Skip to main content
Finin2minCurrent Action Guide · 14 Aug 2026
DPDP, AI & Cyber GovernanceUpdated 5 October 2026Checked 14 August 2026

Vendor Suffers Data Breach Affecting Your Customers: Processor Incident and Notification File

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

India-first finance and compliance workflow with primary-source anchors.

2-minute summary

Current position

A vendor breach must be evaluated against reporting duties that apply on the incident date. At 5 October 2026, CERT-In reporting can already be relevant, whereas much of the detailed DPDP fiduciary/breach machinery remains within the statutory transition calendar. Contract clauses should support both present six-hour cyber assessment and the richer DPDP evidence/notification processes due at later commencement.

Control and decision map

#Control / decision step
1Open one joint incident chronology with first detection, vendor notice, containment and customer-impact timestamps.
2Demand affected dataset/user list, log scope, attack vector, exfiltration evidence and sub-processor impact.
3Independently map affected customers/data categories to your own data inventory.
4Assess CERT-In and sector/client reporting clocks from your detection/notification facts.
5Prepare customer communication that states known facts, protective steps and contact route without speculation.
6Track vendor root cause, control remediation and contract/SLA lessons before closing the incident.

Evidence pack

Worked example

A SaaS payroll vendor reports that an attacker accessed a support database containing employee names, bank details and tickets for several customers. The client company should not wait for the vendor’s final forensic report before starting its own impact map and reporting-clock analysis; it can report available facts where required and supplement later.

Common mistakes

  1. Assuming only the vendor must report the breach.
  2. Waiting for perfect forensic certainty before assessing a short statutory reporting deadline.
  3. Sending customers a generic breach email without identifying the affected data or protective steps.
  4. Closing the incident when service resumes rather than after root-cause remediation.

Frequently asked questions

Does CERT-In apply when the breach is at a vendor?

CERT-In FAQ states reporting obligations can still apply when an entity’s data is affected in a third party’s systems.

Can later information be added?

Yes. CERT-In FAQ allows available information first and additional information later.

What contract term matters most?

Operationally prompt incident notice plus evidence/log cooperation, not just liability language.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, contract, facts and professional judgement before acting.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.