Vendors

Zoho, Tally, Google Workspace, WhatsApp Business: a Data Processor?

A man at a dairy shop among milk cans looking at his phone.

Where a software supplier stores or handles customer data for you, the DPDP Act treats it as your Data Processor, and you stay responsible for that data whatever its terms say. You may engage one for offering goods or services only under a valid contract. These duties start on 13 May 2027.

Last checked against the official text: Updated 5 min read

On this page
  1. When a software supplier is your Data Processor
  2. What the law makes you answer for
  3. Our view: map where the data sits
  4. Our view: what to do
  5. Common questions
  6. In the news
  7. Sources

Customer names, phone numbers and invoices rarely sit in one place. They can sit in several places, for example an accounting package such as Tally, a customer tool such as Zoho, email and files in Google Workspace, and chats in WhatsApp Business. This page applies what the DPDP Act and Rules say about suppliers that handle personal data for you. It names these tools only as examples of where data sits. The Act and Rules name no software product, and this page makes no claim about any of those products or the companies behind them. The sections on the law are cited in the Sources box. The sections marked Our view are our opinion and carry no citation.

When a software supplier is your Data Processor

A Data Fiduciary is any person who, alone or with others, decides why and how personal data is processed. A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. Processing covers collecting, recording, storing, using, sharing, disclosing and erasing digital personal data. If you decide why customer data is held and a supplier stores or handles it for you, you are the Data Fiduciary and, on the wording, the supplier is your Data Processor. The definition looks at what the supplier does with the data. Read the three roles in plain words if the terms are new.

What the law makes you answer for

A man at a dairy shop handing over a milk packet, a phone in his other hand.
What the law saysWhat it means for your tools
You are responsible for complying with the Act and Rules for processing done by you or on your behalf by a Data Processor, whatever any agreement says.A line in a supplier’s terms that makes the supplier responsible does not remove your duty.
You may engage a Data Processor for any activity related to offering goods or services to people only under a valid contract.You need to know what contract sits behind each tool that handles customer data.
Reasonable security safeguards cover processing done on your behalf. The Rules’ minimum list includes access controls over the computer resources you or your processor use, wherever applicable, and an appropriate provision in your contract with the processor for taking those safeguards, wherever applicable.The duty stays with you; the contract is where the supplier’s part is written down.
When a person withdraws consent, you must within a reasonable time stop processing and cause your Data Processors to stop, unless the Act, the Rules or another law requires or authorises the processing.Withdrawal reaches every tool that holds her data.
You must erase personal data when consent is withdrawn or the purpose is no longer served, and cause your Data Processor to erase any data you made available to it, unless retention is necessary to comply with a law.Deleting a customer in one tool is not enough if copies sit in another.
The Rules require personal data, traffic data and logs of the processing, including processing done on your behalf by a processor, to be kept for at least one year, for the purposes the Rules list. The Rules’ own example is a company that uses a cloud provider to host customer records: it must make sure the provider also keeps the data and logs for at least one year before erasure, unless another law requires longer.Ask each supplier how long it keeps logs and what it erases when you tell it to.
A person who gave you consent can ask for the identities of all Data Fiduciaries and Data Processors with whom you shared her data, with a description of what was shared.Keep a current list of the suppliers that touch customer data.
After a personal data breach you must tell the Board and each affected person. The detailed report to the Board is due within 72 hours of becoming aware of the breach, or a longer period the Board allows.The 72 hours run from when you become aware, so you need to hear quickly if a supplier has a problem. See the breach duties.

These duties start on 13 May 2027. The detail of what goes into the contract is in processors and vendors: what goes in a data processing agreement.

Our view: map where the data sits

Our view. The table lists kinds of places where small businesses keep personal data, with an example tool for each, and the questions we would ask. The examples show where data can be. They make no statement about any product.

Where the data sitsExamplePersonal data you would expect
Accounts and invoicesTallyCustomer and supplier names, addresses, phone numbers, bill details
Customers and sales follow-upZohoNames, phone numbers, email addresses, notes on enquiries
Email, documents and spreadsheetsGoogle WorkspaceEverything customers send you, plus any list you keep in a sheet
Customer messagingWhatsApp BusinessPhone numbers, chat history, photos and documents customers send

Our view. Reading the definition word for word, a supplier is a Data Processor when it processes data on your behalf. Software that runs only on your own computer, whose supplier never receives the data, may not fit that description. Ask each supplier which case applies to the product you use.

Our view: what to do

Our view. This is the order we would work in.

  1. List every tool where customer, lead or staff data sits, including free ones and ones one person set up alone.
  2. For each, write down who runs it, what personal data it holds and which terms or contract you accepted. Keep a copy of the terms.
  3. Check what those terms say about security safeguards and about what the supplier does when you tell it to delete data.
  4. Find out whether the supplier processes data outside India. If it does, read sending personal data outside India.
  5. Decide how you will hear about a problem at the supplier, and who in your business acts on it.
  6. Set deletion dates for each kind of data and include the copies held by suppliers. How long you can keep customer data.

The same list helps with answering customers. A person who asks where her data went can be told which suppliers hold it, and a request to delete reaches every copy. A delete request when you must keep invoices covers the case where the law says to keep part of a record.

Common questions

Is my accounting or customer software a Data Processor under the DPDP Act?

A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. If a supplier stores or handles your customers’ personal data for you, it fits that wording. The Act and Rules name no software product, so the answer depends on what the supplier does with the data.

Am I still responsible if the supplier handles the data?

Yes. You are responsible for complying with the Act and Rules for any processing done by you or on your behalf by a Data Processor, whatever any agreement says.

Do I need a contract with each software supplier?

You may engage a Data Processor for any activity related to offering goods or services to people only under a valid contract. The Rules also ask for an appropriate provision in your contract with the processor for taking reasonable security safeguards, wherever applicable.

What happens to data held by a supplier when a customer withdraws consent?

You must stop processing within a reasonable time and cause your Data Processors to stop, unless the Act, the Rules or another law requires or authorises the processing. You must also cause the processor to erase data you made available to it, unless retention is necessary to comply with a law.

Can a customer ask which suppliers hold her data?

Yes. A person who gave you consent can ask for the identities of all Data Fiduciaries and Data Processors with whom you shared her data, and a description of what was shared.

Next steps

In the news

Sources

Every section, rule and date above was checked against the official text on 6 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)

  • Section 2(i)Data Fiduciary: decides the purpose and means of processing
  • Section 2(k)Data Processor: processes personal data on behalf of a Data Fiduciary
  • Section 2(x)Processing: collection, storage, use, sharing, disclosure, erasure and other operations on digital personal data
  • Section 6(6)On withdrawal of consent, cease and cause Data Processors to cease; telecom illustration
  • Section 8(1)Responsible for processing by the Data Fiduciary or on its behalf by a Data Processor, irrespective of any agreement
  • Section 8(2)Data Processor for offering goods or services only under a valid contract
  • Section 8(5)Reasonable security safeguards, including for processing by a Data Processor
  • Section 8(6)Intimation of a personal data breach to the Board and each affected person
  • Section 8(7)Erase when consent is withdrawn or the purpose is served, unless a law requires retention; cause the Data Processor to erase
  • Section 11(1)Right to the identities of Data Fiduciaries and Data Processors the data was shared with

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4)Rules 3, 5 to 16 in force eighteen months from publication
  • Rule 6(1)Minimum safeguards: access control over computer resources of the Data Fiduciary or Data Processor; contract provision with the Data Processor
  • Rule 7(2)Detailed breach report to the Board within seventy-two hours of becoming aware
  • Rule 8(3)One-year minimum for personal data, traffic data and logs, including processing on behalf of the Data Fiduciary; cloud provider illustration

Notifications

Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)

  • G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17 in force eighteen months from 13 November 2025

A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.