A contract cannot move the obligation off you. What it can do is make your vendor give you the things you need to meet it.
Six words in the Act settle it: a Data Fiduciary is responsible irrespective of any agreement to the contrary.
The Board comes to you, not to your vendor. If a processor you engaged loses personal data, the failure is yours to answer for — whatever the indemnity clause says, and however clearly the contract allocates blame. That allocation still matters. It just operates between you and the vendor, afterwards, and never between you and the regulator.
Which is why a review that only reads the liability clauses has read the least useful part of the document.
Reading contracts is the fast part. Establishing which contracts to read is usually where the time goes.
Named suppliers, the tools somebody expensed, the agency with a spreadsheet. Almost nobody has this list, and the ones with no contract at all only surface here.
Not against a European template. Breach timing versus Rule 7, the Rule 6 safeguards, your power to make them stop, sub-processors, and where the data physically sits.
Red, amber or green, with the reason in one line a non-lawyer can act on, and the contracts ranked by what they would actually cost you if they were tested.
A DPDP agreement you can put in front of any supplier, amendment letters for contracts not worth reopening, and support when a large vendor pushes back — which they will.
Where a vendor will not move and cannot be replaced, the outcome is a written accepted risk rather than an open one. That is a real deliverable and not a failure: a documented decision to live with a known gap is defensible, and the same gap unrecorded is not.
The Act does not list mandatory clauses. So each of these exists because one of your obligations cannot be discharged without it.
A stated number of hours for the vendor to tell you about an incident — small enough that your own clock has not already run.
NotificationThe safeguards Rule 6 actually names, applied to their systems: encryption or masking, access control, monitoring, backups, a year of logs.
SecurityA duty to stop when you tell them to. On a withdrawal you must cause your processors to cease — which needs a clause that lets you.
CeaseCooperation on rights requests, inside your timeline rather than theirs. You cannot answer for data you cannot reach.
RightsErasure that reaches their copies and their backups, and return or deletion when the contract ends rather than whenever they get round to it.
DeletionWhere the data is stored and processed, named. Transfer abroad is allowed except to countries the government restricts — but you have to know.
LocationSub-processors declared, and the same terms flowed down. Their supplier is still processing your data, and still your responsibility.
Sub-processorsA right to verify — evidence, a questionnaire, an audit. Otherwise every safeguard above is something you were told rather than something you know.
VerifyA word on the templates being sold in this market. GDPR Article 28(3) enumerates eight mandatory terms; DPDP does not, and a European template dropped into an Indian contract carries obligations you do not owe while missing the Rule 6 and Rule 7 specifics you do. Familiar shape, wrong statute.
It is the most common breach-notification wording in the market, and against Rule 7 it is unusable.
Rule 7 requires you to intimate the Data Protection Board without delay on becoming aware of a breach, and to give full particulars within seventy-two hours. A breach inside your processor is still your breach; awareness is the trigger, not fault.
If the contract says they will inform you “promptly” or “without undue delay”, they have promised nothing measurable. Four days later is still arguably prompt, and by then your seventy-two hours are gone.
Twenty-four hours is the usual landing point, and it is not arbitrary: it leaves you two clear days to establish what happened, work out who is affected and file something the Board can use.
A notice saying “we experienced a security event” starts your clock without helping you meet it. What was taken, whose, when, and what they have done — named in the contract, because you will not get it by asking politely at 2am.
This is the clause we find broken most often, in contracts everyone had already signed off. It is also the cheapest to fix, because a vendor asked to put a number on their own incident process rarely refuses — they simply had not been asked.
Attention goes to the one agreement your lawyer drafted. The risk sits in the forty nobody read.
Every SaaS tool came with a data addendum accepted at sign-up. It was written to protect the vendor, it is the operative contract, and nobody in your business has read it.
Free plans routinely carry weaker data terms than paid ones, and sometimes permit uses that would horrify you. Free is a pricing decision that changed your legal position.
The agency with a spreadsheet of your customers. The consultant with a database export. Section 8(2) permits a processor only under a valid contract — none is a failure by itself.
Signed in 2019, auto-renewing, silent on data protection because nothing required it then. It is still the contract governing what they may do today.
Your vendor’s hosting, their analytics, their support desk in another country. Your data reaches all of them, and your responsibility travels with it.
Which is why this is a review service before it is a drafting service. Drafting a good DPA is a day’s work. Finding out what you have already agreed to, across everything that touches personal data, is the part nobody has done.
A position on every vendor that touches personal data, and the paperwork to move the ones that need moving.
Where a vendor will not move and cannot be replaced, you get that in writing as an accepted risk rather than an open one.
Some vendors will refuse. A documented decision to accept a known gap is a defensible position; the same gap undocumented is negligence.
Not in the sense the question usually means. Section 8(1) makes a Data Fiduciary responsible for compliance "irrespective of any agreement to the contrary" — so a contract cannot move your statutory duty onto a processor. If they lose the data, the Board's conversation is with you. What the contract does is give you recourse against the vendor afterwards, and give you the levers your own obligations depend on: notification in time, cooperation on rights requests, the power to make them stop. Those are worth having. They are just not the same as being covered.
As a starting point, with edits, and only if somebody reads it properly. GDPR Article 28(3) enumerates eight mandatory terms; the DPDP Act does not enumerate any, which means the European template is neither sufficient nor necessary here. It typically carries obligations you do not owe under Indian law while missing what you do need — the specific safeguards Rule 6 names, and a notification window that works against Rule 7's seventy-two hours. Familiar shape, wrong statute.
It is not a deadline. Rule 7 requires you to intimate the Board without delay on becoming aware of a breach and to furnish full particulars within seventy-two hours — and a breach inside your processor is your breach. If the contract only obliges them to tell you "promptly", four days later is arguably still prompt, and your seventy-two hours have gone. The fix is a number, usually twenty-four hours, plus a list of what has to arrive with the notice. It is the clause we find broken most often and the easiest one to get changed.
Often true, and worth planning for rather than discovering. Large providers publish standard data terms and will not redline them for a mid-sized Indian customer. Three things still help: their published terms are frequently better than people assume and simply need reading, some maintain India-specific or regional addenda that are not offered unless requested, and where neither applies you document the gap as an accepted risk with a reason. A known gap on the record is a defensible position. The same gap unnoticed is not.
Yes, and it is often the more commercially urgent half. If you are processing on behalf of a client, their DPA is landing on your desk with terms their counsel wrote, and every unreviewed one is an obligation you have accepted on your own operations. We review what you are being asked to sign, tell you which commitments you can actually keep, and give you a position to negotiate from. Being able to answer that paperwork quickly also stops shortening your sales cycle from being somebody else's problem.
It depends almost entirely on how many vendors you have and whether anybody knows. With a maintained list, reading and positioning the contracts is fast. Without one — which is more common — the first task is establishing who actually touches personal data, and that is discovery work rather than legal work. We will tell you which of the two you are buying before you commit to either.
Real client quotes, attributed by role and sector — we never name a client.
Working across
The contract you would write is not the risk. The forty already in force, written by somebody else, are.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.