Operate · DPA & Contract Review

Data processing agreements under DPDP

A contract cannot move the obligation off you. What it can do is make your vendor give you the things you need to meet it.

Talk to us The clause most DPAs get wrong Most of your exposure is in contracts you signed, not ones you wrote.
§8(1)

You cannot contract your way out of this

Six words in the Act settle it: a Data Fiduciary is responsible irrespective of any agreement to the contrary.

The Board comes to you, not to your vendor. If a processor you engaged loses personal data, the failure is yours to answer for — whatever the indemnity clause says, and however clearly the contract allocates blame. That allocation still matters. It just operates between you and the vendor, afterwards, and never between you and the regulator.

What a DPA does do

  • Satisfies section 8(2), which permits a processor only under a valid contract
  • Gives you the power section 6(6) assumes — to cause them to stop processing
  • Obliges them to tell you about an incident in time for you to meet your own clock
  • Obliges them to help you answer a rights request you cannot answer alone
  • Gives you recourse against the vendor for what their failure costs you
  • Counts as diligence, which section 33(2) makes a factor in any penalty

What no DPA can do

  • Move your statutory responsibility onto the processor
  • Make their non-compliance stop being your non-compliance
  • Give you a defence that the vendor promised to behave
  • Substitute for actually knowing what they do with the data

Which is why a review that only reads the liability clauses has read the least useful part of the document.

What we actually do

The engagement, in four steps

Reading contracts is the fast part. Establishing which contracts to read is usually where the time goes.

1

We build the list of who touches your data

Named suppliers, the tools somebody expensed, the agency with a spreadsheet. Almost nobody has this list, and the ones with no contract at all only surface here.

2

We read every agreement against your duties

Not against a European template. Breach timing versus Rule 7, the Rule 6 safeguards, your power to make them stop, sub-processors, and where the data physically sits.

3

You get a position on each vendor

Red, amber or green, with the reason in one line a non-lawyer can act on, and the contracts ranked by what they would actually cost you if they were tested.

4

We fix the ones that do not hold

A DPDP agreement you can put in front of any supplier, amendment letters for contracts not worth reopening, and support when a large vendor pushes back — which they will.

Where a vendor will not move and cannot be replaced, the outcome is a written accepted risk rather than an open one. That is a real deliverable and not a failure: a documented decision to live with a known gap is defensible, and the same gap unrecorded is not.

Working backwards from your own duties

What has to be in it, and why

The Act does not list mandatory clauses. So each of these exists because one of your obligations cannot be discharged without it.

§8(6) · Rule 7₹200 Cr

A stated number of hours for the vendor to tell you about an incident — small enough that your own clock has not already run.

Notification
§8(5) · Rule 6₹250 Cr

The safeguards Rule 6 actually names, applied to their systems: encryption or masking, access control, monitoring, backups, a year of logs.

Security
§6(6)₹50 Cr

A duty to stop when you tell them to. On a withdrawal you must cause your processors to cease — which needs a clause that lets you.

Cease
§11–14₹50 Cr

Cooperation on rights requests, inside your timeline rather than theirs. You cannot answer for data you cannot reach.

Rights
§8(7) · Rule 8₹50 Cr

Erasure that reaches their copies and their backups, and return or deletion when the contract ends rather than whenever they get round to it.

Deletion
§16 · Rule 15₹50 Cr

Where the data is stored and processed, named. Transfer abroad is allowed except to countries the government restricts — but you have to know.

Location
§8(1)–(2)₹50 Cr

Sub-processors declared, and the same terms flowed down. Their supplier is still processing your data, and still your responsibility.

Sub-processors
§8(5)₹250 Cr

A right to verify — evidence, a questionnaire, an audit. Otherwise every safeguard above is something you were told rather than something you know.

Verify

A word on the templates being sold in this market. GDPR Article 28(3) enumerates eight mandatory terms; DPDP does not, and a European template dropped into an Indian contract carries obligations you do not owe while missing the Rule 6 and Rule 7 specifics you do. Familiar shape, wrong statute.

The one worth checking tonight

“Without undue delay” is not a deadline

It is the most common breach-notification wording in the market, and against Rule 7 it is unusable.

1

Your clock starts when they find out

Rule 7 requires you to intimate the Data Protection Board without delay on becoming aware of a breach, and to give full particulars within seventy-two hours. A breach inside your processor is still your breach; awareness is the trigger, not fault.

2

Their clause decides whether you can

If the contract says they will inform you “promptly” or “without undue delay”, they have promised nothing measurable. Four days later is still arguably prompt, and by then your seventy-two hours are gone.

3

So it has to be a number

Twenty-four hours is the usual landing point, and it is not arbitrary: it leaves you two clear days to establish what happened, work out who is affected and file something the Board can use.

4

And it has to say what arrives with it

A notice saying “we experienced a security event” starts your clock without helping you meet it. What was taken, whose, when, and what they have done — named in the contract, because you will not get it by asking politely at 2am.

This is the clause we find broken most often, in contracts everyone had already signed off. It is also the cheapest to fix, because a vendor asked to put a number on their own incident process rarely refuses — they simply had not been asked.

Where the exposure actually is

You sign far more of these than you write

Attention goes to the one agreement your lawyer drafted. The risk sits in the forty nobody read.

01

The terms somebody clicked

Every SaaS tool came with a data addendum accepted at sign-up. It was written to protect the vendor, it is the operative contract, and nobody in your business has read it.

02

The tools on a free tier

Free plans routinely carry weaker data terms than paid ones, and sometimes permit uses that would horrify you. Free is a pricing decision that changed your legal position.

03

The ones with no contract at all

The agency with a spreadsheet of your customers. The consultant with a database export. Section 8(2) permits a processor only under a valid contract — none is a failure by itself.

04

The contract that predates the Act

Signed in 2019, auto-renewing, silent on data protection because nothing required it then. It is still the contract governing what they may do today.

05

Their suppliers, whom you never chose

Your vendor’s hosting, their analytics, their support desk in another country. Your data reaches all of them, and your responsibility travels with it.

Which is why this is a review service before it is a drafting service. Drafting a good DPA is a day’s work. Finding out what you have already agreed to, across everything that touches personal data, is the part nobody has done.

The engagement

What you get

A position on every vendor that touches personal data, and the paperwork to move the ones that need moving.

Reviewing what exists

  • Every vendor that touches personal data, listed — including the unlisted ones
  • Each contract read against your obligations, not against a European template
  • A red / amber / green position per vendor, with the reason in one line
  • The breach-notification clause checked against Rule 7 in every single one
  • Sub-processors and storage locations pulled out and named
  • The vendors operating with no contract at all, which is its own finding

Fixing what does not hold

  • A DPDP data processing agreement you can put in front of any supplier
  • Amendment letters for contracts not worth reopening in full
  • Negotiation support where the vendor pushes back, which the big ones will
  • A due-diligence questionnaire for suppliers you have not signed yet
  • Clauses for your own customer contracts, where you are the processor

Where a vendor will not move and cannot be replaced, you get that in writing as an accepted risk rather than an open one.

The last point is not a footnote.

Some vendors will refuse. A documented decision to accept a known gap is a defensible position; the same gap undocumented is negligence.

Questions

Straight answers

If we have a signed DPA, are we covered?

Not in the sense the question usually means. Section 8(1) makes a Data Fiduciary responsible for compliance "irrespective of any agreement to the contrary" — so a contract cannot move your statutory duty onto a processor. If they lose the data, the Board's conversation is with you. What the contract does is give you recourse against the vendor afterwards, and give you the levers your own obligations depend on: notification in time, cooperation on rights requests, the power to make them stop. Those are worth having. They are just not the same as being covered.

Can we use our GDPR data processing agreement?

As a starting point, with edits, and only if somebody reads it properly. GDPR Article 28(3) enumerates eight mandatory terms; the DPDP Act does not enumerate any, which means the European template is neither sufficient nor necessary here. It typically carries obligations you do not owe under Indian law while missing what you do need — the specific safeguards Rule 6 names, and a notification window that works against Rule 7's seventy-two hours. Familiar shape, wrong statute.

What is actually wrong with "without undue delay"?

It is not a deadline. Rule 7 requires you to intimate the Board without delay on becoming aware of a breach and to furnish full particulars within seventy-two hours — and a breach inside your processor is your breach. If the contract only obliges them to tell you "promptly", four days later is arguably still prompt, and your seventy-two hours have gone. The fix is a number, usually twenty-four hours, plus a list of what has to arrive with the notice. It is the clause we find broken most often and the easiest one to get changed.

Our vendor is a large multinational. They will not negotiate.

Often true, and worth planning for rather than discovering. Large providers publish standard data terms and will not redline them for a mid-sized Indian customer. Three things still help: their published terms are frequently better than people assume and simply need reading, some maintain India-specific or regional addenda that are not offered unless requested, and where neither applies you document the gap as an accepted risk with a reason. A known gap on the record is a defensible position. The same gap unnoticed is not.

We are the processor — our customers send us DPAs. Does this help?

Yes, and it is often the more commercially urgent half. If you are processing on behalf of a client, their DPA is landing on your desk with terms their counsel wrote, and every unreviewed one is an obligation you have accepted on your own operations. We review what you are being asked to sign, tell you which commitments you can actually keep, and give you a position to negotiate from. Being able to answer that paperwork quickly also stops shortening your sales cycle from being somebody else's problem.

How long does a review take?

It depends almost entirely on how many vendors you have and whether anybody knows. With a maintained list, reading and positioning the contracts is fast. Without one — which is more common — the first task is establishing who actually touches personal data, and that is discovery work rather than legal work. We will tell you which of the two you are buying before you commit to either.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Start with what you signed.

The contract you would write is not the risk. The forty already in force, written by somebody else, are.