Data Processing Agreements
A data processing agreement (DPA) is the contract between a business that decides how personal data is used and a vendor that handles the data for it. It limits the vendor to the business’s instructions and sets its duties on security, sub-contractors, breaches and deletion. Under India’s Digital Personal Data Protection Act, 2023, a business may use a processor only under a valid contract.
The Act calls the business a Data Fiduciary and the vendor a Data Processor. The fiduciary stays responsible to the individual and to the Data Protection Board for what its processor does, so the agreement is how it controls that risk. European customers ask for a DPA that meets Article 28 of the GDPR.
When you need it
When a vendor handles your customers’ or employees’ data
Cloud hosting, payroll, customer support, marketing and analytics vendors are all processors.
When you process data for your customers
A software or outsourcing business is the processor, and its customers will send their own DPA for signature.
When a European customer requires one
The GDPR lists what the contract must contain, and adds transfer clauses where data comes to India.
When vendor contracts predate the new law
Existing contracts usually say little about personal data and need an addendum before May 2027.
When a vendor uses its own sub-contractors
The business needs to know who else holds its data, and to have the same obligations passed down.
How the process works
Four stages. Timings are typical, not promised.
- 1
Map the relationship
A few working daysEstablish what personal data the vendor receives, what it does with it, where it is stored, who its sub-contractors are and which laws apply to the business and its customers.
Documents
- The main agreement with the vendor or customer
- A description of the data and the service
- The vendor’s list of sub-processors and security summary
- 2
Draft or review
Commonly within a weekPrepare a DPA or mark up the other side’s. The terms cover the subject matter and instructions, confidentiality, security measures, sub-processors, help with individual requests, breach reporting, audits, transfers, and return or deletion at the end.
- 3
Settle liability
Depends on the other sideAgree how the DPA sits with the liability cap in the main agreement, who bears the cost of a breach and a regulator’s penalty, and what insurance the vendor carries.
- 4
Sign and keep a register
At signingSign the DPA as part of, or an addendum to, the main agreement, and keep a register of processors with the date and terms of each.
Common questions
Section 8(2) of the Digital Personal Data Protection Act allows a Data Fiduciary to engage a Data Processor only under a valid contract. The Rules add that the contract must provide for reasonable security safeguards. The duty applies from 13 May 2027.
To the individual and the Board, the Data Fiduciary. Section 8(1) makes it responsible for compliance in respect of processing by its processor, whatever the contract says. The DPA is how it recovers its loss from the vendor.
The purpose and instructions, the kinds of data, security measures, confidentiality of staff, conditions for using sub-processors, prompt notice of a breach, help with individuals’ requests, deletion or return of data at the end, and the right to verify compliance.
Another company the processor uses to handle the data, such as a cloud host. The DPA should require the business’s approval, general or specific, a current list, and the same obligations to be imposed on each one.
Article 28 of the GDPR lists mandatory terms in more detail, and a transfer of European data to India also needs the standard contractual clauses. A business serving both markets often uses one DPA with a schedule for each law.
The DPDP Act puts the duty to notify the Board and affected individuals on the Data Fiduciary, which has to give the Board details within 72 hours. The DPA should therefore require the processor to tell the fiduciary much sooner, commonly within 24 hours.
The fiduciary is required to erase personal data once its purpose is over and to have its processors do the same. The DPA should set a period for return or deletion and require written confirmation.
Related
To discuss a data processing agreement, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 7 October 2026.

