The direct answer

Vendor exit should reconcile the agreed return or deletion obligation with an inventory of live systems, backups, logs and sub-Processors. Define permitted residual retention, restrict further use and record the deletion method. A generic certificate should not close an exit review where material repositories remain unaccounted for.

The business situation

An illustrative scenario

A support provider confirms that it deleted the customer database. Later, a backup restoration recreates old support tickets. The certificate was accurate for the live database but silent about recovery systems. The exit terms never distinguished the two.

A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.

What needs examining

01. Define the perimeter before requesting certification

List the datasets, environments, support exports, endpoints and sub-Processors involved in the service. Separate data belonging to the customer from independent records that the provider is legally required to retain. The classification must reflect the real relationship; a provider cannot turn all service data into its own records through a broad contract label.

02. Give backups a workable and lawful treatment

Immediate removal from every backup may not be technically achievable. Determine whether the proposed expiry cycle and restrictions are legally and contractually acceptable for the information involved. Address access controls, restoration procedures and re-deletion after recovery. Do not promise absolute erasure where the technical design cannot support it; resolve the limitation before approving the exit.

03. Connect contractual remedies to practical assurance

Require the confirmation to identify the signatory, method, completion date, systems covered and permitted exceptions. Reserve proportionate verification and cooperation rights. An indemnity may allocate financial exposure, but it does not remove the Data Fiduciary's applicable duties or recreate data that should have been returned before destruction.

Law, contract and recommended practice

DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.

Connect the control to the evidence

Use this table to scope the review. The legal basis and the practical control are identified separately.

Obligation or objectivePractical controlEvidence to retain
Law, where applicable
Limit residual processing and retention
Review legal basis and retention purposeReasoned retention exception record
Contractual control
Complete the agreed exit obligation
Return, deletion and sub-Processor flow-downExit schedule and scoped certificate
Recommended practice
Prevent accidental restoration of retired data
Restore-and-redelete procedureRecovery test and access logs

Records to prepare

Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.

Service agreement and data-processing terms
Repository and sub-Processor inventory
Backup lifecycle and recovery procedure
Return acceptance and deletion confirmations

Common questions

Must every vendor supply a forensic destruction report?

There is no universal report format for every service. The assurance should be proportionate to the data, risk, architecture and applicable obligation. A certificate may suffice in some cases; an unsupported blanket statement may not.

Should the business delete first or confirm return first?

Where return is required, verify completeness and usability before destruction. Agree the sequence and access window in advance. Otherwise the business may lose records needed for operations, litigation or regulatory compliance.

The next practical step

An exit should close when the data perimeter, return acceptance and residual retention position are reconciled. Procurement, IT, security and legal should work from the same final record.

Legislation & official resources

These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.

This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.

Explore the AMLEGALS data privacy practice