Vendor exit should reconcile the agreed return or deletion obligation with an inventory of live systems, backups, logs and sub-Processors. Define permitted residual retention, restrict further use and record the deletion method. A generic certificate should not close an exit review where material repositories remain unaccounted for.
The business situation
A support provider confirms that it deleted the customer database. Later, a backup restoration recreates old support tickets. The certificate was accurate for the live database but silent about recovery systems. The exit terms never distinguished the two.
A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.
What needs examining
01. Define the perimeter before requesting certification
List the datasets, environments, support exports, endpoints and sub-Processors involved in the service. Separate data belonging to the customer from independent records that the provider is legally required to retain. The classification must reflect the real relationship; a provider cannot turn all service data into its own records through a broad contract label.
02. Give backups a workable and lawful treatment
Immediate removal from every backup may not be technically achievable. Determine whether the proposed expiry cycle and restrictions are legally and contractually acceptable for the information involved. Address access controls, restoration procedures and re-deletion after recovery. Do not promise absolute erasure where the technical design cannot support it; resolve the limitation before approving the exit.
03. Connect contractual remedies to practical assurance
Require the confirmation to identify the signatory, method, completion date, systems covered and permitted exceptions. Reserve proportionate verification and cooperation rights. An indemnity may allocate financial exposure, but it does not remove the Data Fiduciary's applicable duties or recreate data that should have been returned before destruction.
Law, contract and recommended practice
DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, where applicable Limit residual processing and retention | Review legal basis and retention purpose | Reasoned retention exception record |
| Contractual control Complete the agreed exit obligation | Return, deletion and sub-Processor flow-down | Exit schedule and scoped certificate |
| Recommended practice Prevent accidental restoration of retired data | Restore-and-redelete procedure | Recovery test and access logs |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Must every vendor supply a forensic destruction report?
There is no universal report format for every service. The assurance should be proportionate to the data, risk, architecture and applicable obligation. A certificate may suffice in some cases; an unsupported blanket statement may not.
Should the business delete first or confirm return first?
Where return is required, verify completeness and usability before destruction. Agree the sequence and access window in advance. Otherwise the business may lose records needed for operations, litigation or regulatory compliance.
An exit should close when the data perimeter, return acceptance and residual retention position are reconciled. Procurement, IT, security and legal should work from the same final record.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
- DPDP Act commencement notification: G.S.R. 843(E)MeitY · Gazette of India · Notification dated 13 November 2025. Different provisions commence in different phases.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS data privacy practice