An organisation evaluating a new AI-powered analytics platform invites the vendor to conduct a proof-of-concept demonstration. To produce a realistic and relevant output, the internal team exports a sample of live customer data — including names, transaction history, and behavioural records — and shares it with the vendor for use in the demo environment.
Questions Raised for Compliance Review
Does sharing customer personal data with a prospective vendor for demonstration purposes constitute a DPDP compliance event?
What risks arise from the use of live personal data in third-party vendor evaluation processes?
What is the compliant approach to vendor proof-of-concept exercises involving data analysis?
Is This Permitted Under DPDP?
Not permissible as described. The customers whose data was exported did not consent to their personal information being shared with a third-party vendor for evaluation purposes. No processing agreement exists with the vendor at this stage — they are a prospective supplier, not an onboarded data processor. The data transfer has no lawful basis under DPDP.
Where the Breach Risks Sit
Unauthorised third-party transfer — The customer data was collected for defined service delivery purposes. Sharing it with an external vendor — even temporarily, even under an NDA — is a transfer to a third party without consent or a valid processing agreement. An NDA does not constitute a Data Processing Agreement under DPDP.
No processor relationship established — DPDP requires that any third party processing personal data on the organisation's behalf operate under a formal data processing agreement defining the scope, purpose, and safeguards. A vendor evaluation process predates any such agreement, leaving the transfer entirely ungoverned.
Data persistence in vendor environments — Once customer data enters a vendor's demo environment, the organisation has no control over how it is stored, who accesses it, or when it is deleted. Vendors may retain demo data in shared or unsecured environments not designed for production-grade data handling.
Risk to data principal rights — Customers cannot exercise their DPDP rights — access, correction, or erasure — over data held by a vendor with whom the organisation has no formal relationship.
The Ideal Compliant Approach
Use synthetic or anonymised data for all vendor demos. Before any vendor evaluation involving data analysis, the organisation's IT or data team should generate a synthetic dataset that mirrors the structure and characteristics of real data without containing actual personal information. Vendors receive a realistic environment; customers are not exposed.
Where real data is essential, execute a DPA first. In the rare scenario where only real data can validate the vendor's capabilities, a Data Processing Agreement must be executed before any data is shared — even for evaluation. This agreement must define the purpose, the retention period, the deletion obligation, and the vendor's security standards.
Define and enforce a demo data policy. Organisations should have a documented policy that explicitly prohibits the use of live personal data in vendor evaluations, system testing, or proof-of-concept exercises without prior DPO and legal sign-off.
DPDP Risk Summary
Element
Status
Recommended Action
Live customer data shared with prospective vendor
✗ Unauthorised transfer, no lawful basis
Cease practice; use synthetic data for all vendor demos
No Data Processing Agreement with vendor
✗ Mandatory before any data sharing
Execute DPA before sharing any personal data, even for evaluation
NDA treated as sufficient data governance
✗ NDA ≠ DPA under DPDP
Treat NDA and DPA as separate, both required
No control over data in vendor environment
✗ No data minimisation or security assurance
Require vendor to confirm deletion post-demo in writing
No synthetic data capability in place
⚠ Operational gap
Invest in synthetic data generation as a standard practice