Data Processing Agreements Under the DPDP Act: Fixing Vendor Contracts Before May 2027
Under Section 8 of the DPDP Act, your business stays responsible for what your vendors do with personal data. Here is what a DPDP data processing agreement should cover, and a four-week plan to get your vendor contracts in order.
Pick any Indian startup with thirty people and count the outside companies that touch its customer data: the cloud host, payment gateway, CRM, WhatsApp messaging provider, payroll firm, KYC vendor and the agency running ads off an uploaded customer list. Ten vendors is normal. Twenty is common.
Now ask how many of those relationships sit on a contract that says anything specific about personal data. For most SMEs we speak to, it's two or three. That gap matters because the Digital Personal Data Protection Act, 2023 puts the legal weight on you, and a data processing agreement under the DPDP Act is the main tool you have to control what vendors do with data you are answerable for.
What the DPDP Act says about vendors
The Act calls your business the Data Fiduciary and calls a vendor handling data on your instructions a Data Processor. Three provisions in Section 8 do most of the work.
Section 8(1) makes you responsible for complying with the Act for any processing done "by it or on its behalf by a Data Processor", and it applies "irrespective of any agreement to the contrary". You cannot contract your way out. An indemnity may help you recover money from a vendor, but it does not move regulatory responsibility off your books.
Section 8(2) says you may involve a Data Processor to process personal data on your behalf "only under a valid contract". The Act doesn't prescribe clauses, but it does make the written contract a precondition.
Section 8(5) requires reasonable security safeguards for personal data in your possession or control, including processing done on your behalf by a processor. Section 8(7) then requires you to erase data once consent is withdrawn or the purpose is served, and to cause your Data Processor to erase whatever you gave it.
The DPDP Rules, 2025 add one explicit contract term. Rule 6(1)(f) lists, among the minimum security measures, an appropriate provision in your contract with each Data Processor for taking reasonable security safeguards.
Why the timing matters now
The Rules were notified on 13 November 2025 and come into force in phases. The Consent Manager framework opens around 13 November 2026. The substantive obligations, including notice, consent, security safeguards under Rule 6, breach intimation under Rule 7 and data principal rights, take effect on 13 May 2027.
That sounds far away, but most SaaS agreements renew annually. If a key contract renews in December 2026 without DPDP terms, you may not get another natural chance to fix it before May 2027.
There is also news pressure. In January 2026, MeitY discussed with industry a proposal to shorten parts of the timeline, particularly for Significant Data Fiduciaries, according to a summary by law firm S.S. Rana & Co. As of early September 2026, trackers had not located a notified amendment. Plan for May 2027, but don't build a schedule that only works if nothing changes.
The penalty ceiling is the other reason. Failing to take reasonable security safeguards to prevent a personal data breach can attract up to ₹250 crore per instance under the Act's Schedule, and failing to notify the Board and affected people of a breach can cost up to ₹200 crore. Either can follow an incident that started at a vendor.
What a DPDP data processing agreement should cover
Because the Act only asks for a "valid contract", there's no official template. A workable DPDP vendor contract for an Indian SME usually covers these points:
- Scope and instructions. The categories of personal data, the purposes, and a clear statement that the vendor processes only on your documented instructions and won't use the data for its own purposes, including training its own models.
- Security safeguards. Specific commitments that line up with Rule 6: encryption or masking where appropriate, access controls, logging and monitoring. "Industry standard security" on its own is too vague to evidence anything.
- Log retention. Rule 6 expects logs and personal data to be kept for one year for detecting and investigating unauthorised access, unless another law requires otherwise. Your vendor holds many of those logs, so the contract should require it to keep them and hand them over.
- Breach notice to you. Under Rule 7, you must inform affected people and the Board without delay and send the Board a fuller report within 72 hours of becoming aware. Your vendor's delay eats into your 72 hours, which is why many Indian contracts now ask for notice within 24 to 48 hours, plus cooperation on investigation.
- Sub-processors. No new sub-processor without your prior approval, and the same obligations passed down the chain.
- Help with rights requests. When a customer asks to access, correct or erase data, the vendor must act on your instruction within a set time.
- Erasure and return. On contract end or on your instruction, delete or return the data and confirm in writing, so you can meet Section 8(7).
- Location and transfers. Where data is stored, and a commitment to follow any country restrictions the government notifies under Section 16.
- Audit rights. The right to ask for evidence, certifications or an independent assessment.
A four-week plan to get it done
Week 1: build the vendor inventory. Pull from your accounts payable ledger, cloud console and app SDK list. For each vendor, note what personal data it touches, whose data it is (customers, employees, candidates) and where it is stored.
Week 2: rank by risk. Put vendors holding large volumes, financial data, health data or children's data at the top. Flag anything with a renewal date before May 2027.
Week 3: gap-check the top ten. Read what you've actually signed. Note the gaps against the list above.
Week 4: send your addendum. Prepare a short DPDP addendum and send it to the priority vendors, starting with those renewing soonest. Record who signed and when; dated evidence helps if the Board ever asks.
A privacy impact assessment data map makes Week 1 much faster.
Where GDPR paperwork helps and where it falls short
If you serve European clients, your GDPR Article 28 agreements already carry over most of these clauses. The differences are in the detail: the DPDP Act holds the Fiduciary responsible regardless of contract terms, the Indian breach report has its own content and 72-hour timing, and Rule 6 sets the one-year log expectation. A short Indian rider is often enough. Our GDPR compliance consulting team can help you map one onto the other.
The goal for now is knowing which vendors hold your customers' data and having written terms with the ones that matter most before the 2027 deadline.
This article is general guidance, not legal advice. Please take advice on your specific contracts and circumstances.
Want to see where your vendor contracts stand? Start with our free DPDP compliance checklist, or talk to us about a vendor contract review.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation