Vendor and Processor Contracts Under DPDP
What Indian businesses must build into vendor and data processor contracts to stay DPDP-compliant, including security, breach notice and erasure clauses.
If a vendor mishandles personal data your business collected, the law still looks first to your business, not just the vendor. That makes vendor and processor contracts one of the most overlooked pieces of DPDP compliance.
Key facts at a glance
- Under DPDP, the data fiduciary (the business that decides why and how data is processed) remains accountable even when a data processor (vendor) handles the data.
- Full DPDP substantive obligations, including security and breach-notification duties, become enforceable 13 May 2027, with no stated grace period.
- Penalties for inadequate security safeguards can reach up to Rs 250 crore per instance.
- A DPDP-ready vendor contract should address scope of processing, security, breach notice, sub-processing, and erasure on termination at minimum.
- The Consent Manager registration framework under DPDP Rules 2025 becomes operational 13 November 2026.
- Vendors that predate DPDP still need their contracts reviewed; the law does not grandfather existing agreements.
Why the fiduciary carries the risk, not just the vendor
DPDP places primary legal responsibility on the entity that determines why personal data is collected and how it is used, called the data fiduciary. If that business outsources processing, say, payroll runs, customer support, or email marketing, to a third party, the third party is typically a data processor acting on the fiduciary's instructions. The fiduciary cannot simply point to the vendor's mistake and walk away; it remains accountable for ensuring the vendor handles the data properly.
This is the same logic seen in data protection regimes worldwide: outsourcing a task does not outsource legal responsibility for it.
What belongs in a DPDP-ready vendor contract
Scope and purpose of processing
The contract should spell out exactly what personal data the vendor may access, for what purpose, and for how long. Vague or open-ended access clauses ("all data reasonably necessary") make it harder to demonstrate purpose limitation later.
Security safeguards
The vendor should be contractually required to maintain reasonable technical and organisational security measures proportionate to the sensitivity of the data it handles, and to allow the fiduciary to verify this where practical.
Breach notification timelines
The contract should require the vendor to notify the fiduciary promptly, ideally within a short, specific window, of any suspected or confirmed data breach, so the fiduciary can meet its own downstream reporting obligations.
Restrictions on sub-processing
If the vendor plans to use its own sub-vendors (a common pattern in cloud and SaaS tools), the contract should require prior notice or approval, and should flow the same security and breach obligations down to the sub-processor.
Data return or erasure on termination
When the engagement ends, the contract should specify whether the vendor must return the data, delete it, or anonymise it, and within what timeframe, rather than leaving old data sitting in a decommissioned vendor's systems indefinitely.
Audit and inspection rights
Where practical, the fiduciary should retain the right to review or audit the vendor's data-handling practices, particularly for vendors handling large volumes or sensitive categories of personal data.
Comparing typical vendor relationships
| Vendor type | Typical data handled | Key contract priority |
|---|---|---|
| Payroll or HR software | Employee salary, bank, PF/ESI details | Security safeguards, sub-processor restrictions |
| CRM or marketing platform | Customer contact and behavioural data | Consent-linked purpose limits, erasure on request |
| Cloud hosting or IT support | Broad access across systems | Breach notification timelines, audit rights |
| Payment gateway or fintech partner | Financial and transaction data | Security certification, incident response coordination |
| Outsourced call centre or support desk | Customer identity and complaint data | Access restrictions, staff-level confidentiality obligations |
A practical rollout order
Start with the vendors that handle the most sensitive or highest-volume personal data, such as payroll processors, CRM platforms, and payment partners, and update their contracts first. Lower-risk vendors, such as a one-off design agency with no ongoing data access, can follow later. Keep a simple vendor register noting which contracts have been reviewed and updated, since this register itself becomes useful evidence of a structured compliance effort if ever questioned.
If you are not sure where your business stands on vendor and data-processor risk under DPDP, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology - meity.gov.in
- Data Protection Board of India (as constituted under DPDP) - meity.gov.in
- Ministry of Corporate Affairs, for corporate contracting norms - mca.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Does DPDP hold a business responsible for its vendors' data practices?
- Yes. Under the Digital Personal Data Protection Act 2023, the entity that decides why and how personal data is processed (the data fiduciary) remains accountable for that data even when a vendor or processor handles it on their behalf.
- What is the difference between a data fiduciary and a data processor under DPDP?
- A data fiduciary determines the purpose and means of processing personal data and bears primary legal responsibility, while a data processor handles that data only on the fiduciary's instructions, typically under a service contract.
- What clauses should a DPDP-ready vendor contract include?
- At minimum it should cover the scope and purpose of processing, security safeguards, breach notification timelines, data return or erasure on termination, restrictions on sub-processing, and audit or inspection rights.
- When do DPDP's substantive obligations become enforceable for vendor relationships?
- Full substantive DPDP obligations, including security safeguards and breach reporting, become enforceable on 13 May 2027, with no stated grace period after that date.
- What is the penalty exposure if a vendor causes a data breach?
- Penalties for failing to implement reasonable security safeguards can reach up to Rs 250 crore per instance, and this exposure can extend to the fiduciary even when the breach originates at a vendor, depending on the facts.
- Should every vendor contract be renegotiated for DPDP?
- Any vendor or processor that handles personal data on your behalf, such as payroll, CRM, marketing, IT support or cloud hosting providers, should have its contract reviewed and updated with DPDP-specific clauses even if it predates the law.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.