Read those two sub-sections together and the position is uncomfortable: your vendor's failure is your breach, and no drafting changes that. What good drafting does is give you visibility, a remedy, and the ability to demonstrate you exercised oversight.

Does the DPDP Act require a DPA?

Yes, in substance. Section 8(2) is short — engagement only under a valid contract — and the Act does not enumerate mandatory clauses the way GDPR Article 28 does. That brevity is misleading. The clauses you need are dictated by the obligations you have to discharge through the processor. Work backwards from your own duties and the required contract terms fall out.

Who is your processor?

More vendors than most organisations realise. Anyone processing personal data on your instruction: cloud hosting, SaaS tools holding customer data (CRM, helpdesk, marketing automation), payment processors, email and SMS delivery, analytics providers, call centres and BPO, payroll and HR vendors, marketing agencies running your tags and campaigns, developers and contractors with production access, document storage, and AI and ML vendors processing your data.

Start with a list. Most organisations doing this exercise for the first time find between thirty and a hundred, and find several nobody owns.

The eleven clauses that matter

1. Scope and purpose limitation. The subject matter, duration, nature and purpose of processing, categories of personal data and categories of data principals. Processing only on your documented instruction and for no other purpose — including no use of your data to train the vendor's models unless expressly agreed.

2. Sub-processor control. Whether sub-processors are permitted, notice before adding one, your right to object, and flow-down of equivalent obligations. Ask for the current list with processing locations, because you cannot answer a section 11 access request without it.

3. Security measures. Specific and stated, not "industry standard". Section 8(5) is the obligation carrying the ₹250 crore maximum, and it expressly extends to processing by a processor on your behalf.

4. Breach notification — measured in hours, not days. This is the clause most existing contracts get wrong.

Your clockDeadline
CERT-In Directions, April 20226 hours from detection — in force today
DPDP Rule 7(2)(a)Without delay — from 13 May 2027
DPDP Rule 7(2)(b)72 hours for the detailed report

A contract giving your processor 72 hours to tell you puts you in breach before you know anything happened. Notification must be immediate, with a defined channel and named contacts, plus an obligation to assist your investigation.

5. Assistance with Data Principal rights. When you receive an access, correction or erasure request, you may need the processor to action it in systems you don't administer. Specify the assistance, the turnaround, and who pays.

6. Deletion and return on termination — with the retention floor. Section 8(7) requires you to cause your processor to erase. But Rule 8(3) requires personal data, associated traffic data and processing logs to be retained for a minimum of one year from processing, expressly including processing carried out by a processor on your behalf. So the clause must express both: erase on instruction, and retain for the statutory minimum. → See how erasure and retention interact

7. Audit and information rights. The right to request evidence of compliance and to audit, whether directly or through a third party.

8. Cross-border processing. Where the processor or its sub-processors process outside India, name the locations. DPDP does not impose a localisation mandate — but you need to know where data actually goes.

9. Confidentiality and personnel. Binding obligations on personnel, background verification proportionate to access, and training.

10. Liability and indemnity. Since section 8(1) leaves your exposure intact, this clause is your only route to recovery. A 12-month-fees cap against a serious breach is often a rounding error next to the exposure.

11. Assistance with your own accountability. Cooperation with your DPIAs where applicable, records to support your ROPA, and support in responding to the Board.

Fix breach notification timelines first

Consiva's vendor register holds your processor inventory with DPA status, risk tiers, sub-processor chains and expiry alerts, so a breach shows you which vendors are in scope instantly.

Talk to Us About Vendor Governance →

Are you a processor as well as a fiduciary?

If you sell software or services, almost certainly both — processor for your customers' data, fiduciary for your own users, billing contacts and marketing lists. From 2027 your customers will require a DPA from you, and it will become a gating item in Indian enterprise procurement. Draft it before the sales cycle, not during it — a DPA negotiated under deal pressure concedes more. → See our guide for SaaS & IT

Practical sequence

  1. Inventory every processor. Nothing else is possible first.
  2. Tier by risk — volume, sensitivity, access level, criticality.
  3. Start at the top. Your hosting provider and your CRM matter more than a font CDN.
  4. Fix breach notification timelines first. It is the clause most likely to be wrong and the one with the shortest fuse.
  5. Collect subprocessor lists with locations. You need them for section 11 and for your own notice.
  6. Get your own DPA ready if you are also a processor.
  7. Set a review cycle. Vendors change sub-processors; contracts go stale.

Frequently Asked Questions

Yes in substance. Section 8(2) permits a Data Fiduciary to engage a Data Processor only under a valid contract. The Act doesn't enumerate mandatory clauses as GDPR Article 28 does, but the clauses needed follow from the obligations you must discharge through the processor.

Yes. Section 8(1) makes the Data Fiduciary responsible for compliance in respect of processing undertaken on its behalf by a Data Processor, notwithstanding any agreement to the contrary. Contractual allocation gives you a claim against the vendor; it doesn’t move your exposure to the Board.

Fast enough for you to meet your own deadlines — which means hours. You face a 6-hour CERT-In window today and, from 13 May 2027, a duty to intimate the Board "without delay". A 72-hour vendor notification clause puts you in breach.

Not without qualification. Rule 8(3) requires retention of personal data, traffic data and processing logs for at least one year from processing, including where a processor holds them. The clause must express both erasure and the retention floor.

Not directly to Data Principals. A processor's duties arise under its contract with the Data Fiduciary. This differs from GDPR, which imposes direct obligations on processors.

No. Rule 15 permits transfers subject to requirements the Government may specify, and section 16 allows restricting transfers to notified countries. There is no localisation mandate — but you still need to know where your data goes.

Get Your Vendor Register in Order

Consiva's vendor register holds processor inventory, DPA status, risk tiers, sub-processor chains and expiry alerts — linked to the purposes each vendor supports.