AMLEGALS — Strategic Lawyering
← All Insights
Article

DPDPA Data Processor Agreement: What Global Vendors Must Include in Their India DPA

Anandaday MisshraMay 2026
DPDPA Data Processor Agreement: What Global Vendors Must Include in Their India DPA

Section 8(2): The Chain of Responsibility

Section 8(2) of the DPDPA establishes a fundamental principle: the Data Fiduciary is responsible for ensuring that any Data Processor engaged by the Data Fiduciary processes personal data only in accordance with a valid contract and only for the purposes and in the manner specified by the Data Fiduciary. This creates a chain of contractual accountability that flows from the Data Fiduciary through every tier of the processing chain.

What Must Be in the Agreement

While the DPDPA does not prescribe a specific DPA template, the agreement must at minimum address: (a) the specific personal data to be processed, (b) the specific purpose for which processing is authorised, (c) the manner of processing, (d) the obligation to implement security safeguards under Section 8(4), (e) the obligation to notify the Data Fiduciary of any breach, (f) the obligation to delete personal data upon completion of the processing purpose or termination of the agreement, and (g) sub-processing restrictions and conditions.

Global Vendor Considerations

For global vendors who process personal data of Indian Data Principals — cloud providers, SaaS platforms, analytics services, payment processors — the DPDPA DPA requirements create obligations that differ from GDPR DPAs in several ways. First, the DPDPA does not recognise "joint controller" arrangements — the distinction is strictly between Data Fiduciary and Data Processor. Second, the DPDPA does not provide for Standard Contractual Clauses as a transfer mechanism. Third, the deletion obligation is absolute — there is no exception for data required for the vendor's own compliance purposes unless that processing falls under a separate legitimate use under Section 7.

Sub-Processor Governance

Most global vendors use sub-processors. A cloud vendor uses infrastructure from another cloud provider. An analytics vendor stores data on a third party's servers. Under DPDPA, the Data Fiduciary remains responsible for the entire chain. The DPA must either: (a) prohibit sub-processing without the Data Fiduciary's written consent, or (b) require the Data Processor to ensure that any sub-processor is bound by equivalent obligations. The Data Fiduciary must know who every sub-processor is and where they process data — for Section 16 compliance.

Audit Rights

The DPA should include audit rights allowing the Data Fiduciary to verify the Data Processor's compliance. For SDF entities, this is especially important because the independent data auditor appointed under Rule 12 may need to audit the entire processing chain. Global vendors that resist audit clauses create a compliance gap that the Data Fiduciary cannot close.

Breach Notification Flow

When a breach occurs at the Data Processor level, the notification must flow: Data Processor → Data Fiduciary → Data Protection Board and Data Principals. The DPA must specify the timeline for the Data Processor to notify the Data Fiduciary. Given the overall notification timeline under Rule 7, the Data Processor notification should be within hours, not days — the Data Fiduciary needs sufficient time to prepare its own Board and Data Principal notifications.

Need guidance on this topic?

We advise organisations across India on DPDPA compliance, AI governance and cross border data transfers.

Get in Touch →