Data Processing Agreements

A data processing agreement (DPA) is the contract between a business that decides how personal data is used and a vendor that handles the data for it. It limits the vendor to the business’s instructions and sets its duties on security, sub-contractors, breaches and deletion. Under India’s Digital Personal Data Protection Act, 2023, a business may use a processor only under a valid contract.

The Act calls the business a Data Fiduciary and the vendor a Data Processor. The fiduciary stays responsible to the individual and to the Data Protection Board for what its processor does, so the agreement is how it controls that risk. European customers ask for a DPA that meets Article 28 of the GDPR.

When you need it

  • When a vendor handles your customers’ or employees’ data

    Cloud hosting, payroll, customer support, marketing and analytics vendors are all processors.

  • When you process data for your customers

    A software or outsourcing business is the processor, and its customers will send their own DPA for signature.

  • When a European customer requires one

    The GDPR lists what the contract must contain, and adds transfer clauses where data comes to India.

  • When vendor contracts predate the new law

    Existing contracts usually say little about personal data and need an addendum before May 2027.

  • When a vendor uses its own sub-contractors

    The business needs to know who else holds its data, and to have the same obligations passed down.

How the process works

Four stages. Timings are typical, not promised.

  1. 1

    Map the relationship

    A few working days

    Establish what personal data the vendor receives, what it does with it, where it is stored, who its sub-contractors are and which laws apply to the business and its customers.

    Documents

    • The main agreement with the vendor or customer
    • A description of the data and the service
    • The vendor’s list of sub-processors and security summary
  2. 2

    Draft or review

    Commonly within a week

    Prepare a DPA or mark up the other side’s. The terms cover the subject matter and instructions, confidentiality, security measures, sub-processors, help with individual requests, breach reporting, audits, transfers, and return or deletion at the end.

  3. 3

    Settle liability

    Depends on the other side

    Agree how the DPA sits with the liability cap in the main agreement, who bears the cost of a breach and a regulator’s penalty, and what insurance the vendor carries.

  4. 4

    Sign and keep a register

    At signing

    Sign the DPA as part of, or an addendum to, the main agreement, and keep a register of processors with the date and terms of each.

Common questions

Section 8(2) of the Digital Personal Data Protection Act allows a Data Fiduciary to engage a Data Processor only under a valid contract. The Rules add that the contract must provide for reasonable security safeguards. The duty applies from 13 May 2027.

To discuss a data processing agreement, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 7 October 2026.