Remediation
Every finding has an owner, a due date and a closure trail. Traceable to vendor → contract → framework → rule.
Open
3
In Progress
3
Accepted
0
Remediated
2
Closed
0
| Finding | Third party | Contract | Framework clause | Severity | Owner | Due | Status | Action |
|---|---|---|---|---|---|---|---|---|
No explicit prior consent for sub-processor changes F-501 | MedInsights AI | MedInsights AI Data Processing Agreement | § 7.2 Sub-processors | Critical | ||||
Breach notification window not aligned with DPDP timelines F-502 | MedInsights AI | MedInsights AI Data Processing Agreement | § 11 Breach Notification | Critical | ||||
Cross-border transfer lacks DPDP notified-country safeguard F-503 | MedInsights AI | MedInsights AI Data Processing Agreement | § 4.1 Data Transfers | High | ||||
Audit cadence limited to once every 24 months F-504 | Salesforce CRM | Salesforce CRM DPA 2026 | § 9 Audit Rights | Medium | ||||
Children's data processing without verifiable parental consent clause F-505 | KidsLearn EdTech | KidsLearn EdTech NDA | § 3 Data Categories | Critical | ||||
Liability cap unusually low (12 months fees) F-506 | CloudVault | CloudVault MSA | § 14 Liability Cap | High | ||||
Retention defined but deletion proof not required F-507 | LoyaltyHub | LoyaltyHub Services SOW | § 6 Retention | Informational | ||||
Encryption clause meets DPDP reasonable security safeguards F-508 | Salesforce CRM | Salesforce CRM DPA 2026 | § 5 Security Controls | Compliant |
