Start with data minimization
The safest sensitive record is the one the vendor never receives. Limit datasets, mask fields where practical and separate development from production.
Use individual identities and least privilege
Avoid shared master accounts. Grant only the access required for each role, use multi-factor authentication where available and remove access promptly when assignments end.
Understand Indian data-protection obligations
India’s Digital Personal Data Protection Act 2023 is being implemented through the Digital Personal Data Protection Rules 2025 on a phased timeline. Buyers should not assume that the existence of Indian law automatically satisfies obligations in the buyer’s own jurisdiction.
For Canadian buyers, outsourcing does not remove accountability
The Office of the Privacy Commissioner of Canada says organizations subject to PIPEDA remain responsible for personal information transferred to a third party for processing and should use contractual or other means to provide a comparable level of protection. Provincial rules may also matter.
Ask about incident response
Define how security events are detected, escalated and communicated. CERT-In maintains cyber-security directions that apply to specified service providers and organizations in India. Your contract should still contain the incident-notification terms your business requires.
Keep backups and business continuity independent
Do not rely on the development vendor as the only holder of source code or backups. The business should be able to restore critical assets even if the supplier is unavailable.
Official references
MeitY: Digital Personal Data Protection Rules 2025 ↗
CERT-In cyber-security directions ↗
Office of the Privacy Commissioner of Canada: privacy and outsourcing ↗
Inventory subprocessors and AI tools
A provider may use cloud storage, ticketing systems, remote-access tools, AI assistants or subcontractors that also receive buyer data. Ask for a current subprocessor list and define whether new subprocessors require notice or approval.
Test offboarding access
When a team member leaves, disable identity accounts, VPN access, repository credentials and local copies promptly. Periodically review active access so old permissions do not accumulate during a long engagement.
Review data location against contracts
The technical system may allow global processing even when a customer agreement limits where data can be accessed or stored. Inventory contractual location commitments as well as legal requirements before approving offshore access.
Run access reviews on a schedule
Long engagements accumulate permissions. Review active users, roles, tokens and shared secrets periodically and remove access that is no longer required. This is especially important after team changes or scope reductions.