News
Data Privacy and AI Governance Enter Automotive Vendor Cybersecurity Assessments
Privacy, cloud data and AI governance now appear as mandatory sections in automotive vendor assessments, bringing DPDP duties into a commercial process.
Neha Dvivedi · 13 September 2026
Vendor cybersecurity assessments issued to Indian auto component manufacturers have widened beyond conventional information security controls. Data privacy, cloud data handling and the governance of artificial intelligence now appear as distinct assessed areas, and they are commonly categorised as mandatory rather than desirable. For suppliers, this brings DPDP Act compliance for manufacturing companies into a commercial process for the first time.
What has been added
Alongside the established control areas covering access control, logging, configuration management and physical security, current assessment instruments carry separate sections addressing data privacy, data privacy on cloud, and artificial intelligence security.
- Data privacy. Suppliers are asked whether personal data has been identified and inventoried, whether it is classified into sensitive and normal categories, what safeguards apply, and whether the organisation has determined its role as a Data Fiduciary or Data Processor. These map to ISO/IEC 27701 and, in India, to the Digital Personal Data Protection Act, 2023.
- Data privacy on cloud. Whether personal data is processed or stored in cloud environments, and whether the services used have been formally approved. ISO/IEC 27017 and ISO/IEC 27018 are the applicable standards.
- Artificial intelligence security. AI security checkpoints ask whether AI systems are used in operational or decision-making processes, whether any operate without human oversight, and whether the resulting risk has been formally assessed. ISO/IEC 42001 is the corresponding management system standard.
The inclusion of AI governance is notable. Most published commentary on automotive supply chain security does not yet address it, and few Indian component manufacturers hold any formal position on AI use.
The statutory overlap
Unlike the assessment itself, which is contractual, the privacy obligations sit on the supplier directly. The Digital Personal Data Protection Act, 2023 governs the handling of employee and customer personal data regardless of what any customer requires. The CERT-In Directions of April 2022 set incident reporting timelines and log retention obligations. Section 43A of the Information Technology Act, 2000, together with the rules on reasonable security practices, remains in force and expressly recognises ISO/IEC 27001 as a benchmark standard.
The practical consequence is that a supplier addressing the privacy sections of a customer assessment is largely doing work it already owes under Indian law. Treating the two as one programme costs less than treating them as two.
Why it is being asked now
The regulatory driver for automotive supplier cybersecurity requirements in India is AIS-189, the Cyber Security Management System standard, which applies to new vehicle types from October 2027 and to all vehicle types from October 2028, on a timetable that is still being given force through draft rules. AIS-190 covers software update management. Both are modelled on UNECE R155 and R156 and on ISO/SAE 21434, and the Ministry of Road Transport and Highways has moved to bind them through proposed Rules 125-T and 125-U.
The rules are in draft and the dates attached to them are not final. Check the current position on the Ministry of Road Transport and Highways site before planning against them.
AIS-189 requires the vehicle manufacturer to manage cybersecurity dependencies across suppliers, service providers and sub-organisations, with bilateral cybersecurity interface agreements allocating responsibility. Because the manufacturer must evidence control over its supply chain, the requirement cascades, and Tier 2 supplier cybersecurity requirements follow from the same logic.
Recent incidents have reinforced the concern about information leaving the supply chain. In June 2026 an extortion group published a dataset reported at more than 630 GB, said to contain component design documentation associated with global manufacturers. In the same month a ransomware attack on Bajaj Auto affected corporate IT infrastructure and an engineering subsidiary, and was reported to CERT-In under the Information Technology Act, 2000.
What suppliers should do
The privacy sections are among the least expensive to address, because the first requirement is an inventory rather than a technology purchase. Identifying what personal data the organisation holds, where it sits, who can reach it, whether any of it resides in cloud services, and whether the organisation acts as controller or processor addresses most of what is asked. Establishing a documented position on AI use, even if that position is that no AI system operates without human oversight, closes the remaining section.
Privacy obligations map to ISO/IEC 27701 and to DPDP Act compliance; the AI section maps to ISO/IEC 42001. The statutory obligations guide sets out what Indian law requires whether or not a customer asks. MSCi supports automotive suppliers through both. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. Try the free readiness checklist.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Vendor Cybersecurity Assessments Move from Advisory to Scored: What Indian Suppliers Are Now Being Measured On
Vehicle manufacturers in India now score suppliers on cybersecurity against weighted checklists, with corrective action deadlines. What is being measured.
13 September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Control Families, Scoring and Standards Mapping
What an automotive vendor cybersecurity assessment covers, how it is scored, the evidence it asks for, and how each control family maps to ISO standards.
13 September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 September 2026
