← Template library
Data Protection / Privacy

Data Processing Agreement (DPDP Act 2023) — India

A data processing agreement drafted to India's DPDP Act 2023 and DPDP Rules 2025 — not a re-badged GDPR Article 28 DPA. Uses the statutory Data Fiduciary / Data Processor / Data Principal vocabulary, flows down the Rule 6 security floor including the one-year log minimum, sets a breach escalation window short enough for the Fiduciary's own 72-hour Board report under Rule 7, mirrors the s.8(7)(b) erasure duty, and handles cross-border transfer the way s.16 actually works.

Jurisdiction
India
Length
2,540 words
Licence
Free reuse, no attribution
Last reviewed
2026-08-19
Download .txtor print this page to PDF
DATA PROCESSING AGREEMENT (Digital Personal Data Protection Act, 2023 — India) This Data Processing Agreement ("Agreement") is made on [DATE] BETWEEN [FIDUCIARY NAME], a company incorporated under the Companies Act, 2013 having its registered office at [ADDRESS] (the "Data Fiduciary"); AND [PROCESSOR NAME], a company incorporated under [LAW] having its registered office at [ADDRESS] (the "Data Processor"). The Data Fiduciary and the Data Processor are each a "Party" and together the "Parties". BACKGROUND A. The Parties have entered into [MASTER AGREEMENT / SERVICES AGREEMENT] dated [DATE] (the "Principal Agreement"), under which the Data Processor processes Personal Data on behalf of the Data Fiduciary. B. This Agreement records the Parties' obligations under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. 1. DEFINITIONS AND INTERPRETATION 1.1 Terms used in this Agreement and defined in the Act have the meaning given to them in the Act. In particular, "Data Fiduciary", "Data Processor", "Data Principal", "Personal Data", "Processing" and "Personal Data Breach" bear their section 2 meanings. 1.2 "Act" means the Digital Personal Data Protection Act, 2023 and "Rules" means the Digital Personal Data Protection Rules, 2025, in each case as amended and as brought into force from time to time. 1.3 COMMENCEMENT. The Parties acknowledge that the substantive provisions of the Act — including section 8, section 16 and the Schedule of penalties — commence on 13 May 2027. The obligations in this Agreement apply from the date of this Agreement as a matter of contract, and the Parties will comply with them as a matter of statute from commencement. 1.4 This Agreement is governed by the Act and is not drafted to Regulation (EU) 2016/679. Where the Principal Agreement contains data protection terms drafted to another regime, this Agreement prevails in respect of Personal Data to which the Act applies. 2. SCOPE AND ROLES 2.1 The Data Fiduciary determines the purpose and means of Processing. The Data Processor processes Personal Data only on behalf of the Data Fiduciary and only under this Agreement. 2.2 The Parties acknowledge that, under section 8(1) of the Act, the Data Fiduciary remains responsible for compliance in respect of Processing undertaken by the Data Processor on its behalf, whether or not the Data Principal has any agreement with the Data Processor. Nothing in this Agreement transfers that statutory responsibility. 2.3 The particulars of Processing — categories of Personal Data, categories of Data Principals, the purpose, the nature of Processing and its duration — are set out in Schedule 1. 3. INSTRUCTIONS 3.1 The Data Processor shall process Personal Data only on the documented instructions of the Data Fiduciary, including as to transfers outside India, unless required to do otherwise by law. Where so required, the Data Processor shall inform the Data Fiduciary before Processing, unless the law prohibits that notice. 3.2 The Data Processor shall promptly inform the Data Fiduciary if, in its opinion, an instruction would cause either Party to breach the Act. 3.3 The Data Processor shall not process Personal Data for its own purposes, and shall not use Personal Data to train any model or system except on the separate written instruction of the Data Fiduciary specifying the purpose. 4. LAWFUL BASIS 4.1 The Data Fiduciary is responsible for establishing the lawful basis for Processing under section 4 of the Act, being either the consent of the Data Principal under section 6 or a legitimate use under section 7. 4.2 The Parties acknowledge that section 7 sets out an exhaustive list of legitimate uses. Neither Party shall rely on a basis not provided for by the Act, and in particular shall not rely on any "legitimate interests" balancing test. 4.3 Where Processing rests on consent, the Data Fiduciary bears the burden of proving that valid notice was given and valid consent obtained (section 6(10)). The Data Processor shall not process Personal Data in a manner inconsistent with the consent notified to it under clause 5. 5. CONSENT AND WITHDRAWAL 5.1 The Data Fiduciary shall give each Data Principal the notice required by section 5 and Rule 3. 5.2 The Data Fiduciary shall inform the Data Processor of the scope of consent relevant to the Processing, and of any change to or withdrawal of that consent, without undue delay and in any event within [2] Business Days. 5.3 On being informed of a withdrawal of consent, the Data Processor shall cease the affected Processing and shall erase the affected Personal Data in accordance with clause 9, unless retention is required by law. 6. SECURITY SAFEGUARDS 6.1 The Data Processor shall implement reasonable security safeguards to prevent a Personal Data Breach, and shall at a minimum maintain the measures prescribed by Rule 6(1), namely: (a) encryption, obfuscation, masking or the use of virtual tokens mapped to the Personal Data; (b) control over access to its computer resources used for Processing; (c) logs, monitoring and review giving visibility of access to the Personal Data, sufficient to enable detection and investigation of unauthorised access and remedial action; (d) measures for continued processing in the event of loss of access, including reasonable backups; (e) retention of the logs and Personal Data referred to in (c) for a period of not less than ONE YEAR, unless a longer period is required by law; (f) provision in every contract with any sub-processor requiring equivalent reasonable security safeguards; and (g) appropriate technical and organisational measures to ensure the effective observance of these safeguards. 6.2 The measures in clause 6.1 are a floor and not a ceiling. Schedule 2 sets out any additional measures agreed between the Parties. 7. PERSONAL DATA BREACH 7.1 The Data Processor shall notify the Data Fiduciary of any Personal Data Breach affecting Personal Data processed under this Agreement WITHOUT DELAY and in any event within [24] HOURS of becoming aware of it. NOTE FOR THE DRAFTER: this window must be materially shorter than 72 hours. On becoming aware of a breach, the Data Fiduciary must give the Board an immediate description and a six-part report within 72 hours under Rule 7(2), and must intimate each affected Data Principal without delay under Rule 7(1). A 72-hour processor window makes the Fiduciary's own deadline unmeetable. Do not lengthen it to match a GDPR precedent. 7.2 The notification under clause 7.1 shall include, so far as known, and shall be supplemented as further information becomes available: (a) a description of the breach, including its nature, extent and timing and the location at which it occurred; (b) the categories and approximate volume of Personal Data affected and the Data Principals affected; (c) the consequences relevant to the Data Principals that are likely to arise from the breach; (d) the measures implemented or proposed to mitigate risk; and (e) the contact details of a person able to respond to queries. 7.3 The Data Processor shall provide all cooperation, information and access reasonably required for the Data Fiduciary to discharge its obligations under section 8(6) of the Act and Rule 7, including for the purpose of intimating affected Data Principals. 7.4 The Data Processor shall not communicate with any Data Principal, the Data Protection Board of India or any regulator about a Personal Data Breach affecting Personal Data processed under this Agreement without the prior written consent of the Data Fiduciary, unless required by law. 8. DATA PRINCIPAL RIGHTS 8.1 The Data Processor shall provide the Data Fiduciary with reasonable assistance, by appropriate technical and organisational measures, to respond to a request from a Data Principal to exercise a right under the Act, being the right to: (a) obtain a summary of Personal Data processed and the processing activities undertaken, together with the identities of other Data Fiduciaries and Data Processors with whom the Personal Data has been shared (section 11); (b) correction, completion, updating and erasure (section 12); (c) grievance redressal (section 13); and (d) nominate another individual to exercise the Data Principal's rights in the event of death or incapacity (section 14). 8.2 The Parties acknowledge that the Act does not confer a general right to data portability or a general right to object to Processing, and that no obligation in respect of such rights arises under this Agreement. 8.3 The Data Processor shall forward any request received directly from a Data Principal to the Data Fiduciary within [2] Business Days and shall not respond to it itself, unless instructed to do so. 9. RETENTION AND ERASURE 9.1 The Data Processor shall erase Personal Data, and cause any sub-processor to erase it, on the instruction of the Data Fiduciary given following the withdrawal of consent by a Data Principal or where the specified purpose is no longer being served, in accordance with section 8(7)(b) of the Act and Rule 8(3). 9.2 Erasure shall be effected within [7] Business Days of instruction unless a longer period is agreed in writing, and shall extend to backups on the Data Processor's ordinary backup cycle. 9.3 Clause 9.1 does not require erasure of Personal Data whose retention is required by law, nor of the logs required to be retained under clause 6.1(e). 9.4 On expiry or termination of the Principal Agreement, the Data Processor shall at the Data Fiduciary's election return or erase all Personal Data and certify erasure in writing. 10. SUB-PROCESSING 10.1 The Data Processor shall not engage a sub-processor without the prior [written / general] authorisation of the Data Fiduciary. Where general authorisation is given, the Data Processor shall inform the Data Fiduciary of any intended change at least [30] days in advance and the Data Fiduciary may object. 10.2 The Data Processor shall impose on every sub-processor obligations no less protective than those in this Agreement, including the security safeguards required by clause 6.1(f), and remains fully liable to the Data Fiduciary for the acts and omissions of each sub-processor. 10.3 The sub-processors authorised at the date of this Agreement are listed in Schedule 3. 11. TRANSFERS OUTSIDE INDIA 11.1 The Data Processor may process Personal Data outside India only as instructed by the Data Fiduciary and only in a country in respect of which the Central Government has not issued a restriction under section 16(1) of the Act. 11.2 The Parties acknowledge that the Act operates by restriction rather than by adequacy: transfer is permitted unless and until the Central Government restricts a country by notification. Accordingly no adequacy decision, standard contractual clauses or transfer impact assessment under any other regime is relied on by this Agreement. 11.3 The Data Processor shall, within [15] days of a restriction taking effect in respect of a country in which it processes Personal Data, cease that Processing and migrate it to a permitted location at [its own / the Parties' shared] cost. 11.4 Where the Data Fiduciary is notified as a Significant Data Fiduciary and is subject to a direction under Rule 13(4) that specified Personal Data be processed subject to the restriction that it not be transferred outside India, the Data Processor shall comply with that direction on notice and shall not charge for doing so beyond [AGREED BASIS]. 11.5 The Data Processor shall not make Personal Data available to any foreign State or its instrumentality save in accordance with Rule 15 and after notifying the Data Fiduciary, unless prohibited from giving that notice. 12. SIGNIFICANT DATA FIDUCIARY SUPPORT 12.1 Where the Data Fiduciary is notified as a Significant Data Fiduciary under section 10(1), the Data Processor shall provide reasonable assistance and information for the Data Fiduciary's Data Protection Impact Assessment and independent audit under section 10(2)(a), and for any algorithmic due diligence under section 10(2)(b). 12.2 Assistance under clause 12.1 shall be provided [at no additional charge / on the basis set out in Schedule 4]. 13. AUDIT 13.1 The Data Processor shall make available to the Data Fiduciary the information reasonably necessary to demonstrate compliance with this Agreement, and shall allow and contribute to audits conducted by the Data Fiduciary or an auditor appointed by it, on [30] days' notice and no more than [once] in any twelve-month period, save following a Personal Data Breach when no such limit applies. 14. CHILDREN AND PERSONS WITH DISABILITY 14.1 Where the Processing involves the Personal Data of a child or of a person with a disability who has a lawful guardian, the Data Processor shall process it only in accordance with the Data Fiduciary's instructions reflecting section 9 of the Act and Rules 10 to 12. 14.2 The Data Processor shall not undertake tracking or behavioural monitoring of children, or targeted advertising directed at children, in the course of Processing under this Agreement. 15. LIABILITY AND INDEMNITY 15.1 Each Party's liability under this Agreement is subject to the limitations in the Principal Agreement, save that no limitation applies to [ ]. 15.2 The Data Processor shall indemnify the Data Fiduciary against penalties imposed on the Data Fiduciary under the Schedule to the Act to the extent they arise from the Data Processor's breach of this Agreement. NOTE FOR THE DRAFTER: penalties under the Schedule reach Rs 250 crore for failure to take reasonable security safeguards. Both Parties should price this clause deliberately rather than inherit a generic cap. 16. TERM 16.1 This Agreement takes effect on the date first written above and continues for so long as the Data Processor processes Personal Data on behalf of the Data Fiduciary, and thereafter in respect of clauses 9, 13 and 15. 17. GOVERNING LAW AND DISPUTES 17.1 This Agreement is governed by the laws of India. 17.2 The courts at [CITY] shall have exclusive jurisdiction, subject to any arbitration agreement in the Principal Agreement. SCHEDULE 1 — PARTICULARS OF PROCESSING Categories of Personal Data: [ ] Categories of Data Principals: [ ] Specified purpose: [ ] Nature of Processing: [ ] Duration: [ ] Locations of Processing: [ ] SCHEDULE 2 — ADDITIONAL SECURITY MEASURES [ ] SCHEDULE 3 — AUTHORISED SUB-PROCESSORS Name | Location | Processing activity [ ] SCHEDULE 4 — CHARGES FOR ASSISTANCE [ ] SIGNED for and on behalf of the Data Fiduciary Name: ______________________ Designation: ______________________ Date: ______________________ SIGNED for and on behalf of the Data Processor Name: ______________________ Designation: ______________________ Date: ______________________ ---------------------------------------------------------------------------- DRAFTING NOTES 1. Stamp duty. A DPA is generally stamped as an agreement not otherwise provided for; the rate is state-specific. An insufficiently stamped agreement is inadmissible in evidence in India, which matters precisely when you need to rely on it. 2. Do not import GDPR machinery. Standard contractual clauses, adequacy recitals, "legitimate interests" bases, and portability and objection rights have no counterpart in the Act. Their presence signals the document was not drafted for India. 3. The breach window in clause 7.1 is the clause most often got wrong. Set it materially below 72 hours. 4. If either Party is or may become a Significant Data Fiduciary, revisit clauses 11.4 and 12 before signing — SDF status brings localisation directions and audit obligations that a standard DPA does not anticipate. 5. Commencement is 13 May 2027 for the substantive regime. Signing earlier is sensible; assuming nothing bites until then is not, because the contract binds from signature. This template is a drafting starting point and is not legal advice. Have it reviewed by a qualified advocate before signature.

Licence & disclaimer

Free to use, copy, modify and redistribute, including commercially, without attribution.

Provided as-is as a drafting starting point. This is not legal advice and does not create an attorney-client or advocate-client relationship. Indian law is fact- and state-specific — stamp duty, registration and several employment obligations vary by state. Have a qualified advocate or company secretary review any document before you sign it.

More templates

Employment Agreement (India) — StandardESOP Plan + Grant Letter — IndiaFounders' Agreement — India