top of page

Processors and vendors: why you stay responsible, and what goes in a DPA

6 days ago
5 min read

This explainer is also published on dpdpa.support. Every section, rule and date was checked against the official text on 4 Oct 2026.

If you use cloud hosting, payroll software, email delivery or a call centre, you hand personal data to vendors. Where a vendor processes personal data on your behalf, the Digital Personal Data Protection Act, 2023 treats it as your Data Processor, and you remain the Data Fiduciary. Two short provisions set the rules for that relationship. Section 8(1) keeps you responsible. Section 8(2) requires a valid contract for processors engaged for activities related to offering goods or services.

Who is who

A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data (Section 2(i)). A Data Processor is any person who processes personal data on behalf of a Data Fiduciary (Section 2(k)). The label follows the role, not the size of the company: a large cloud provider hosting your customer records is your Data Processor for that data.

Section 8(1): the responsibility stays with you

Section 8(1) makes a Data Fiduciary responsible for complying with the Act and the Rules for any processing “undertaken by it or on its behalf by a Data Processor”. It applies “irrespective of any agreement to the contrary”.

That phrase settles a common question. A clause saying the vendor is solely responsible for compliance does not move your legal duty to the vendor. The contract can give you remedies against the vendor, such as an indemnity, but your obligations to Data Principals and to the Board stay where Section 8(1) puts them.

Section 8(2): only under a valid contract

Section 8(2) lets a Data Fiduciary engage a Data Processor to process personal data on its behalf “only under a valid contract”. The sub-section covers processors engaged for any activity related to offering goods or services to Data Principals. For processing that may not relate to offering goods or services, such as payroll for your own staff, the case for a contract rests on your Section 8(1) responsibility and on Rule 6(1)(f), which calls for a security-safeguards provision in the processor contract “wherever applicable”.

The Act does not list the clauses a processor contract must contain. Several other provisions, though, only work if the contract supports them.

Duties that reach into the vendor’s work

  • Security safeguards. Your duty to take reasonable security safeguards covers processing done on your behalf by a Data Processor (Section 8(5); Rule 6(1)). Rule 6(1)(b) requires access controls over computer resources used by you or your processor, and Rule 6(1)(f) requires an appropriate provision in the contract for reasonable security safeguards.

  • Withdrawal of consent. When a person withdraws consent, you must within a reasonable time cease, and cause your Data Processors to cease, processing her data, unless law requires or authorises it (Section 6(6)).

  • Erasure. You must cause your Data Processor to erase any personal data you made available to it, when erasure is due (Section 8(7)(b)).

  • Log retention. Rule 8(3) requires personal data, traffic data and logs of processing done by you or on your behalf by a processor to be kept for at least one year. The Rule’s own illustration is a company using a cloud provider to host customer records: the company must ensure the provider also keeps the data and logs for at least one year before erasure, unless another law requires longer.

  • Breach notice. You must notify the Board and affected people (Section 8(6); Rule 7). Your 72-hour period for the detailed Board report runs from when you become aware, so the vendor has to tell you quickly (see Rule 7 in detail).

  • Access requests. A Data Principal can ask you for the identities of all Data Processors you have shared her data with, with a description of what was shared (Section 11(1)(b)). You need a current list.

  • Transfers abroad. If the vendor processes data outside India, Section 16 and Rule 15 apply to that transfer; see sending personal data outside India.

What goes in a Data Processing Agreement

Only Rule 6(1)(f) prescribes contract content outright: a provision for reasonable security safeguards. The rest of the table is drafting practice that helps you meet duties the Act places on you. Describe it to the vendor that way.

  • Scope: whose data, which data, the purpose, the processing, where it runs, how long. Why: Defines the processing the contract covers; Basis: Section 8(2) valid contract, where it applies; drafting practice

  • Act only on your documented instructions. Why: Keeps the vendor processing “on behalf of” you; Basis: Section 2(k); drafting practice

  • Security measures mapped to Rule 6(1)(a) to (g). Why: Contract provision for safeguards; Basis: Rule 6(1)(f)

  • Keep logs and data for at least one year. Why: Your retention duty covers processor work; Basis: Rule 8(3) and Rule 6(1)(e) duties fall on you; the clause is drafting practice

  • Tell you of any breach within a set number of hours. Why: Lets you meet Rule 7; Basis: The number is your choice; the Rules do not fix one

  • Stop processing and erase or return data on instruction, with certification. Why: Withdrawal and erasure duties; Basis: Section 6(6); Section 8(7)(b); return and certification are drafting practice

  • Help answer access, correction, erasure and grievance requests. Why: Your Chapter III duties depend on its data; Basis: Sections 11 to 13; drafting practice

  • No sub-processor without your written consent. Why: Keeps your list of processors complete; Basis: Section 11(1)(b); drafting practice

  • Audit and information rights. Why: Evidence that measures are in place; Basis: Section 8(4); drafting practice

  • Limits on transfers outside India. Why: Notified restrictions and orders; Basis: Section 16; Rule 15; the clause is drafting practice

Figures such as a 24-hour breach notice to you, a sub-processor notice period or an indemnity cap are negotiating positions. Choose them on risk and record them as your choice.

Screen before you sign

A contract records promises. It does not show whether the vendor can keep them. Before signing, check the vendor against the same Rule 6 items: encryption or masking, access control, logging and monitoring, backups, one-year retention of logs, and how quickly it can tell you about an incident. Tier vendors by the data they hold, and review high-risk ones more often.

Existing contracts count too

Sections 6 (other than 6(9)), 8, 11 and 16, and Rules 6, 7, 8 and 15, apply from 13 May 2027 (clause (c) of G.S.R. 843(E); Rule 1(4)). Existing vendor contracts signed before then will need review against these provisions, not just new ones.

Sources

Every section, rule and date above was checked against the official text on 4 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

  • Section 2(i): Data Fiduciary

  • Section 2(k): Data Processor

  • Section 6(6): Cease, and cause processors to cease, on withdrawal

  • Section 8(1): Responsible "irrespective of any agreement to the contrary"

  • Section 8(2): Processor engaged for activities related to offering goods or services: only under a valid contract

  • Section 8(4): Technical and organisational measures

  • Section 8(5): Security safeguards, including processing by a processor

  • Section 8(6): Breach intimation

  • Section 8(7)(b): Cause the processor to erase

  • Sections 11 to 13: Access (including Section 11(1)(b), the identities of processors), correction and erasure, and grievance redressal

  • Section 16: Transfers outside India

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4): Rules 6, 7, 8 and 15 in force eighteen months from publication

  • Rule 6(1): Safeguards (a) to (g), including (b) access control, (e) log retention and (f) contract provision

  • Rule 7: Breach intimation, including the 72-hour detailed report

  • Rule 8(3): One-year retention, including the cloud-provider illustration

  • Rule 15: Transfers: requirements about foreign States

Notifications

  • G.S.R. 843(E), clause (c): Sections 6 (except 6(9)), 8, 11 and 16 in force eighteen months from 13 November 2025

Screen the vendor, then sign the contract

How-to 09 scores each vendor on a 38-question questionnaire with critical flags. How-to 09b is a Data Processing Agreement, clause by clause, with a schedule for the vendor's measure against each Rule 6 item.

The how-to walkthroughs and the editable Word and Excel files are in the DPDPA Compliance Toolkit program on this site. The version of this article that we keep up to date is on dpdpa.support.

Drafting aid, not legal advice.

header.all-comments

ratings-display.rating-aria-label
header.no-ratings-yet

comment-box.add-a-rating

Cyber Security Services

           CynorSense Solution Pvt. Ltd. is your dedicated partner in the ever-evolving domain of cybersecurity. We are committed to delivering cutting-edge cybersecurity solutions, tailored to meet the unique needs of each client. Our comprehensive suite of services includes DPDPA, Penetration Testing, SOC & SIEM Services, Incident Response, and Cyber Security Consultation.

​

Our expertise extends across Secure Code Review, Vulnerability Assessment and Penetration Testing (VAPT) Services, Security Audits, Risk and Threat Assessment, and Vulnerability Scanning. In addition, we offer services in Malware Analysis, Phishing Simulation, Social Engineering Testing, Web Application Testing, Mobile Application Testing, Network Security Testing, Infrastructure Security Testing, Application Security Testing, and Data Security Testing. 

​

We understand the importance of compliance in today's regulatory environment. Our Compliance Testing services are designed to help your organization navigate the complex landscape of regulations such as DPDPA, ISO 27001, PCI DSS, HIPAA, SOX, GLBA, NERC CIP, FISMA, and the NIST Cybersecurity Framework. 

​

At CynorSense, we blend innovative technology with a robust understanding of the cybersecurity landscape to provide you with the tools and knowledge needed to safeguard your digital assets. Let us be your trusted guide in the realm of cybersecurity, providing the assurance you need in an increasingly interconnected world.

ISO 27001 and ISO 9001 certified company

TELEPHONE:

 +91 80 62 181 669

 ADDRESS: 

 Cynor Sense Solutions Pvt. Ltd.

 Vijay Krishna Towers,   Nanakramguda, Hyderabad,

 Telangana, India - 500032

© 2026 CynorSense Solutions Pvt. Ltd. All rights reserved.

bottom of page