AMLEGALS — Strategic Lawyering
← All Insights
Article

DPDPA Data Processor Agreement: What Global Vendors Must Include in Their India DPA

Anandaday MisshraMay 2026
DPDPA Data Processor Agreement: What Global Vendors Must Include in Their India DPA

Section 8(2): The Chain of Responsibility

Section 8(2) of the DPDPA establishes a fundamental principle: the Data Fiduciary is responsible for ensuring that any Data Processor engaged by the Data Fiduciary processes personal data only in accordance with a valid contract and only for the purposes and in the manner specified by the Data Fiduciary. This creates a chain of contractual accountability that flows from the Data Fiduciary through every tier of the processing chain.

What Must Be in the Agreement

While the DPDPA does not prescribe a specific DPA template, the agreement must at minimum address: (a) the specific personal data to be processed, (b) the specific purpose for which processing is authorised, (c) the manner of processing, (d) the obligation to implement security safeguards under Section 8(4), (e) the obligation to notify the Data Fiduciary of any breach, (f) the obligation to delete personal data upon completion of the processing purpose or termination of the agreement, and (g) sub-processing restrictions and conditions.

Global Vendor Considerations

For global vendors who process personal data of Indian Data Principals — cloud providers, SaaS platforms, analytics services, payment processors — the DPDPA DPA requirements create obligations that differ from GDPR DPAs in several ways. First, the DPDPA does not recognise "joint controller" arrangements — the distinction is strictly between Data Fiduciary and Data Processor. Second, the DPDPA does not provide for Standard Contractual Clauses as a transfer mechanism. Third, the deletion obligation is absolute — there is no exception for data required for the vendor's own compliance purposes unless that processing falls under a separate legitimate use under Section 7.

Sub-Processor Governance

Most global vendors use sub-processors. A cloud vendor uses infrastructure from another cloud provider. An analytics vendor stores data on a third party's servers. Under DPDPA, the Data Fiduciary remains responsible for the entire chain. The DPA must either: (a) prohibit sub-processing without the Data Fiduciary's written consent, or (b) require the Data Processor to ensure that any sub-processor is bound by equivalent obligations. The Data Fiduciary must know who every sub-processor is and where they process data — for Section 16 compliance.

Audit Rights

The DPA should include audit rights allowing the Data Fiduciary to verify the Data Processor's compliance. For SDF entities, this is especially important because the independent data auditor appointed under Rule 13 may need to audit the entire processing chain. Global vendors that resist audit clauses create a compliance gap that the Data Fiduciary cannot close.

Breach Notification Flow

When a breach occurs at the Data Processor level, the notification must flow: Data Processor → Data Fiduciary → Data Protection Board and Data Principals. The DPA must specify the timeline for the Data Processor to notify the Data Fiduciary. Given the overall notification timeline under Rule 7, the Data Processor notification should be within hours, not days — the Data Fiduciary needs sufficient time to prepare its own Board and Data Principal notifications.

Need guidance on this topic?

We advise organisations across India on DPDPA compliance, AI governance and cross border data transfers.

Get in Touch →

DPDPA Data Processor Agreement Requirements Global Vendors: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What rights do individuals have under DPDPA?

Data Principals have the right to access information about processing (Section 11), correction, completion, updating and erasure (Section 12), grievance redressal (Section 13) and nomination (Section 14). Rule 14 governs the manner in which these rights are exercised.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPDPA Data Processor Agreement Requirements Global Vendors?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPDPA Data Processor Agreement Requirements Global Vendors under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPDPA Data Processor Agreement Requirements Global Vendors under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPDPA Data Processor Agreement Requirements Global Vendors?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPDPA Data Processor Agreement Requirements Global Vendors rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPDPA Data Processor Agreement Requirements Global Vendors?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPDPA Data Processor Agreement Requirements Global Vendors · DPDPA Exposure Assessment