 9 violation — processing of children's personal data without verifiable parental consent and prohibition on tracking / targeted advertising.

Suggested replacement

Insert verifiable parental consent workflow and prohibition on behavioural tracking of children.

Owner · A. Mehta

CloudVault

1 total
1 high
across 1 contracts
High
Internal
F-506 · § 14 Liability Cap
Open

Liability cap unusually low (12 months fees)

Contract · CloudVault MSA

Compliance impact

Below internal policy threshold (24 months) for critical vendors.

Suggested replacement

Raise liability cap to 24 months of fees with carve-outs for data breach and DPDP penalty exposure.

Owner · Legal

LoyaltyHub

1 total
across 1 contracts
Informational
DPDP
F-507 · § 6 Retention
Accepted

Retention defined but deletion proof not required

Contract · LoyaltyHub Services SOW

Compliance impact

DPDP Sec. 8(7) — Data Fiduciary must erase data when purpose is served; deletion evidence improves accountability.

Suggested replacement

Add obligation to provide deletion certificate within 30 days of contract termination.

Owner · T. Singh