Personal data risk at vendors is the potential harm that arises when a vendor, partner, or service provider processing your customers’ personal data mishandles, leaks, or retains that data without adequate oversight. That risk doesn’t stay contained to the vendor, since the consequences flow back to the company that hired them in the first place.
The scale of this problem is well documented. Verizon’s own 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled to 30% in a single year, based on an analysis of more than 22,000 security incidents worldwide.
The trouble is that personal data risk at vendors is often treated as settled the moment a contract is signed. Legally, that’s not how responsibility actually works, and this article breaks down why, along with what to do about it.
Why This Risk Stays Your Responsibility, Even When Outsourced
Legally, this relationship is governed by Articles 51 to 54 of Indonesia’s Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), which treats a vendor as a data processor required to process personal data strictly on the controller’s instructions. As with the PDP Law’s other obligations, this applies extraterritorially, so a foreign company can be in scope simply because a vendor processes the personal data of people in Indonesia on its behalf.
In practice, this means that when a payment vendor or cloud provider you use suffers a data breach, your company as the controller can still be held legally accountable. That principle is exactly why managing personal data risk at vendors can’t just be handed off without further oversight.
That said, responsibility isn’t entirely one-sided. The table below breaks down how it splits between controller and processor under the PDP Law.
| Party | Main Responsibility |
|---|---|
| Controller (Your Company) | Establishing a lawful basis for processing, selecting and overseeing vendors, and answering to data subjects and regulators for the processing as a whole |
| Processor (Vendor) | Processing data only on the controller’s written instructions, keeping data confidential and secure, reporting incidents, and never engaging a subprocessor without written consent |
A vendor only becomes legally liable in its own right once it’s shown to have processed data outside the controller’s instructions. As long as the vendor sticks to those instructions, primary responsibility stays with the company that appointed them.
Types of Personal Data Risk at Third-Party Vendors
Personal data risk at vendors generally falls into 5 categories, depending on how the data is mishandled once it leaves your direct control. The table below summarises each category with an example.
| Type of Risk | Description | Example |
|---|---|---|
| Data Security Risk | The vendor suffers a cyber incident that exposes the personal data it holds for you | An email marketing provider is breached, exposing the customer contact database |
| Processing Beyond Instructions | The vendor uses personal data for purposes beyond what the contract agreed | A vendor uses your customer data to market its own products |
| Subprocessor Chain Risk | Personal data is passed to another subprocessor without your knowledge or consent | A hosting vendor quietly hands data management to another cloud provider |
| Data Retention Risk | The vendor keeps personal data after the contract ends or the data is no longer needed | Former customers’ data sits in a vendor’s old system for years after termination |
| Excess Access Risk | The vendor grants more of its own staff access to personal data than the work requires | A former vendor employee can still open your customer records after resigning |
These 5 categories rarely occur in isolation, since one poor vendor practice usually triggers more than one at once. A vendor careless about data retention is typically just as careless about controlling who can still access that data.
5 Steps to Manage Personal Data Risk at Vendors
Managing personal data risk at vendors follows 5 steps in order: classify vendors, run due diligence, build required clauses into the contract, monitor regularly, and prepare an exit process. Each step is explained below.
1. Classify Vendors by the Type and Volume of Personal Data They Access
Not every vendor processes personal data with the same intensity, so oversight shouldn’t be one-size-fits-all. A vendor handling sensitive data or large volumes of customer data belongs in a critical tier, while a vendor supplying office stationery doesn’t need that level of scrutiny.
2. Run Due Diligence on the Vendor’s Data Protection Practices
Before signing, ask the vendor to show how it stores, restricts access to, and secures the personal data it will process for you. This step is the one most often skipped, usually because procurement is in a rush to close the deal.
3. Build Required Clauses Into the Vendor Contract
A vendor contract needs clear terms on processing instructions, confidentiality obligations, security standards, and your right to audit. The UK’s ICO takes a similar approach: contracts should state that the vendor may only process data on documented instructions, must report incidents, and can’t bring in a subprocessor without prior written consent.
4. Monitor How Vendors Handle Personal Data on an Ongoing Basis
An assessment done only at onboarding loses relevance fast once a vendor’s data practices change. Schedule a review at least annually for critical vendors, and sooner if there’s any change in how they store or access your customers’ data.
5. Make Sure Personal Data Is Deleted or Returned When the Contract Ends
Contracts should require the vendor to delete or return all personal data once the relationship ends, with proof of deletion. Without that clause, customer data can quietly sit in a former vendor’s systems without your knowledge.

Common Mistakes Companies Make Managing Vendor Data Risk
There are at least 5 mistakes that most often undermine how companies manage personal data risk at vendors. Recognising the pattern helps avoid repeating it.
- Assessing a vendor once at the start of the contract, without ever reviewing how they handle personal data afterward.
- Leaving legal out of the contract negotiation, resulting in weak or missing data protection clauses.
- Granting a vendor broader access to personal data than its work actually requires.
- Having no complete list of every vendor with access to personal data, which lets unmonitored “shadow vendors” slip through.
- Failing to require deletion of personal data once a contract ends or the data is no longer needed.
Conclusion
Personal data risk at vendors doesn’t end the moment a contract is signed, because legal responsibility stays with the company that appointed the vendor in the first place. Classifying vendors, running due diligence early, writing clear contract clauses, and monitoring continuously are what decide whether this risk is genuinely managed or just waiting to become a problem.
The more business functions get handed to third parties, the larger the risk surface a company has to watch. Managing this by hand in a spreadsheet might work for the first handful of vendors, but it stops scaling once the vendor list keeps growing.
Ready to Manage Privacy Compliance as a Business Risk?
See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.
FAQ
The PDP Law doesn’t use the term “due diligence” explicitly, but the duty to ensure a processor follows instructions and the law effectively requires that kind of review. Without it, a controller would struggle to demonstrate its own compliance.
Your company as the controller can still be held legally accountable. The vendor, as processor, can also be held liable if it’s shown to have processed data outside the instructions given.
Yes, since a subprocessor appointed by your main vendor still has access to the same data. Contracts with the main vendor should require written consent before any subprocessor is brought in.
At least once a year for vendors with access to critical data, and sooner if there’s a meaningful change in their service. Lower-risk vendors can go on a longer review cycle.
Yes. The PDP Law applies extraterritorially, so processing the personal data of people in Indonesia can bring both parties into scope regardless of where either company is based.




