Last reviewed: 27 August 2026. Basis: DPDP Act, 2023 and DPDP Rules, 2025 (notified November 2025).
The DPDP Act allows a data fiduciary to engage a data processor “only under a valid contract”, and the DPDP Rules, 2025 list contractual measures with processors among the reasonable security safeguards. A data processing agreement under DPDP is therefore the document that proves you controlled your vendors when the Data Protection Board asks. This guide sets out the 12 clauses a compliant agreement needs, with sample wording for six, marks negotiation red lines for each side, compares the result with a GDPR Article 28 DPA, and gives a rollout plan for existing vendors before May 2027.
Why a data processing agreement under DPDP is a legal requirement, not a nicety
The Act separates the data fiduciary, who decides purpose and means, from the data processor, who acts on its behalf. Two features matter for contracts: the fiduciary may engage a processor only under a valid contract, and it remains responsible for compliance regardless of that contract. You can outsource the work but not the liability.
The DPDP Rules, 2025 sharpen this. The reasonable security safeguards required under Section 8 include encryption, access control, logging and monitoring with logs retained for at least one year, backups, and contractual measures with data processors. A fiduciary whose vendor loses data and who cannot produce a contract obliging that vendor to protect it has, in our reading, failed the security safeguards duty itself, which the Schedule caps at Rs 250 crore. Our penalties Schedule explainer sets out the tiers.
The timeline is tight. Security safeguards and breach notification become enforceable in May 2027, and most Indian businesses have dozens to hundreds of vendors touching personal data. Each needs a contract that reflects the Act before that date.
DPDP vendor contract clauses: the 12 you cannot leave out
The Act does not prescribe a clause list the way GDPR Article 28 does. That gives drafting freedom, but the Board will judge whether your contract actually delivered the safeguards the Act expects. In practice, these 12 clauses are the minimum. Sample language is given for the six that generate the most negotiation.
1. Scope and purpose
State the categories of data principals and personal data, the processing operations, and the specified purpose. Tie the purpose to your Section 5 notice, because a processor cannot be asked to do something you never told the data principal about.
Sample clause: “The Processor shall process Personal Data solely for the purposes in Schedule 1. Any other processing requires the Fiduciary’s prior written instruction. The Processor acknowledges that Data Principals have been given notice for the Schedule 1 purposes only.”
2. Processing on documented instructions
The processor acts only on documented instructions and must flag any instruction it believes would breach the Act. This clause keeps the vendor a processor rather than a fiduciary in its own right.
3. Security safeguards
Do not write “industry standard security”. Mirror the Rules.
Sample clause: “The Processor shall implement and maintain, at minimum, the safeguards in Schedule 2, which include: encryption of Personal Data in transit and at rest; access limited to personnel with a documented need; logging of access to and processing of Personal Data, with logs retained for not less than one year; and backups sufficient to restore Personal Data within the recovery objectives in Schedule 2.”
4. Sub-processing
Require prior authorisation for sub-processors, a maintained list, flow-down of the same obligations, and full responsibility for sub-processors’ acts. Most disputes with cloud and SaaS vendors sit here.
Sample clause: “The Processor shall not engage a Sub-processor without the Fiduciary’s prior written authorisation. The Processor shall impose on each Sub-processor, by written contract, obligations no less protective than those in this Agreement and shall remain fully liable to the Fiduciary for the performance of each Sub-processor.”
5. Breach notification and assistance timelines
The fiduciary must notify affected data principals and the Board without delay and file a detailed report within 72 hours; CERT-In Directions separately require reporting of listed incidents within 6 hours. If the vendor takes five days to tell you, both deadlines are gone. The contract must set a much shorter clock.
Sample clause: “The Processor shall notify the Fiduciary of any Personal Data Breach without undue delay and in any event within 12 hours of becoming aware of it, providing the information in Schedule 3, and shall update that information as it becomes available. The Processor shall provide all assistance the Fiduciary reasonably requires to notify Data Principals, the Data Protection Board and CERT-In within applicable statutory timelines.”
Our 72-hour breach response guide shows how this clock feeds your own runbook.
6. Assistance with data principal rights
Data principals can seek access, correction, erasure and grievance redressal under Sections 11 to 14, within the period you publish under the Rules (maximum 90 days). The processor must locate, correct and erase data within a window that leaves you time to respond.
7. Retention and deletion on termination
Section 8 requires erasure when the purpose is served. The processor must delete or return data on termination or instruction, certify deletion, and clear backups within a stated cycle.
Sample clause: “Within 30 days of termination or expiry, or earlier on the Fiduciary’s instruction, the Processor shall return or securely delete all Personal Data, including copies held by Sub-processors, and shall certify deletion in writing. Personal Data in backup media shall be deleted within the Processor’s standard backup rotation cycle, not exceeding 90 days, and shall not be restored to live systems.”
8. Audit and evidence
The Board can require evidence, and Significant Data Fiduciaries face an independent data audit under Section 10. Reserve the right to request evidence and to audit on reasonable notice.
Sample clause: “The Processor shall, on 15 days’ notice and not more than once in any 12 months (or at any time following a Personal Data Breach), permit the Fiduciary or an independent auditor bound by confidentiality to audit its compliance with this Agreement, and shall provide on request the evidence in Schedule 4.”
9. Cross-border processing
Section 16 permits transfers except to countries restricted by Central Government notification. Require disclosure of processing locations, advance notice of changes, and cessation of transfers to any restricted country. Sector rules such as RBI payment data localisation may be stricter. See our Section 16 cross-border explainer.
10. Confidentiality and personnel
Personnel with access must be under written confidentiality obligations, trained, and background-checked in proportion to the data.
11. Liability and indemnity
Penalties fall on the fiduciary, so the contract is your only route to recover from a vendor. Cover indemnity for penalties and third-party claims caused by the processor, and negotiate the cap deliberately rather than accepting a fee-based boilerplate.
12. Term and survival
Confidentiality, deletion, audit rights for a defined period, and indemnity must survive termination.
Negotiation red lines in a dpdp third party contract: fiduciary versus processor
Both sides have legitimate positions. The table shows where each should hold and where it can concede.
A processor that refuses any breach notice, audit or deletion obligation cannot meet the Act. In practice, that is a vendor to replace, not negotiate with.
Data processor agreement India template versus a GDPR Article 28 DPA
GDPR-style DPAs signed with European customers or global SaaS vendors are a useful starting point, not a substitute.
In practice a GDPR DPA needs its breach clock tightened, log retention added, the Board and CERT-In named as recipients, the rights window aligned to your published period, and the cross-border clause rewritten around restricted-country notifications rather than adequacy. For a broader comparison, see our DPDP 101 primer and the Act and Rules Explorer.
Rolling out a dpa template india across vendors you already have
New vendors are easy. The harder job is the existing base. A workable rollout, with indicative timelines, looks like this.
Step 1: Inventory and tier (3 to 4 weeks)
List every vendor that receives, stores or can access personal data and tier them by volume, sensitivity and substitutability. Tier 1 holds customer or employee data at scale (payroll, cloud, CRM, support outsourcing); Tier 3 has incidental exposure, such as a courier receiving a name and address. Our Readiness Checklist includes a vendor inventory section.
Step 2: Decide the instrument (1 week)
Tier 1: a standalone agreement or comprehensive addendum. Tier 2: an addendum to the master agreement. Tier 3: standard clauses in purchase order terms. Negotiating a full DPA with 300 vendors is how programmes stall.
Step 3: Issue and negotiate (8 to 12 weeks)
Send the addendum with a cover note citing the statutory basis and the May 2027 date. Global vendors will offer their own DPDP addendum; review it against the 12 clauses rather than redlining line by line. Track responses in a register.
Step 4: Handle refusers (ongoing)
A vendor that will not sign leaves three options: accept a documented risk with a replacement plan, restrict the data shared, or exit. Record the decision. A documented risk decision is more defensible than a missing contract with no explanation.
Step 5: Evidence and maintenance
File signed agreements, sub-processor lists and evidence packs in one place, with a trigger to re-check whenever a restricted country is notified. Our vendor remediation guide covers the register format we use.
Indicative effort for a mid-sized company with 80 to 150 data-touching vendors is 12 to 20 weeks of part-time work by legal, procurement and IT. Start in 2026.
Frequently Asked Questions
Does the DPDP Act require a written data processing agreement?
The Act says a fiduciary may engage a processor only under a valid contract, and the DPDP Rules, 2025 list contractual measures with processors among the reasonable security safeguards. In our reading, a written agreement is the only practical way to evidence both. Treat it as mandatory.
Can our existing GDPR DPA with a vendor serve as our DPDP agreement?
Only partly. A GDPR DPA has the right structure but the wrong timelines, recipients and cross-border mechanics. Tighten the breach clock, add log retention of at least one year, name the Data Protection Board and CERT-In, and align the rights window to the period you publish under the Rules.
How quickly should a processor be required to notify us of a breach?
The fiduciary must notify the Board and affected data principals without delay and file a detailed report within 72 hours, and CERT-In requires reporting of listed incidents within 6 hours. In practice we recommend initial contractual notice within 12 to 24 hours of awareness, with updates as information becomes available.
Is the fiduciary still liable if the processor causes the breach?
Yes. The Act states that the fiduciary remains responsible for compliance regardless of any arrangement with a processor. The contract’s indemnity and liability clauses are your only route to recover losses from the vendor, so the cap deserves careful negotiation.
When do these contracts need to be in place?
Security safeguard and breach notification obligations become enforceable in May 2027, 18 months after the Rules were notified in November 2025. Given negotiation cycles of 8 to 12 weeks per wave of vendors, most organisations should have the programme running through 2026.
Related explainers
Next step
The 12 clauses above are drafted in full, with schedules for data description, security safeguards, breach information and audit evidence, in our vendor agreement template, part of the 16 DPDP Starter Templates. Download the vendor agreement template and issue it to your Tier 1 vendors this quarter.