Processors and vendors: why you stay responsible, and what goes in a DPA
This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.
If you use cloud hosting, payroll software, email delivery or a call centre, you hand personal data to vendors. Where a vendor processes personal data on your behalf, the Digital Personal Data Protection Act, 2023 treats it as your Data Processor, and you remain the Data Fiduciary. Two short provisions set the rules for that relationship. Section 8(1) keeps you responsible. Section 8(2) requires a valid contract for processors engaged for activities related to offering goods or services.
Who is who
A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data (Section 2(i)). A Data Processor is any person who processes personal data on behalf of a Data Fiduciary (Section 2(k)). The label follows the role, not the size of the company: a large cloud provider hosting your customer records is your Data Processor for that data.
Section 8(1): the responsibility stays with you
Section 8(1) makes a Data Fiduciary responsible for complying with the Act and the Rules for any processing “undertaken by it or on its behalf by a Data Processor”. It applies “irrespective of any agreement to the contrary”.
That phrase settles a common question. A clause saying the vendor is solely responsible for compliance does not move your legal duty to the vendor. The contract can give you remedies against the vendor, such as an indemnity, but your obligations to Data Principals and to the Board stay where Section 8(1) puts them.
Section 8(2): only under a valid contract
Section 8(2) lets a Data Fiduciary engage a Data Processor to process personal data on its behalf “only under a valid contract”. The sub-section covers processors engaged for any activity related to offering goods or services to Data Principals. For processing that may not relate to offering goods or services, such as payroll for your own staff, the case for a contract rests on your Section 8(1) responsibility and on Rule 6(1)(f), which calls for a security-safeguards provision in the processor contract “wherever applicable”.
The Act does not list the clauses a processor contract must contain. Several other provisions, though, only work if the contract supports them.
Duties that reach into the vendor’s work
Security safeguards. Your duty to take reasonable security safeguards covers processing done on your behalf by a Data Processor (Section 8(5); Rule 6(1)). Rule 6(1)(b) requires access controls over computer resources used by you or your processor, and Rule 6(1)(f) requires an appropriate provision in the contract for reasonable security safeguards.
Withdrawal of consent. When a person withdraws consent, you must within a reasonable time cease, and cause your Data Processors to cease, processing her data, unless law requires or authorises it (Section 6(6)).
Erasure. You must cause your Data Processor to erase any personal data you made available to it, when erasure is due (Section 8(7)(b)).
Log retention. Rule 8(3) requires personal data, traffic data and logs of processing done by you or on your behalf by a processor to be kept for at least one year. The Rule’s own illustration is a company using a cloud provider to host customer records: the company must ensure the provider also keeps the data and logs for at least one year before erasure, unless another law requires longer.
Breach notice. You must notify the Board and affected people (Section 8(6); Rule 7). Your 72-hour period for the detailed Board report runs from when you become aware, so the vendor has to tell you quickly (see Rule 7 in detail).
Access requests. A Data Principal can ask you for the identities of all Data Processors you have shared her data with, with a description of what was shared (Section 11(1)(b)). You need a current list.
Transfers abroad. If the vendor processes data outside India, Section 16 and Rule 15 apply to that transfer; see sending personal data outside India.
What goes in a Data Processing Agreement
Only Rule 6(1)(f) prescribes contract content outright: a provision for reasonable security safeguards. The rest of the table is drafting practice that helps you meet duties the Act places on you. Describe it to the vendor that way.
Scope: whose data, which data, the purpose, the processing, where it runs, how long. Why: Defines the processing the contract covers; Basis: Section 8(2) valid contract, where it applies; drafting practice
Act only on your documented instructions. Why: Keeps the vendor processing “on behalf of” you; Basis: Section 2(k); drafting practice
Security measures mapped to Rule 6(1)(a) to (g). Why: Contract provision for safeguards; Basis: Rule 6(1)(f)
Keep logs and data for at least one year. Why: Your retention duty covers processor work; Basis: Rule 8(3) and Rule 6(1)(e) duties fall on you; the clause is drafting practice
Tell you of any breach within a set number of hours. Why: Lets you meet Rule 7; Basis: The number is your choice; the Rules do not fix one
Stop processing and erase or return data on instruction, with certification. Why: Withdrawal and erasure duties; Basis: Section 6(6); Section 8(7)(b); return and certification are drafting practice
Help answer access, correction, erasure and grievance requests. Why: Your Chapter III duties depend on its data; Basis: Sections 11 to 13; drafting practice
No sub-processor without your written consent. Why: Keeps your list of processors complete; Basis: Section 11(1)(b); drafting practice
Audit and information rights. Why: Evidence that measures are in place; Basis: Section 8(4); drafting practice
Limits on transfers outside India. Why: Notified restrictions and orders; Basis: Section 16; Rule 15; the clause is drafting practice
Figures such as a 24-hour breach notice to you, a sub-processor notice period or an indemnity cap are negotiating positions. Choose them on risk and record them as your choice.
Screen before you sign
A contract records promises. It does not show whether the vendor can keep them. Before signing, check the vendor against the same Rule 6 items: encryption or masking, access control, logging and monitoring, backups, one-year retention of logs, and how quickly it can tell you about an incident. Tier vendors by the data they hold, and review high-risk ones more often.
Existing contracts count too
Sections 6 (other than 6(9)), 8, 11 and 16, and Rules 6, 7, 8 and 15, apply from 13 May 2027 (clause (c) of G.S.R. 843(E); Rule 1(4)). Existing vendor contracts signed before then will need review against these provisions, not just new ones.
Sources
Every section, rule and date above was checked against the official text on 4 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Section 2(i): Data Fiduciary
Section 2(k): Data Processor
Section 6(6): Cease, and cause processors to cease, on withdrawal
Section 8(1): Responsible "irrespective of any agreement to the contrary"
Section 8(2): Processor engaged for activities related to offering goods or services: only under a valid contract
Section 8(4): Technical and organisational measures
Section 8(5): Security safeguards, including processing by a processor
Section 8(6): Breach intimation
Section 8(7)(b): Cause the processor to erase
Sections 11 to 13: Access (including Section 11(1)(b), the identities of processors), correction and erasure, and grievance redressal
Section 16: Transfers outside India
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
Rule 1(4): Rules 6, 7, 8 and 15 in force eighteen months from publication
Rule 6(1): Safeguards (a) to (g), including (b) access control, (e) log retention and (f) contract provision
Rule 7: Breach intimation, including the 72-hour detailed report
Rule 8(3): One-year retention, including the cloud-provider illustration
Rule 15: Transfers: requirements about foreign States
Notifications
G.S.R. 843(E), clause (c): Sections 6 (except 6(9)), 8, 11 and 16 in force eighteen months from 13 November 2025
Screen the vendor, then sign the contract
How-to 09 scores each vendor on a 38-question questionnaire with critical flags. How-to 09b is a Data Processing Agreement, clause by clause, with a schedule for the vendor's measure against each Rule 6 item.
The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.
Drafting aid, not legal advice.




header.all-comments