Risk Findings & Recommendations
Two views — across all contracts per vendor, or contract-by-contract.
MedInsights AI
No explicit prior consent for sub-processor changes
Contract · MedInsights AI Data Processing Agreement
Compliance impact
DPDP Sec. 8(2) — Data Fiduciary remains accountable for sub-processor processing; Data Principals lose visibility.
Suggested replacement
Add 30-day prior notice obligation with right to object for any sub-processor onboarding.
Owner · S. Iyer
Breach notification window not aligned with DPDP timelines
Contract · MedInsights AI Data Processing Agreement
Compliance impact
DPDP Sec. 8(6) requires intimation to the Data Protection Board and affected Data Principals 'as may be prescribed' — clause uses vague 'reasonable time'.
Suggested replacement
Replace 'within reasonable time' with 'without undue delay and in any case within 72 hours of becoming aware', aligned to DPDP rules.
Owner · S. Iyer
Cross-border transfer lacks DPDP notified-country safeguard
Contract · MedInsights AI Data Processing Agreement
Compliance impact
DPDP Sec. 16 — transfers permitted only to countries not restricted by the Central Government; clause does not reference notified-country list.
Suggested replacement
Restrict transfers to countries permitted under DPDP Sec. 16 and reference the Central Government's notified list.
Owner · Legal
Salesforce CRM
Audit cadence limited to once every 24 months
Contract · Salesforce CRM DPA 2026
Compliance impact
Below recommended annual audit for Significant Data Fiduciary processors under DPDP Sec. 10.
Suggested replacement
Allow annual third-party audit and unlimited audits post-incident.
Owner · K. Rao
Encryption clause meets DPDP reasonable security safeguards
Contract · Salesforce CRM DPA 2026
Compliance impact
DPDP Sec. 8(5) — encryption at rest (AES-256) and in transit (TLS 1.3) satisfies 'reasonable security safeguards'.
Suggested replacement
—
Owner · Security
KidsLearn EdTech
Children's data processing without verifiable parental consent clause
Contract · KidsLearn EdTech NDA
Compliance impact
DPDP Sec. 9 violation — processing of children's personal data without verifiable parental consent and prohibition on tracking / targeted advertising.
Suggested replacement
Insert verifiable parental consent workflow and prohibition on behavioural tracking of children.
Owner · A. Mehta
CloudVault
Liability cap unusually low (12 months fees)
Contract · CloudVault MSA
Compliance impact
Below internal policy threshold (24 months) for critical vendors.
Suggested replacement
Raise liability cap to 24 months of fees with carve-outs for data breach and DPDP penalty exposure.
Owner · Legal
LoyaltyHub
Retention defined but deletion proof not required
Contract · LoyaltyHub Services SOW
Compliance impact
DPDP Sec. 8(7) — Data Fiduciary must erase data when purpose is served; deletion evidence improves accountability.
Suggested replacement
Add obligation to provide deletion certificate within 30 days of contract termination.
Owner · T. Singh
