contract clauses
Data Protection Clauses in Indian Contracts Under the DPDP Act
A data protection clause allocates who handles personal data, what they may do with it, and who answers when something goes wrong. In India, this is no longer just good practice copied from a GDPR template. The Digital Personal Data Protection Act, 2023 (DPDP Act) gives it a statutory backbone: a defined "Data Fiduciary" and "Data Processor," a rule that a fiduciary can only hand data to a processor "under a valid contract," a breach-notification duty, and rules on moving data outside India. The one thing most people get wrong: assuming a DPDP clause is optional until the Act is "fully in force." It is not. The Act was notified in August 2023, its Rules in November 2025, and the substantive obligations come into force on 14 May 2027 on the government's own staggered timeline. Contracts signed today will still be running when that date arrives. (This guide is published by Adira, which makes contract review and CLM software, so we have a commercial stake in you understanding this clause, but it is written to stand on its own without a sales pitch.)
Plain meaning
Strip away the acronyms and a data protection clause says three things. First, it names the "Data Fiduciary," who decides why and how personal data is processed, and the "Data Processor," who processes it on the fiduciary's behalf without making those decisions independently. Second, it sets ground rules on what the processor may do with the data and what security it must maintain. Third, it covers what everyone forgets to negotiate until too late: what happens on a breach (who tells whom, how fast), and what happens when the contract ends (deleted, returned, or left sitting on someone's server).
This clause used to be a boilerplate confidentiality add-on. Under the DPDP Act it is closer to a compliance instrument. If a company engages a vendor and the contract does not properly allocate DPDP roles, the company, as Data Fiduciary, remains on the hook for the vendor's conduct. Section 8(1) is explicit that the fiduciary stays responsible "in respect of any processing undertaken by it or on its behalf by a Data Processor." You cannot contract out of that responsibility, only contract to make sure the processor does what it is supposed to.
Who it protects and what triggers it
The clause protects two people at once: the Data Principal, the individual whose data is processed, an employee, customer, patient, or user, never a party to the contract itself, and the Data Fiduciary, the business that answers to the Data Protection Board of India if something goes wrong, by binding its processor (vendor, cloud provider, payroll processor, agency) to behave.
The trigger is any processing under the contract, not just a breach; it should govern day-to-day handling, not just activate as an emergency plan afterward. A sharper trigger sits inside it: a personal data breach, defined under Section 2(u) as "any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data." Then notice obligations kick in on a clock, not at the vendor's convenience.
What to look for
Five mechanics decide whether the clause works, and none show up if you only check that "confidential" appears somewhere:
- Role allocation. Does the clause say, plainly, who is the Data Fiduciary and who is the Data Processor here? A vendor can be a fiduciary for one dataset (its own employee records) and a processor for another (your customer data) in the same relationship.
- Instructions-only processing. Does the processor promise to process data only on documented instructions, not for its own purposes, model training, or resale, without separate consent?
- Security safeguard standard. Is there a stated standard (encryption, access controls, logging) or just the word "appropriate," meaning whatever the vendor decides until a regulator disagrees?
- Breach notice timeline. Must the processor tell the fiduciary within a specific, short window, hours, not days, given the fiduciary's own tight statutory clock?
- Cross-border transfer and deletion terms. Does the clause say where data may be processed, and what happens to it, deletion or return, at contract end?
The Indian position: the DPDP Act, 2023
The DPDP Act defines both roles in Section 2. A "Data Fiduciary" is "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data" (Section 2(j)). A "Data Processor" is defined in Section 2(k):
"'Data Processor' means any person who processes personal data on behalf of a Data Fiduciary." Source: Section 2, Digital Personal Data Protection Act, 2023
That definition is thin, it says nothing about security, notice, or deletion, which is exactly why Section 8(2) exists:
"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract." Source: Section 8, Digital Personal Data Protection Act, 2023
Three more sub-sections carry the operational weight. Section 8(5) requires the fiduciary to "protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach." Section 8(6) requires that "in the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed." The DPDP Rules, 2025 (notified 14 November 2025) fill in that timeline: an immediate "without delay" alert to the Board, a detailed report within 72 hours, and "without delay" notice to each Data Principal (Rule 7). Section 8(7) requires erasure once consent is withdrawn or the purpose is no longer served, and specifically to "cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor," unless retention is required by another law.
On moving data outside India, Section 16 takes a "restricted list" approach: transfers are allowed by default, except to a country the Central Government specifically restricts by notification. No such list has been notified yet, so transfer is currently unrestricted in practice, but a contract should still say where data may be processed and require notice if that changes, since the notification power can be exercised any time. "DPDP allows transfers" is not the same as "your contract addresses it"; your counterparty's security posture in that jurisdiction is still your problem.
One honest caveat: most of Section 8's obligations sit on that staggered commencement timeline through 14 May 2027. That does not make this clause premature, it makes it something to negotiate now, for contracts that will still be running when the obligations bite.
A named case: the constitutional root, Puttaswamy
The DPDP Act did not appear from nowhere. It exists because of Justice K.S. Puttaswamy (Retd.) v Union of India (Supreme Court, nine-judge bench, 24 August 2017), which challenged the Aadhaar biometric scheme on privacy grounds. The Court held unanimously that the right to privacy is a fundamental right under Article 21 (and Articles 14 and 19), overruling two earlier decisions, M.P. Sharma and Kharak Singh, that had held no such standalone right existed. See the full judgment on Indian Kanoon.
Why this matters for a contract clause: Puttaswamy is why "informational privacy," control over your own data, is a constitutional interest in India, not a consumer-protection nicety, and why the DPDP Act frames data protection around consent and purpose limitation rather than free use. A clause that reads like an afterthought is out of step with where Indian law has headed since 2017.
Red flags
| Normal | Red flag | Why it matters |
|---|---|---|
| Clause names which party is Data Fiduciary and which is Data Processor for this engagement | No DPDP role allocation anywhere in the contract | Leaves both parties to argue after a breach about who was actually responsible for compliance |
| Processor bound to process only on the fiduciary's documented instructions | No restriction on the processor's use of the data, or a vague "as needed to provide the services" | Opens the door to the vendor repurposing data for its own analytics, marketing, or model training |
| Stated security standard: encryption, access controls, logging, or a named framework (ISO 27001, SOC 2) | Only the word "appropriate" or "reasonable" safeguards, undefined | Section 8(5) itself only says "reasonable," so an undefined term gives you nothing beyond the statute's own vague floor |
| Processor must notify the fiduciary within a short, stated window (commonly 24 to 48 hours) | No breach-notice obligation, or notice "promptly" with no number attached | Your own 72-hour clock to the Board starts on becoming aware; a slow processor eats into that window |
| Contract states where data will be processed and requires notice before changing location | Cross-border transfer left unaddressed | Section 16 allows transfer by default, but a silent contract gives no visibility if the vendor moves data, or the government later restricts that country |
| Processor must delete or return data on termination, with a certificate of deletion | No deletion or return obligation on exit | Section 8(7) requires the fiduciary to cause the processor to erase data; an unreachable ex-vendor makes that operational, not just paper |
| Processor needs consent to engage a sub-processor, with flow-down obligations | Unrestricted right to sub-contract processing | Your data ends up with a party you never vetted |
Bad clause → better clause
Bad: "Vendor shall keep Customer data confidential and comply with applicable data protection laws."
No DPDP role allocation, no instructions-only restriction, no security standard, no breach-notice timeline, no cross-border or deletion terms. Reads like it was written in 2015 and never updated.
Better: "For the purposes of the Digital Personal Data Protection Act, 2023, Customer is the Data Fiduciary and Vendor is the Data Processor for personal data under this Agreement. Vendor shall process personal data solely on Customer's documented instructions and solely to provide the Services, and shall not use such data for any other purpose, including analytics or model training, without Customer's prior written consent. Vendor shall implement reasonable security safeguards including encryption at rest and in transit, role-based access controls, and audit logging. Vendor shall process personal data only within [India / named jurisdictions] and give Customer 30 days' written notice before processing it elsewhere. On becoming aware of a personal data breach, Vendor shall notify Customer without delay and within 24 hours, with detail sufficient for Customer to meet its own obligations under Section 8(6). On termination, Vendor shall, at Customer's election, delete or return all personal data and confirm deletion in writing within 30 days, except where retention is required by law."
What changed: roles are named instead of left to inference, security has a real standard instead of one adjective, the breach window is a number, and geography and exit are addressed instead of left silent.
How it interacts with related clauses
A data protection clause rarely stands alone in a well-drafted contract:
- Data processing agreement (DPA). In larger deals these terms move into a standalone schedule covering sub-processors, audit rights, and Data Principal requests in more depth. See Data Processing Agreement (DPA) Clauses Explained for India.
- Confidentiality. Protects business information generally; the DPDP clause is specifically about personal data and carries obligations confidentiality alone does not.
- Indemnity and limitation of liability. A breach from processor negligence is the third-party-claim risk indemnity allocates. Check whether these breach obligations sit inside or outside your liability cap, silence here is a common gap.
- Audit rights. If you are the Data Fiduciary trusting a processor's word on safeguards, an audit right lets you verify that rather than trust it.
You can flag and comment on how these clauses connect directly inside a document, for free, using Weave, before you send a contract back for negotiation.
US and global contrast
The US has no single federal data protection law comparable to the DPDP Act. It runs on a sectoral patchwork, HIPAA for health data, GLBA for financial data, layered with state laws like the California Consumer Privacy Act. A US data clause is usually built to satisfy whichever state or sector law applies, not one unified statute.
The EU's GDPR is the closer comparison, and more prescriptive: Article 28 lists mandatory processor-contract terms, purpose limits, sub-processor consent, audit rights, in the statute itself, where the DPDP Act leaves most of that detail to the contract and Rules. Cross-border transfer is the sharpest contrast: GDPR restricts transfers by default, permitted only to approved countries. The DPDP Act flips that, permitting by default and restricting only countries the government names, none so far, which puts more weight on the contract to fill the gap GDPR's statute already covers.
FAQ
Is my company a Data Fiduciary or a Data Processor? It depends on the data and relationship, not your industry. If you decide why and how data is processed, you are the Data Fiduciary for that data (Section 2(j)); if you process on someone else's instructions, you are the Data Processor (Section 2(k)). A company is commonly both, fiduciary for its own employee data, processor for a client's data.
Does the DPDP Act apply if the substantive provisions are not fully in force yet? The Act and Rules are notified, commencement staggered through 14 May 2027. Contracts signed now will typically still be running once these obligations take effect, so build the clause in now to avoid a costly renegotiation later.
How fast does a breach have to be reported? Under Rule 7 of the DPDP Rules, 2025, the Data Fiduciary must give the Board an immediate, "without delay" alert on becoming aware of a breach, then a detailed report within 72 hours, and notify affected Data Principals without delay too. Your processor contract should require notice well inside that window.
Can personal data be sent outside India under the DPDP Act? Yes, by default. Section 16 restricts transfer only to countries the government names by notification, and none exist yet. "The statute allows it" is not "your contract addresses it," a good clause still states where data is processed and requires notice of any change.
What is the difference between a data protection clause and a full data processing agreement? A clause is a section inside a broader contract. A data processing agreement (DPA) is a standalone document, or schedule, dedicated to how a processor handles a fiduciary's data, covering sub-processors, audit rights, and Data Principal requests in more depth. See Data Processing Agreement (DPA) Clauses Explained for India.
What happens to the data when the contract ends? Under Section 8(7), the Data Fiduciary must cause its Data Processor to erase personal data made available for processing, once the purpose is served and no law requires retention. Make this an explicit termination obligation, with a timeline and a confirmation requirement, rather than trusting the processor to remember.
This guide gets you to understanding what a data protection clause under the DPDP Act should contain and what to check before you sign. It does not tell you whether a specific clause meets your compliance obligations, that depends on your actual data flows and facts a lawyer needs to review, and is not legal advice. Talk to a lawyer, and where relevant a privacy specialist, before you finalise a data protection clause in a live contract.
Frequently asked questions
- Is my company a Data Fiduciary or a Data Processor?
- It depends on the specific data and relationship, not your industry generally. If you decide why and how personal data is processed, you are the Data Fiduciary for that data under Section 2(j) of the DPDP Act. If you process it on someone else's instructions and for their purposes, you are the Data Processor under Section 2(k), for that same data. A single company is commonly both, fiduciary for its own employee data, processor for a client's data it handles under a service contract.
- Does the DPDP Act apply if the substantive provisions are not fully in force yet?
- The Act itself and the DPDP Rules, 2025 are notified, and commencement is staggered through 14 May 2027 on the government's own timeline. Contracts signed now will typically still be running when the substantive obligations, consent, breach notice, security safeguards, take effect, so building the clause in now avoids a costly renegotiation later, even though enforcement of the core obligations has not fully started.
- How fast does a personal data breach have to be reported under the DPDP Act?
- Under Rule 7 of the DPDP Rules, 2025, the Data Fiduciary must give the Data Protection Board an immediate, without-delay alert on becoming aware of a breach, followed by a detailed report within 72 hours, and must notify affected Data Principals without delay as well. A contract with any processor should require them to notify the fiduciary well inside that window, not at the edge of it.
- Can personal data be sent outside India under the DPDP Act?
- Yes, by default. Section 16 of the DPDP Act restricts transfer only to countries the Central Government specifically notifies by name, and no such restricted-country list has been notified as of this writing. That said, the statute allowing transfer is not the same as a contract addressing it; a good clause still states where data will be processed and requires notice of any change in location.
- What is the difference between a data protection clause and a full data processing agreement?
- A data protection clause is a section inside a broader commercial contract. A data processing agreement (DPA) is a standalone document, or a detailed schedule, dedicated entirely to how a processor handles a fiduciary's personal data, covering sub-processor consent, audit rights, and assistance with Data Principal requests in more depth than a single clause usually can.
- What happens to personal data when the contract ends?
- Under Section 8(7) of the DPDP Act, the Data Fiduciary must erase personal data once the purpose is served or consent is withdrawn, and must cause its Data Processor to erase any personal data made available to it for processing, unless retention is required by another law. Contracts should make this an explicit termination obligation with a stated timeline and a confirmation requirement.
Sources
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), official text
- Digital Personal Data Protection Rules, 2025, notified 14 November 2025 (PIB press release)
- Justice K.S. Puttaswamy (Retd.) and Anr. vs Union of India and Ors., Supreme Court, 24 August 2017 (right to privacy)
- Digital Personal Data Protection Act, 2023, Section 2 (definitions: Data Fiduciary, Data Processor, personal data breach)
- Digital Personal Data Protection Act, 2023, Section 8 (Data Fiduciary obligations: valid contract, security, breach notice, erasure)
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free