“Where the processing is to be carried out on behalf of a data fiduciary, the data fiduciary shall only use processors who can offer adequate assurances of implementing suitable technical and organisational measures. These measures should ensure that the processing aligns with the stipulations of this Regulation and upholds the data principal's rights and protection."
In simpler terms, this means that the data fiduciary is obligated to select processors who adhere to the DPDP Act. If they fail to do so, they could face penalties themselves. As regulatory authorities enforce penalties on data fiduciaries for insufficient or improper vetting, processors might need to obtain independent compliance certifications to instil confidence in their prospective clients.