Every Outsourcing Arrangement That Involves Indian Personal Data Is Now a DPDPA Compliance Event
Section 8(2) makes the Data Fiduciary — the client — responsible for the processing conducted by the Data Processor — the outsourcing provider. But the provider also has direct obligations as a Data Fiduciary for its own employee and operational data.
India's IT outsourcing and BPO industry processes personal data of millions of individuals across the globe — customer service records, financial transactions, healthcare claims, insurance processing, and technical support interactions. Under the DPDPA, every outsourcing provider processing personal data of Data Principals within India is a Data Processor with statutory obligations.
For global companies that outsource operations to India, DPDPA creates a dual compliance challenge. First, the Indian outsourcing provider processes data on behalf of the foreign client (Data Processor obligations). Second, the same provider processes personal data of its own Indian employees (Data Fiduciary obligations). Both must be addressed in the contractual framework.
Contractual Framework Under Section 8(2)
Section 8(2) requires a valid contract between the Data Fiduciary and the Data Processor. For outsourcing arrangements, this contract must specify: the scope of processing authorised, the security safeguards required, the sub-processing restrictions, the breach notification obligations, and the data return or deletion requirements upon termination. Existing master service agreements (MSAs) drafted before August 2023 are unlikely to contain DPDPA-compliant provisions.
Key DPDPA Obligations
| Obligation | Section / Rule | Description |
|---|---|---|
| DPDPA-aligned MSA provisions | Section 8(2) | Data processing clauses in every outsourcing agreement meeting statutory requirements |
| Employee data compliance | Sections 5, 6 | Notice and consent for Indian employees of the outsourcing provider |
| Sub-processor restrictions | Section 8(2) | Contractual controls on further sub-processing by the outsourcing provider |
| Cross-border data flow governance | Section 16 | Mapping of all personal data processed by the provider against restricted jurisdictions |
Request an Outsourcing DPDPA Compliance Framework Review
A confidential review of your India outsourcing contracts — MSA provisions, employee data compliance, sub-processor governance, and cross-border data flow mapping against DPDPA requirements.
Request a Confidential Briefing
Our data privacy counsel will reach out within one working day.
Frequently Asked Questions
Who is responsible for DPDPA compliance in an outsourcing arrangement?
The Data Fiduciary (the client) remains primarily responsible under Section 8(2). The Data Processor (the outsourcing provider) must process data only under a valid contract. Both parties share operational compliance obligations, but statutory liability rests primarily with the Data Fiduciary.
