Vendors Applies from 13 May 2027

DPDP processors: what goes in a DPA, and why you stay responsible

Two colleagues in an office, one showing a tablet screen to the other.

You stay responsible for personal data your vendors handle for you, whatever the contract says. The DPDP Act lets you use a processor for offering goods or services only under a valid contract, and your security safeguards must include an appropriate contract provision with the processor, wherever applicable, for reasonable security safeguards. These duties start on 13 May 2027.

Last checked against the official text: Updated 6 min read

On this page
  1. Who is who
  2. Section 8(1): the responsibility stays with you
  3. Section 8(2): only under a valid contract
  4. Duties that reach into the vendor’s work
  5. What goes in a Data Processing Agreement
  6. Screen before you sign
  7. Existing contracts count too
  8. Common questions
  9. In the news
  10. Sources

If you use cloud hosting, payroll software, email delivery or a call centre, you hand personal data to vendors. Where a vendor processes personal data on your behalf, the Digital Personal Data Protection Act, 2023 treats it as your Data Processor, and you remain the Data Fiduciary. Two short provisions set the rules for that relationship. Section 8(1) keeps you responsible. Section 8(2) requires a valid contract for processors engaged for activities related to offering goods or services.

Who is who

A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data (Section 2(i)). A Data Processor is any person who processes personal data on behalf of a Data Fiduciary (Section 2(k)). The label follows the role, not the size of the company: a large cloud provider hosting your customer records is your Data Processor for that data.

Section 8(1): the responsibility stays with you

Section 8(1) makes a Data Fiduciary responsible for complying with the Act and the Rules for any processing “undertaken by it or on its behalf by a Data Processor”. It applies “irrespective of any agreement to the contrary”.

That phrase settles a common question. A clause saying the vendor is solely responsible for compliance does not move your legal duty to the vendor. The contract can give you remedies against the vendor, such as an indemnity, but your obligations to Data Principals and to the Board stay where Section 8(1) puts them.

Section 8(2): only under a valid contract

Section 8(2) lets a Data Fiduciary engage a Data Processor to process personal data on its behalf “only under a valid contract”. The sub-section covers processors engaged for any activity related to offering goods or services to Data Principals. For processing that may not relate to offering goods or services, such as payroll for your own staff, the case for a contract rests on your Section 8(1) responsibility and on Rule 6(1)(f), which calls for a security-safeguards provision in the processor contract “wherever applicable”.

A man in a hoodie working on a laptop in an office, a colleague at a computer behind him.

The Act does not list the clauses a processor contract must contain. Several other provisions, though, only work if the contract supports them.

Duties that reach into the vendor’s work

  • Security safeguards. Your duty to take reasonable security safeguards covers processing done on your behalf by a Data Processor (Section 8(5); Rule 6(1)). Rule 6(1)(b) requires access controls over computer resources used by you or your processor, and Rule 6(1)(f) requires an appropriate provision in the contract for reasonable security safeguards.
  • Withdrawal of consent. When a person withdraws consent, you must within a reasonable time cease, and cause your Data Processors to cease, processing her data, unless law requires or authorises it (Section 6(6)).
  • Erasure. You must cause your Data Processor to erase any personal data you made available to it, when erasure is due (Section 8(7)(b)).
  • Log retention. Rule 8(3) requires personal data, traffic data and logs of processing done by you or on your behalf by a processor to be kept for at least one year. The Rule’s own illustration is a company using a cloud provider to host customer records: the company must ensure the provider also keeps the data and logs for at least one year before erasure, unless another law requires longer.
  • Breach notice. You must notify the Board and affected people (Section 8(6); Rule 7). Your 72-hour period for the detailed Board report runs from when you become aware, so the vendor has to tell you quickly (see Rule 7 in detail).
  • Access requests. A Data Principal can ask you for the identities of all Data Processors you have shared her data with, with a description of what was shared (Section 11(1)(b)). You need a current list.
  • Transfers abroad. If the vendor processes data outside India, Section 16 and Rule 15 apply to that transfer; see sending personal data outside India.

What goes in a Data Processing Agreement

Only Rule 6(1)(f) prescribes contract content outright: a provision for reasonable security safeguards. The rest of the table is drafting practice that helps you meet duties the Act places on you. Describe it to the vendor that way.

ClauseWhyBasis
Scope: whose data, which data, the purpose, the processing, where it runs, how longDefines the processing the contract coversSection 8(2) valid contract, where it applies; drafting practice
Act only on your documented instructionsKeeps the vendor processing “on behalf of” youSection 2(k); drafting practice
Security measures mapped to Rule 6(1)(a) to (g)Contract provision for safeguardsRule 6(1)(f)
Keep logs and data for at least one yearYour retention duty covers processor workRule 8(3) and Rule 6(1)(e) duties fall on you; the clause is drafting practice
Tell you of any breach within a set number of hoursLets you meet Rule 7The number is your choice; the Rules do not fix one
Stop processing and erase or return data on instruction, with certificationWithdrawal and erasure dutiesSection 6(6); Section 8(7)(b); return and certification are drafting practice
Help answer access, correction, erasure and grievance requestsYour Chapter III duties depend on its dataSections 11 to 13; drafting practice
No sub-processor without your written consentKeeps your list of processors completeSection 11(1)(b); drafting practice
Audit and information rightsEvidence that measures are in placeSection 8(4); drafting practice
Limits on transfers outside IndiaNotified restrictions and ordersSection 16; Rule 15; the clause is drafting practice

Figures such as a 24-hour breach notice to you, a sub-processor notice period or an indemnity cap are negotiating positions. Choose them on risk and record them as your choice.

Screen before you sign

A contract records promises. It does not show whether the vendor can keep them. Before signing, check the vendor against the same Rule 6 items: encryption or masking, access control, logging and monitoring, backups, one-year retention of logs, and how quickly it can tell you about an incident. Tier vendors by the data they hold, and review high-risk ones more often.

Existing contracts count too

Sections 6 (other than 6(9)), 8, 11 and 16, and Rules 6, 7, 8 and 15, apply from 13 May 2027 (clause (c) of G.S.R. 843(E); Rule 1(4)). Existing vendor contracts signed before then will need review against these provisions, not just new ones.

Labs, pharmacies and billing vendors raise the same questions for a clinic. See the DPDP Act for clinics and hospitals.

Common questions

Am I responsible for what my vendor does with personal data?

Yes. The Act makes the Data Fiduciary responsible for complying with the Act for processing it does, or that a Data Processor does on its behalf, “irrespective of any agreement to the contrary”.

Do I need a contract with a processor?

For any activity related to offering goods or services to people, the Act allows you to engage a processor only under a valid contract. The security safeguards you must take include an appropriate contract provision with the processor, wherever applicable.

What happens to my vendor’s copy when a person withdraws consent or the purpose ends?

When a person withdraws consent, you must cease processing, and cause your processors to cease, unless a law requires or authorises the processing. When erasure is due, you must cause the processor to erase the data you made available to it.

How long must a vendor keep logs?

At least one year from the processing, for the purposes the Rules list in the Seventh Schedule, then erased unless another law requires longer. The Rules’ own example is a company that hosts customer records with a cloud provider: the company must ensure the provider also keeps the data and logs for at least one year, unless another law needs longer.

Do the Rules set how fast a vendor must tell me about a breach?

No. The Rules set your own clock, which runs from when you become aware of the breach. Agree the vendor’s notice time in the contract so that you can meet it.

Next steps

In the news

Sources

Every section, rule and date above was checked against the official text on 5 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)

  • Section 2(i)Data Fiduciary
  • Section 2(k)Data Processor
  • Section 6(6)Cease, and cause processors to cease, on withdrawal
  • Section 8(1)Responsible "irrespective of any agreement to the contrary"
  • Section 8(2)Processor engaged for activities related to offering goods or services: only under a valid contract
  • Section 8(4)Technical and organisational measures
  • Section 8(5)Security safeguards, including processing by a processor
  • Section 8(6)Breach intimation
  • Section 8(7)(b)Cause the processor to erase
  • Sections 11 to 13Access (including Section 11(1)(b), the identities of processors), correction and erasure, and grievance redressal
  • Section 16Transfers outside India

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4)Rules 6, 7, 8 and 15 in force eighteen months from publication
  • Rule 6(1)Safeguards (a) to (g), including (b) access control, (e) log retention and (f) contract provision
  • Rule 7Breach intimation, including the 72-hour detailed report
  • Rule 8(3)One-year retention, including the cloud-provider illustration
  • Rule 15Transfers: requirements about foreign States

Notifications

Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)

  • G.S.R. 843(E), clause (c)Sections 6 (except 6(9)), 8, 11 and 16 in force eighteen months from 13 November 2025

A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.