{"id":27292,"date":"2026-10-01T12:00:00","date_gmt":"2026-10-01T12:00:00","guid":{"rendered":"https:\/\/legistify.com\/learn\/?p=27292"},"modified":"2026-09-30T05:46:52","modified_gmt":"2026-09-30T05:46:52","slug":"data-processing-agreement-dpdp-act","status":"publish","type":"post","link":"https:\/\/legistify.com\/learn\/data-processing-agreement-dpdp-act\/","title":{"rendered":"Data Processing Agreements (DPA) under the DPDP Act: Clauses Every Contract Now Needs"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A Data Processing Agreement is the only document that stops a vendor&#8217;s data-handling failure from becoming your organisation&#8217;s own legal liability under India&#8217;s Digital Personal Data Protection Act, 2023. Under Section 8(1) of the Act, the Data Fiduciary, the organisation determining the purpose and means of processing, remains continuously responsible for compliance in relation to processing carried out on its behalf, even when a third-party Data Processor is actually doing the processing. Section 8(2) goes further: a Data Fiduciary may engage a Data Processor for covered activities only under a valid contract. Without a proper DPA, the engagement itself is not compliant, regardless of how carefully the vendor otherwise handles the data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide covers what the DPDP Act and its 2025 Rules require in a Data Processing Agreement DPDP Act, the essential clauses every DPA needs, and the specific compliance deadlines enterprises should track.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Where This Obligation Actually Comes From<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Section 8 of the Digital Personal Data Protection Act, 2023 contains the core provisions governing Data Fiduciaries and Data Processors. The distinction between the two roles matters considerably: the Act&#8217;s compliance obligations fall primarily on the Fiduciary, not the Processor, which is exactly why the Fiduciary needs a properly drafted DPA to ensure the Processor&#8217;s obligations are contractually locked in, rather than relying on the Processor&#8217;s own goodwill or general data-handling reputation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, alongside the establishment of the Data Protection Board of India, providing the detailed operational requirements the Act itself left to subordinate rulemaking. Critically, the DPDP Act does not prescribe specific mandatory DPA clauses by name. Instead, the required content of a compliant DPA is derived by combining Section 8&#8217;s obligations, the DPDP Rules 2025 (particularly Rule 6 on security safeguards), and internationally established best practice for data processing contracts more broadly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One clarifying point worth noting: unlike the EU&#8217;s GDPR, which prescribes Standard Contractual Clauses for international data transfers, the DPDP Act leaves DPA drafting to the parties themselves, without a government-issued template clause set. This means the responsibility for getting the DPA&#8217;s substantive content right sits squarely with the drafting parties and their legal counsel, not with a government-supplied form that can simply be adopted wholesale.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Does the DPA Need to Be a Standalone Document?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No. The Act requires a &#8220;valid contract,&#8221; not necessarily a standalone Data Processing Agreement as a separate document. DPA-equivalent clauses can be incorporated directly into an existing service agreement or Master Service Agreement, provided the substantive requirements described below are genuinely addressed within that broader contract, rather than needing their own dedicated document in every case.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Essential Clauses Every Data Processing Agreement DPDP Act Needs<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Identity, roles, and scope of the parties<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Clearly establishes which party is the Data Fiduciary and which is the Data Processor (or Processors, where sub-processing is involved), and defines the scope and purpose of processing precisely, since the Processor&#8217;s use of personal information should be strictly limited to what the Fiduciary has actually authorised.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Categories of personal data and data principals<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Specifies precisely what categories of personal data are being processed and which categories of data principals (customers, employees, or other individuals) are involved, since this scoping directly determines the applicable security and compliance obligations that follow.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Purpose and duration of processing<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Defines exactly why the processing is happening and for how long, preventing the Processor&#8217;s use of the data from quietly expanding beyond the originally authorised purpose over the life of the relationship.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Security safeguards<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Establishes appropriate security obligations specifically, rather than relying on a generic confidentiality clause borrowed from an unrelated template. Rule 6 of the DPDP Rules, 2025 governs this area directly, and the DPA should reflect the specific technical and organisational security measures the Processor commits to maintaining.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>5. Data subject rights assistance<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Requires the Processor to cooperate with and support the Fiduciary&#8217;s obligations to respond to data principal requests, such as access, correction, or erasure requests, since the Fiduciary remains ultimately responsible for fulfilling these rights even where the underlying data actually sits with the Processor.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>6. Breach notification and incident response<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is one of the most operationally critical clauses in any DPA. A well-drafted breach notification clause typically requires the Processor to notify the Fiduciary within 24 hours of becoming aware of a breach, giving the Fiduciary the remaining time within the Act&#8217;s 72-hour notification window to prepare and submit its own notification to the Data Protection Board. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike the EU&#8217;s GDPR, the DPDP Act sets no minimum severity threshold for breach reporting, meaning even comparatively minor breaches can trigger a notification obligation, which makes a tight, enforceable notification timeline in the DPA considerably more important than it might be under a threshold-based regime. The Processor&#8217;s incident response plan should also be provided to the Fiduciary, ideally reviewed and refreshed annually.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>7. Restrictions on sub-processing<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Addresses whether and how the Processor can engage its own sub-processors, requiring the Fiduciary&#8217;s prior approval before any sub-processor is brought into the processing chain, and ensuring sub-processors are bound by data protection obligations that are at least as protective as those the primary Processor has accepted.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>8. Data residency and cross-border transfer terms<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For sectors or organisations subject to data residency requirements, whether for regulatory reasons or simply as an internal risk-management decision, the DPA should specify explicitly that personal data is processed and stored within India, and that the Processor will not transfer, access, or permit access to that data from outside India without the Fiduciary&#8217;s prior written consent for a specific, defined transfer. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Section 16 of the DPDP Act separately allows the Central Government to restrict processing outside India to specified countries or territories through notification, which the DPA should be drafted to accommodate as that list develops. A DPA that allows the Processor discretion over where data is backed up or processed, for redundancy or similar reasoning, without the Fiduciary&#8217;s specific, informed consent, is a significant red flag rather than a routine operational convenience.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>9. Audit rights<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Gives the Fiduciary the right to audit the Processor&#8217;s compliance, whether directly or through an independent auditor, and should specify the scope, frequency, and process for exercising this right, since an audit right that exists on paper but has no defined mechanism for actually being exercised provides limited practical protection.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>10. Return or deletion of personal data on termination<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Requires the Processor to return or delete all personal data upon termination of the arrangement, with written confirmation of deletion provided to the Fiduciary. The DPDP Act does not prescribe specific retention periods, but does require that personal data be erased once the purpose for which it was collected has been fulfilled and retention is no longer necessary, making this an obligation the DPA needs to operationalise concretely rather than leave as a vague, aspirational statement.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>11. Indemnification for processor-caused breaches<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Allocates financial responsibility where a breach or non-compliance is caused by the Processor&#8217;s own failure to meet its obligations under the DPA, giving the Fiduciary a contractual remedy that sits alongside, rather than replaces, its own regulatory exposure under the Act.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>12. Governing law, jurisdiction, and cooperation with the Data Protection Board<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Specifies the governing law and jurisdiction for the agreement, and should explicitly require the Processor&#8217;s cooperation in the event the Data Protection Board of India initiates an inquiry relating to the processing covered by the DPA.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Penalty Exposure That Makes This Non-Negotiable<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The DPDP Act&#8217;s penalty framework underscores why a properly drafted DPA is not optional legal formality. Breach of a Significant Data Fiduciary&#8217;s obligations under Section 10 carries a maximum penalty of up to \u20b9150 crore. Organisations designated as Significant Data Fiduciaries face enhanced obligations that should be reflected in an enhanced DPA specifically, including provisions addressing DPO appointment, Data Protection Impact Assessments, and algorithmic audit rights, layered on top of the baseline 12 clauses that apply to every DPDP-compliant DPA regardless of Fiduciary size.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Key Compliance Deadlines to Track<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The DPDP Rules, 2025 introduced a phased implementation timeline that enterprises should be actively tracking against their DPA templates and existing vendor contracts. Within 12 months of the Rules&#8217; notification, by 13 November 2026, Rule 4&#8217;s Consent Manager registration and obligations become operational, meaning DPAs should include consent management integration clauses addressing how the Processor will interact with the Consent Manager framework once it takes effect. Enterprises finalising or renewing DPAs now should build this forward compatibility in directly, rather than treating it as a future amendment to be dealt with closer to the deadline.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Practical Steps for Enterprises<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Treat this as an ongoing exercise, not a one-time template update.<\/strong> New vendor contracts need to include DPDPA-compliant DPAs from the point of execution going forward. Existing vendor contracts, with technology vendors, marketing partners, HR platforms, MSME suppliers, and any other counterparty that processes personal data on the organisation&#8217;s behalf, need to be actively reviewed and updated, since the compliance gap in a legacy contract is just as real as in a newly signed one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Update standard contract templates centrally.<\/strong> Rather than negotiating DPA terms individually for every new vendor relationship, standard MSA and vendor agreement templates should be updated once to include DPDPA-compliant DPA provisions by default, reducing both negotiation friction and the risk of inconsistent terms across the vendor portfolio.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Build DPDPA compliance into the contract review playbook.<\/strong> Incoming vendor contracts and any agreement with data processing implications should be reviewed against a documented DPDPA playbook position covering the mandatory DPA elements described above, so that reviewers apply consistent standards rather than relying on ad hoc judgment for each new agreement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Evaluate vendor DPAs critically, not just accept what is offered.<\/strong> When a vendor proposes their own standard DPA, it should be assessed against the same 12-clause framework, with particular attention to data residency commitments and breach notification timelines, both common areas where a vendor&#8217;s default template falls short of what DPDPA compliance actually requires.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Managing DPA Compliance at Enterprise Scale<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For enterprises with a large and growing vendor ecosystem, cloud storage providers, marketing agencies, analytics platforms, HR systems, and technology partners among them, tracking which vendor relationships have a properly executed, DPDPA-compliant DPA in place, and which are still operating under legacy agreements that predate the Act, is a genuine portfolio management challenge, not a single review exercise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Legistify&#8217;s contract management platform supports this specifically, with a DPA clause library built around the 12 essential elements described above, automated flagging of vendor contracts that lack a compliant Data Processing Agreement or DPA schedule, and obligation tracking connected to the phased DPDP Rules implementation timeline, including the Consent Manager framework&#8217;s 13 November 2026 deadline, so legal teams can prioritise remediation across the vendor portfolio systematically rather than discovering gaps one vendor relationship at a time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under Section 8(2) of the DPDP Act, engaging a Data Processor without a valid, properly drafted contract is not a compliant option, and the 12 clauses described above, scope and purpose, security safeguards, breach notification, sub-processing restrictions, data residency, audit rights, and deletion obligations among them, represent the minimum viable content for a DPA that will actually hold up under scrutiny. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the Data Protection Board of India now established and the Consent Manager framework becoming operational in November 2026, enterprises that treat DPA compliance as a systematic, ongoing exercise across their entire vendor portfolio, rather than a one-time template update, will be far better positioned than those addressing it reactively, vendor by vendor, as gaps surface.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Frequently Asked Questions<\/strong><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1790746463053\" class=\"rank-math-list-item\">\n<h4 class=\"rank-math-question \"><strong>Is a Data Processing Agreement mandatory under the DPDP Act?<\/strong><\/h4>\n<div class=\"rank-math-answer \">\n\n<p>Yes. Section 8(2) of the Digital Personal Data Protection Act, 2023 provides that a Data Fiduciary may engage a Data Processor for covered activities only under a valid contract. While the Act does not require a standalone DPA document specifically, the substantive DPA requirements must be addressed either as a standalone agreement or as a schedule within a broader service agreement.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1790746504437\" class=\"rank-math-list-item\">\n<h4 class=\"rank-math-question \"><strong>What are the essential clauses a DPDP-compliant DPA must include?<\/strong><\/h4>\n<div class=\"rank-math-answer \">\n\n<p>The core elements include identity and roles of the parties, categories of personal data and data principals, purpose and duration of processing, security safeguards, data subject rights assistance, breach notification and incident response timelines, restrictions on sub-processing, data residency and cross-border transfer terms, audit rights, data return or deletion obligations on termination, indemnification for processor-caused breaches, and cooperation with the Data Protection Board.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1790746517537\" class=\"rank-math-list-item\">\n<h4 class=\"rank-math-question \"><strong>What is the breach notification timeline required under the DPDP Act?<\/strong><\/h4>\n<div class=\"rank-math-answer \">\n\n<p>A well-drafted DPA typically requires the Data Processor to notify the Data Fiduciary within 24 hours of becoming aware of a breach, allowing the Fiduciary to prepare and submit its own notification to the Data Protection Board within the Act&#8217;s 72-hour window. Unlike GDPR, the DPDP Act has no minimum severity threshold for breach reporting, meaning breach notification clauses need to be strict and comprehensive rather than limited to major incidents.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1790746530037\" class=\"rank-math-list-item\">\n<h4 class=\"rank-math-question \"><strong>Does the DPDP Act require data to be stored only within India?<\/strong><\/h4>\n<div class=\"rank-math-answer \">\n\n<p>The DPDP Act does not impose a blanket data localisation requirement, but Section 16 allows the Central Government to restrict processing outside India to specified countries or territories through notification. For sectors with specific data residency requirements, or as a risk-management choice, a DPA should explicitly commit the Processor to India-based processing and require the Fiduciary&#8217;s prior written consent for any specific cross-border transfer, rather than leaving data location to the Processor&#8217;s discretion.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1790746549187\" class=\"rank-math-list-item\">\n<h4 class=\"rank-math-question \"><strong>What happens if a vendor causes a data breach without a proper DPA in place?<\/strong><\/h4>\n<div class=\"rank-math-answer \">\n\n<p>Under Section 8(1) of the DPDP Act, the Data Fiduciary remains responsible for compliance in relation to processing carried out on its behalf, regardless of whether the breach was caused by its own systems or a vendor&#8217;s. Without a properly drafted DPA including indemnification and clear breach notification obligations, the Fiduciary has limited contractual recourse against the vendor while still facing full regulatory exposure, including penalties of up to \u20b9150 crore under Section 10 for Significant Data Fiduciaries, directly from the Data Protection Board.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A Data Processing Agreement is the only document that stops a vendor&#8217;s data-handling failure from becoming your organisation&#8217;s own legal liability under India&#8217;s Digital Personal Data Protection Act, 2023. Under Section 8(1) of the Act, the Data Fiduciary, the organisation determining the purpose and means of processing, remains continuously responsible for compliance in relation to processing carried out on its behalf, even when a third-party Data Processor is actually doing the processing. Section 8(2) goes further: a Data Fiduciary may engage a Data Processor for covered activities only under a valid contract. Without a proper DPA, the engagement itself is not compliant, regardless of how carefully the vendor otherwise handles the data. This guide covers what the DPDP Act and its 2025 Rules require in a Data Processing Agreement DPDP Act, the essential clauses every DPA needs, and the specific compliance deadlines enterprises should track. Where This Obligation Actually Comes From Section 8 of the Digital Personal Data Protection Act, 2023 contains the core provisions governing Data Fiduciaries and Data Processors. The distinction between the two roles matters considerably: the Act&#8217;s compliance obligations fall primarily on the Fiduciary, not the Processor, which is exactly why the Fiduciary needs a properly drafted DPA to ensure the Processor&#8217;s obligations are contractually locked in, rather than relying on the Processor&#8217;s own goodwill or general data-handling reputation. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, alongside the establishment of the Data Protection Board of India, providing the detailed operational requirements the Act itself left to subordinate rulemaking. Critically, the DPDP Act does not prescribe specific mandatory DPA clauses by name. Instead, the required content of a compliant DPA is derived by combining Section 8&#8217;s obligations, the DPDP Rules 2025 (particularly Rule 6 on security safeguards), and internationally established best practice for data processing contracts more broadly. One clarifying point worth noting: unlike the EU&#8217;s GDPR, which prescribes Standard Contractual Clauses for international data transfers, the DPDP Act leaves DPA drafting to the parties themselves, without a government-issued template clause set. This means the responsibility for getting the DPA&#8217;s substantive content right sits squarely with the drafting parties and their legal counsel, not with a government-supplied form that can simply be adopted wholesale. Does the DPA Need to Be a Standalone Document? No. The Act requires a &#8220;valid contract,&#8221; not necessarily a standalone Data Processing Agreement as a separate document. DPA-equivalent clauses can be incorporated directly into an existing service agreement or Master Service Agreement, provided the substantive requirements described below are genuinely addressed within that broader contract, rather than needing their own dedicated document in every case. Essential Clauses Every Data Processing Agreement DPDP Act Needs 1. Identity, roles, and scope of the parties Clearly establishes which party is the Data Fiduciary and which is the Data Processor (or Processors, where sub-processing is involved), and defines the scope and purpose of processing precisely, since the Processor&#8217;s use of personal information should be strictly limited to what the Fiduciary has actually authorised. 2. Categories of personal data and data principals Specifies precisely what categories of personal data are being processed and which categories of data principals (customers, employees, or other individuals) are involved, since this scoping directly determines the applicable security and compliance obligations that follow. 3. Purpose and duration of processing Defines exactly why the processing is happening and for how long, preventing the Processor&#8217;s use of the data from quietly expanding beyond the originally authorised purpose over the life of the relationship. 4. Security safeguards Establishes appropriate security obligations specifically, rather than relying on a generic confidentiality clause borrowed from an unrelated template. Rule 6 of the DPDP Rules, 2025 governs this area directly, and the DPA should reflect the specific technical and organisational security measures the Processor commits to maintaining. 5. Data subject rights assistance Requires the Processor to cooperate with and support the Fiduciary&#8217;s obligations to respond to data principal requests, such as access, correction, or erasure requests, since the Fiduciary remains ultimately responsible for fulfilling these rights even where the underlying data actually sits with the Processor. 6. Breach notification and incident response This is one of the most operationally critical clauses in any DPA. A well-drafted breach notification clause typically requires the Processor to notify the Fiduciary within 24 hours of becoming aware of a breach, giving the Fiduciary the remaining time within the Act&#8217;s 72-hour notification window to prepare and submit its own notification to the Data Protection Board. Unlike the EU&#8217;s GDPR, the DPDP Act sets no minimum severity threshold for breach reporting, meaning even comparatively minor breaches can trigger a notification obligation, which makes a tight, enforceable notification timeline in the DPA considerably more important than it might be under a threshold-based regime. The Processor&#8217;s incident response plan should also be provided to the Fiduciary, ideally reviewed and refreshed annually. 7. Restrictions on sub-processing Addresses whether and how the Processor can engage its own sub-processors, requiring the Fiduciary&#8217;s prior approval before any sub-processor is brought into the processing chain, and ensuring sub-processors are bound by data protection obligations that are at least as protective as those the primary Processor has accepted. 8. Data residency and cross-border transfer terms For sectors or organisations subject to data residency requirements, whether for regulatory reasons or simply as an internal risk-management decision, the DPA should specify explicitly that personal data is processed and stored within India, and that the Processor will not transfer, access, or permit access to that data from outside India without the Fiduciary&#8217;s prior written consent for a specific, defined transfer. Section 16 of the DPDP Act separately allows the Central Government to restrict processing outside India to specified countries or territories through notification, which the DPA should be drafted to accommodate as that list develops. A DPA that allows the Processor discretion over where data is backed up or processed, for redundancy or similar reasoning, without the Fiduciary&#8217;s specific, informed consent, is a significant red flag rather than a routine<\/p>\n","protected":false},"author":3,"featured_media":27295,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[64],"tags":[],"class_list":["post-27292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contract-management"],"uagb_featured_image_src":{"full":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act.jpg",1200,628,false],"thumbnail":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act-150x150.jpg",150,150,true],"medium":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act-300x157.jpg",300,157,true],"medium_large":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act-768x402.jpg",768,402,true],"large":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act-1024x536.jpg",1024,536,true],"1536x1536":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act.jpg",1200,628,false],"2048x2048":["https:\/\/legistify.com\/learn\/wp-content\/uploads\/2026\/09\/Data-Processing-Agreement-DPDP-Act.jpg",1200,628,false]},"uagb_author_info":{"display_name":"Mansi Rana","author_link":"https:\/\/legistify.com\/learn\/author\/mansi-rana\/"},"uagb_comment_info":0,"uagb_excerpt":"A Data Processing Agreement is the only document that stops a vendor&#8217;s data-handling failure from becoming your organisation&#8217;s own legal liability under India&#8217;s Digital Personal Data Protection Act, 2023. Under Section 8(1) of the Act, the Data Fiduciary, the organisation determining the purpose and means of processing, remains continuously responsible for compliance in relation to&hellip;","_links":{"self":[{"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/posts\/27292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/comments?post=27292"}],"version-history":[{"count":2,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/posts\/27292\/revisions"}],"predecessor-version":[{"id":27294,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/posts\/27292\/revisions\/27294"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/media\/27295"}],"wp:attachment":[{"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/media?parent=27292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/categories?post=27292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legistify.com\/learn\/wp-json\/wp\/v2\/tags?post=27292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}