Data Processing Agreements (DPA) under the DPDP Act: Clauses Every Contract Now Needs
A Data Processing Agreement is the only document that stops a vendor’s data-handling failure from becoming your organisation’s own legal liability under India’s Digital Personal Data Protection Act, 2023. Under Section 8(1) of the Act, the Data Fiduciary, the organisation determining the purpose and means of processing, remains continuously responsible for compliance in relation to processing carried out on its behalf, even when a third-party Data Processor is actually doing the processing. Section 8(2) goes further: a Data Fiduciary may engage a Data Processor for covered activities only under a valid contract. Without a proper DPA, the engagement itself is not compliant, regardless of how carefully the vendor otherwise handles the data. This guide covers what the DPDP Act and its 2025 Rules require in a Data Processing Agreement DPDP Act, the essential clauses every DPA needs, and the specific compliance deadlines enterprises should track. Where This Obligation Actually Comes From Section 8 of the Digital Personal Data Protection Act, 2023 contains the core provisions governing Data Fiduciaries and Data Processors. The distinction between the two roles matters considerably: the Act’s compliance obligations fall primarily on the Fiduciary, not the Processor, which is exactly why the Fiduciary needs a properly drafted DPA to ensure the Processor’s obligations are contractually locked in, rather than relying on the Processor’s own goodwill or general data-handling reputation. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, alongside the establishment of the Data Protection Board of India, providing the detailed operational requirements the Act itself left to subordinate rulemaking. Critically, the DPDP Act does not prescribe specific mandatory DPA clauses by name. Instead, the required content of a compliant DPA is derived by combining Section 8’s obligations, the DPDP Rules 2025 (particularly Rule 6 on security safeguards), and internationally established best practice for data processing contracts more broadly. One clarifying point worth noting: unlike the EU’s GDPR, which prescribes Standard Contractual Clauses for international data transfers, the DPDP Act leaves DPA drafting to the parties themselves, without a government-issued template clause set. This means the responsibility for getting the DPA’s substantive content right sits squarely with the drafting parties and their legal counsel, not with a government-supplied form that can simply be adopted wholesale. Does the DPA Need to Be a Standalone Document? No. The Act requires a “valid contract,” not necessarily a standalone Data Processing Agreement as a separate document. DPA-equivalent clauses can be incorporated directly into an existing service agreement or Master Service Agreement, provided the substantive requirements described below are genuinely addressed within that broader contract, rather than needing their own dedicated document in every case. Essential Clauses Every Data Processing Agreement DPDP Act Needs 1. Identity, roles, and scope of the parties Clearly establishes which party is the Data Fiduciary and which is the Data Processor (or Processors, where sub-processing is involved), and defines the scope and purpose of processing precisely, since the Processor’s use of personal information should be strictly limited to what the Fiduciary has actually authorised. 2. Categories of personal data and data principals Specifies precisely what categories of personal data are being processed and which categories of data principals (customers, employees, or other individuals) are involved, since this scoping directly determines the applicable security and compliance obligations that follow. 3. Purpose and duration of processing Defines exactly why the processing is happening and for how long, preventing the Processor’s use of the data from quietly expanding beyond the originally authorised purpose over the life of the relationship. 4. Security safeguards Establishes appropriate security obligations specifically, rather than relying on a generic confidentiality clause borrowed from an unrelated template. Rule 6 of the DPDP Rules, 2025 governs this area directly, and the DPA should reflect the specific technical and organisational security measures the Processor commits to maintaining. 5. Data subject rights assistance Requires the Processor to cooperate with and support the Fiduciary’s obligations to respond to data principal requests, such as access, correction, or erasure requests, since the Fiduciary remains ultimately responsible for fulfilling these rights even where the underlying data actually sits with the Processor. 6. Breach notification and incident response This is one of the most operationally critical clauses in any DPA. A well-drafted breach notification clause typically requires the Processor to notify the Fiduciary within 24 hours of becoming aware of a breach, giving the Fiduciary the remaining time within the Act’s 72-hour notification window to prepare and submit its own notification to the Data Protection Board. Unlike the EU’s GDPR, the DPDP Act sets no minimum severity threshold for breach reporting, meaning even comparatively minor breaches can trigger a notification obligation, which makes a tight, enforceable notification timeline in the DPA considerably more important than it might be under a threshold-based regime. The Processor’s incident response plan should also be provided to the Fiduciary, ideally reviewed and refreshed annually. 7. Restrictions on sub-processing Addresses whether and how the Processor can engage its own sub-processors, requiring the Fiduciary’s prior approval before any sub-processor is brought into the processing chain, and ensuring sub-processors are bound by data protection obligations that are at least as protective as those the primary Processor has accepted. 8. Data residency and cross-border transfer terms For sectors or organisations subject to data residency requirements, whether for regulatory reasons or simply as an internal risk-management decision, the DPA should specify explicitly that personal data is processed and stored within India, and that the Processor will not transfer, access, or permit access to that data from outside India without the Fiduciary’s prior written consent for a specific, defined transfer. Section 16 of the DPDP Act separately allows the Central Government to restrict processing outside India to specified countries or territories through notification, which the DPA should be drafted to accommodate as that list develops. A DPA that allows the Processor discretion over where data is backed up or processed, for redundancy or similar reasoning, without the Fiduciary’s specific, informed consent, is a significant red flag rather than a routine
Data Processing Agreements (DPA) under the DPDP Act: Clauses Every Contract Now Needs Read More »











