There is a sentence buried in India's data protection framework that should change how B2B marketing leaders think about vendor selection. Compliance responsibility rests with the data fiduciary even where the processing is actually carried out by a data processor, and the Rules expressly require appropriate security provisions in the contracts between them. Fisher Phillips
Read that in martech terms. Your marketing automation platform, your enrichment vendor, your chat tool, your CDP, your ad platforms: every one of them is a data processor acting on your instructions. When one of them mishandles personal data, the regulator does not knock on their door. It knocks on yours.
This is not a theoretical risk with a distant price tag. Penalties under the DPDP Act can reach ₹250 crore per violation, and vendor contract clauses are one of the most commonly underestimated line items in compliance budgets. Vinsys
Most organisations discover this in the worst possible order. They buy the platform, integrate it, build campaigns on it, and only reach for the data processing agreement when a prospect's security team asks for it or a breach notification clock starts running. By then the leverage is gone. The renewal is signed, the data is in, and the switching cost is exactly what the vendor hoped it would be.
The alternative is to treat these eight questions as a gate. Not a scorecard. A gate.
Why This Is Binary and Not a Score
Almost everything else about a martech platform is a matter of degree. Adoption can be moderate. Contribution can be plausible but not yet proven. Cost can be a bit high and still worth it. You can hold all of those on a five-point scale and make a reasonable trade.
Compliance does not behave that way. There is no useful sense in which consent lineage is a three out of five. Either withdrawal propagates to that platform reliably, or it does not and you are processing data you no longer have permission to process. Either you know where the data physically sits, or you are making a representation to your customers that you cannot substantiate.
A partial pass is a fail wearing better clothes. So the gate returns one of two values, and a failure overrides every other strength the platform has. A tool that is beautifully adopted, demonstrably driving pipeline, and cheap is still a liability if it cannot clear these eight. In fact it is a worse liability than an unused one, because more data has flowed through it.
The Eight Questions
1. What personal data do you hold on our behalf, and for what purpose?
You are asking for a specific inventory, not a category list. A good answer names the fields, the volume, the retention period, and the processing purpose for each. A red flag is any answer that begins with "it depends on your configuration" and ends there. If the vendor cannot tell you what they hold, you cannot tell a regulator, and you are the one who has to.
2. What lawful basis are we relying on for each processing purpose?
This one belongs jointly to you and the vendor, which is exactly why it gets dropped. The vendor should be able to show which of their processing activities sit inside your instructions and which they perform for their own purposes, such as product improvement or benchmarking. The second category is where most surprises live. Any processing a vendor does for its own purposes needs its own basis, and if it is not documented, it is not defensible.
3. When a person withdraws consent, what happens in your system and how fast?
This is the hardest question in the set and the one most vendors answer badly. A good answer describes an API or webhook that receives the withdrawal, a defined propagation window measured in hours, and confirmation that suppression applies to derived and enriched records, not just the original one. A red flag is a manual suppression list, a monthly batch process, or any answer that treats consent as a static field rather than a state that changes.
4. Where is our data stored and processed, and is that contractually fixed?
Ask for named regions, not a cloud provider's name. Then ask whether those regions can change without your consent. Many contracts allow the vendor to relocate processing at will, which quietly converts your data residency position from a commitment into a preference. The answer you want is a specific region named in the contract with a change-notification obligation attached.
5. Who are your sub-processors, and how are we told when the list changes?
Every vendor uses other vendors. Under GDPR, processors need your prior authorisation before engaging a sub-processor, and the same logic runs through the DPDP framework's accountability chain. A good answer is a published, versioned sub-processor list with a notification period of thirty days or more and a right of objection. A red flag is a list that exists only in the DPA appendix, has no version history, and changes silently.
6. What AI features are active on our account, and what do they access?
This one gets its own section below, because it is now the most common source of undisclosed processing in the stack.
7. How is access controlled on your side, and how often is it reviewed?
You are asking two things: how your own users' access is governed through roles and permissions, and how the vendor's own staff access your tenant. Support engineers with standing production access are common and rarely disclosed. A good answer includes role-based access on both sides, logged and time-bound support access, and a review cadence of at least twice a year. If they cannot tell you who at their company can read your customer records today, nobody can.
8. On termination, how do we get our data out and how do we know it is gone?
Ask for the export format, the completeness of the export including derived fields, the deletion timeline, and whether deletion extends to backups and sub-processors. Then ask for written confirmation of deletion as a contractual deliverable. The best time to test this is before you sign, when the vendor still wants the deal. The worst time is the day you decide to leave.
The AI Clause Problem
Question six deserves separate treatment because it is the newest and least governed part of the stack.
A significant share of martech platforms have shipped generative and predictive features into existing contracts over the past two years, sometimes enabled by default, often under terms that predate the capability entirely. The contract you signed in 2023 did not contemplate an inference engine reading your customer records.
The scale of the problem is not subtle. Forrester expects B2B companies to lose more than $10 billion in enterprise value because of ungoverned use of generative AI, driven by an explosion of new and untested functionality combined with lagging user skills. Internal readiness has not kept pace: 70 percent of CMOs say their marketing processes are not mature enough to implement and scale AI effectively. Scott Brinker's reading of the market points the same direction, noting that as AI moves from content generation into orchestration, governance is trailing adoption. Forrester + 3
Four questions close most of the gap. What data do the AI features access, and can that scope be restricted? Where does inference happen, and does it stay inside our contracted region? Are prompts, inputs, or outputs retained, and for how long? And does any of our data contribute to training a model that other customers benefit from?
That last one is the question people forget to ask and the one that most often produces an uncomfortable pause. Get the answer in writing. If the vendor's standard terms permit training on customer data, ask for an opt-out amendment. Most will grant it. Very few will volunteer it.
The Timeline You Are Working Against
For any organisation with Indian operations or India-linked data flows, the dates are now fixed.
The DPDP Rules were finalised in November 2025, and most operational obligations including notice and consent, breach notification, and individual rights handling become enforceable across an eighteen-month implementation phase ending in mid-May 2027. The Consent Manager registration framework carries a November 2026 milestone, with penalty enforcement expected from May 2027. The period through to late 2026 is widely expected to be one of soft enforcement, with guidance and warnings rather than penalties, before hard enforcement begins. Fisher Phillips + 2
That soft enforcement window is the cheapest time you will ever have to fix a vendor governance gap. It is also finite. Contract amendments take a quarter. Sub-processor reviews take a quarter. Re-platforming a vendor that cannot clear the gate takes considerably longer than that, and the notice period on your current contract does not pause while you decide.
The practical sequence is straightforward: run the eight questions against your top ten platforms by spend this quarter, run them against the long tail next quarter, and time every remediation conversation to land sixty to ninety days ahead of the relevant renewal date. Before a renewal, these questions are leverage. After one, they are homework.
Where This Fits
The eight questions above are the governance gate from the ACES framework, pulled out and expanded because they carry disproportionate weight. In the full model, they sit underneath a four-axis score covering adoption, contribution, economics, and staying power, and a failure on any one of them overrides an otherwise healthy score.
If you want the complete framework, the scoring rubric, and the ninety-day rationalisation sequence, start with the pillar: Your Martech Stack Is a Portfolio. It Is Time to Manage It Like One.
If you want to run this against your own stack today, the ACES Martech Stack Scorecard includes all eight gate checks as a working checklist with remediation owners and target dates.

