dpdp act
The DPDP Act for Contracts: What Changes in Your Agreements
Most Indian commercial contracts were not written with personal data in mind. A services agreement drafted from an old template usually has a thin "confidentiality" clause and nothing else. The Digital Personal Data Protection Act, 2023 (DPDP Act) changes that. It does not create a new type of contract; it changes what an ordinary contract must say the moment personal data, an employee's, a customer's, a patient's, moves through it. (This guide is published by Adira, which makes contract management software, so we have a commercial interest in you trusting contract tools, but the checklist below works whether or not you ever use ours.)
This is a practical drafting guide: what the Act requires, which clauses to add or rewrite, what a Significant Data Fiduciary must do on top of the basics, and what the penalties actually are. For a clause-by-clause deep dive, see Data Protection Clauses in Indian Contracts Under the DPDP Act and Data Processing Agreement (DPA) Clauses Explained for India.
The split every contract has to make: Fiduciary vs Processor
The DPDP Act builds everything on two roles, defined in Section 2. A Data Fiduciary is "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data" (Section 2(j)). A Data Processor is defined more narrowly, in Section 2(k):
"'Data Processor' means any person who processes personal data on behalf of a Data Fiduciary." Source: Section 2, Digital Personal Data Protection Act, 2023
That is thin on its own, it says nothing about security, notice, or deletion, which is why the Act ties it to a contract requirement. Section 8(2) says:
"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract." Source: Section 8, Digital Personal Data Protection Act, 2023
"Only under a valid contract" is not a suggestion, it is the legal gateway. Without one, engaging a processor is itself non-compliant, independent of whether anything goes wrong. Section 8(1) closes the obvious loophole: the fiduciary "shall be responsible for compliance with the provisions of this Act... in respect of any processing undertaken by it or on its behalf by a Data Processor." You cannot push the risk onto a vendor by contract; you can only make the vendor behave, and recover from them if they don't.
The practical consequence: almost every services agreement, SaaS agreement, payroll or HR vendor contract, or IT support contract touching personal data now needs a role allocation and processor obligations built in, not bolted on as an afterthought schedule nobody reads.
Clauses to add or update
Six things belong in any contract where personal data changes hands. None of these are exotic; they are the operational core of Section 8.
1. Processing scope. State what personal data is covered, for what purpose, and that the processor may use it only for that purpose, on the fiduciary's documented instructions. A vague "as needed to provide the Services" is not a scope, it is an open door.
2. Security safeguards. Section 8(5) requires the fiduciary to take "reasonable security safeguards to prevent personal data breach." The statute only says "reasonable," which is not a standard you can point to later. Name one in the contract: encryption at rest and in transit, access controls, audit logging, or a recognised framework like ISO 27001.
3. Breach notification, both directions. Section 8(6) requires the fiduciary to give the Board and each affected Data Principal "intimation of such breach in such form and manner as may be prescribed." The DPDP Rules, 2025 (notified 14 November 2025) fix the clock: an immediate, "without delay" alert to the Board, a detailed report within 72 hours, and "without delay" notice to Data Principals (Rule 7), starting from when the fiduciary becomes aware. If a vendor sits on a breach for three days before mentioning it, that window is already half gone. The contract needs a processor-to-fiduciary deadline well inside 72 hours, commonly 24 to 48 hours, since the Act sets none on that leg itself.
4. Sub-processor flow-down. The DPDP Act does not require sub-processor consent the way GDPR's Article 28(2) does. Left silent, an Indian processor is generally free to hand your data to a sub-contractor without telling you. Fix it: require prior written consent before engaging any sub-processor, bound in writing to obligations at least as strict as the head agreement.
5. Deletion and return on exit. Section 8(7) requires the fiduciary to erase personal data once consent is withdrawn or the purpose is served, and to "cause its Data Processor to erase any personal data that was made available... for processing," unless another law requires retention. Put a number on it: delete or return within a stated number of days of termination, with written confirmation.
6. Assistance with Data Principal rights. Chapter III gives a Data Principal rights to access, correct, and erase their data. When that request lands on the fiduciary and the data sits with a processor, the fiduciary needs the processor's help fast. Commit to a specific response time, not goodwill.
7. Cross-border transfer. Section 16 permits transfer out of India by default, except to a country the Central Government specifically restricts by notification, none exist yet. "The statute allows it" is not "the contract addresses it." State where the processor may process the data, and require notice before that location changes, since a future restricted-country notification could turn a compliant setup into a non-compliant one overnight.
Consent and notice: what the contract has to assume
Two more sections shape drafting even though they sit upstream of the fiduciary-processor relationship. Section 6(1) sets the standard for valid consent:
"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose."
Source: Section 6, Digital Personal Data Protection Act, 2023 (Indian Kanoon). A pre-ticked checkbox does not meet that bar. Section 5 requires every consent request to be "accompanied or preceded by a notice," itemising the data collected, the purpose, and how to withdraw consent. If your data flow relies on customer consent, say, a SaaS product collecting end-user data for a client, the client, as fiduciary, owes that notice, and the contract should say who drafts and hosts it, since invalid upstream consent undermines the whole downstream arrangement.
Significant Data Fiduciary: extra duties that flow into contracts
Section 10 lets the Central Government designate certain fiduciaries as Significant Data Fiduciaries (SDFs), based on the volume and sensitivity of data processed, risk to Data Principals' rights, and impact on India's sovereignty or electoral integrity, catching in practice large processors of financial, health, or biometric data. An SDF under Section 10(2) must appoint an India-based Data Protection Officer reporting to the board, appoint an independent data auditor, and run a periodic Data Protection Impact Assessment (DPIA), which Rule 13 of the DPDP Rules, 2025 requires once every twelve months from designation.
If either contracting party is, or could become, an SDF, build in audit cooperation (the SDF's auditor may need to review how a processor handles the data) and DPIA input, now, before the designation makes it an urgent gap.
Penalties: what "up to Rs 250 crore" actually means
Penalties are civil, imposed by the Data Protection Board under Section 33, and set as fixed rupee ceilings in the Schedule, not a percentage of turnover the way GDPR works. The headline figures:
- Failure to take reasonable security safeguards under Section 8(5), the provision that actually causes a breach: penalty up to Rs 250 crore.
- Failure to give the Board or affected Data Principals breach intimation under Section 8(6): penalty up to Rs 200 crore.
- Breach of additional obligations relating to children's data under Section 9: penalty up to Rs 200 crore.
Source: Schedule to Section 33, Digital Personal Data Protection Act, 2023; see the official Act text, Ministry of Electronics and IT and a plain-language walkthrough at dpdpa.com, Section 33. Under Section 33(2), the Board weighs the nature, gravity and duration of the breach, the data type involved, and any mitigation taken, before fixing the actual number within that ceiling. These fall on the Data Fiduciary, Section 8(1) makes that non-negotiable, which is why the contract's indemnity clause, not the Act itself, is what lets a fiduciary recover the cost from a processor whose negligence caused the breach. Check whether your liability clauses carve data-breach losses out of the general cap; a silent cap can leave a Rs 250 crore exposure sitting inside a contract capped at, say, twelve months' fees.
Practical contract checklist
Before you sign or renew any contract where personal data will be processed, confirm:
- Fiduciary and Processor roles are named for this engagement.
- Processing purpose and scope are stated, instructions-only.
- A named security standard appears, not just "reasonable" or "appropriate."
- A breach-notice deadline from processor to fiduciary is stated in hours.
- Sub-processing requires prior written consent and flow-down obligations.
- Deletion or return on termination has a deadline and written confirmation.
- Processing location is stated, with notice required before it changes.
- Assistance with Data Principal requests has a stated response time.
- If either party could become an SDF, audit-cooperation is addressed.
- Liability clauses are checked for whether data-breach losses sit inside the cap.
You can run this checklist against a live document, free, by marking it up clause by clause in Weave, before you send it back for negotiation.
Red flags
| Normal | Red flag | Why it matters |
|---|---|---|
| Contract names the Data Fiduciary and Data Processor | No role allocation anywhere in the agreement | Leaves both sides arguing after a breach about who was responsible under Section 8 |
| Processor bound to act only on documented instructions | "As needed to provide the Services," undefined | Opens the door to repurposing data for the vendor's own analytics or training |
| A named security standard: encryption, access controls, ISO 27001 | Only "reasonable" or "appropriate" safeguards | Section 8(5) itself only says "reasonable"; an undefined term adds nothing beyond the statute's floor |
| Breach notice to fiduciary within a stated short window (24-48 hrs) | No deadline, or "promptly," with no number | The fiduciary's own 72-hour clock to the Board starts on becoming aware; a slow processor eats that window |
| Sub-processing needs prior written consent and flow-down terms | Unrestricted right to sub-contract | Data ends up with a party the fiduciary never vetted, with no contractual hook to reach them |
| Deletion or return required on termination, with confirmation | "In accordance with our standard retention policy" | Section 8(7) requires the fiduciary to cause the processor to erase data; an unreachable ex-vendor makes this operational |
| Contract states processing location, notice on any change | Cross-border location left unaddressed | Section 16 permits transfer by default, but a silent contract gives no visibility if a restricted-country list is later notified |
| Data-breach losses addressed within the liability cap | Liability clause silent on breaches, general cap applies | A Rs 250 crore exposure can sit inside a contract capped at a year's fees, with no route to recover the rest |
Bad clause, and a better one
Bad: "Vendor shall keep Customer data confidential and comply with applicable data protection laws."
This says nothing the DPDP Act requires: no role allocation, no instructions-only limit, no security standard, no breach-notice timeline, no sub-processor control, no deletion obligation, no processing location. It could have been written before the Act existed, and reads like it was.
Better: "For the purposes of the Digital Personal Data Protection Act, 2023, Customer is the Data Fiduciary and Vendor is the Data Processor for personal data processed under this Agreement. Vendor shall process such data solely on Customer's documented instructions and solely to provide the Services, and shall not use it for any other purpose without Customer's prior written consent. Vendor shall implement reasonable security safeguards including encryption at rest and in transit, role-based access controls, and audit logging. Vendor shall not engage a sub-processor without Customer's prior written consent, and shall bind any approved sub-processor to obligations no less protective than this clause. Vendor shall process personal data only within [India / named jurisdictions] and give Customer 30 days' written notice before processing it elsewhere. On becoming aware of a personal data breach, Vendor shall notify Customer without delay and in any event within 24 hours, with sufficient detail for Customer to meet its obligations under Section 8(6). Vendor shall provide reasonable assistance, within 5 business days, with any request Customer receives from a Data Principal under Chapter III of the Act. On termination, Vendor shall, at Customer's election, delete or return all personal data and confirm deletion in writing within 30 days, except where retention is required by law. Losses arising from Vendor's breach of this clause shall not be subject to the general limitation of liability in Clause [X]."
What changed: every clause element above is now present with a number attached, not an adjective, and the last sentence pulls data-breach exposure out from under the general liability cap, so the Rs 250 crore Schedule risk has somewhere to land contractually.
US and global contrast
The US has no single federal statute comparable to the DPDP Act. It runs sectorally, HIPAA for health data, GLBA for financial data, layered with state laws like the California Consumer Privacy Act, so a US vendor contract satisfies whichever sector or state law applies, not one unified framework.
The EU's GDPR is the closer comparison, and more prescriptive. Article 28 lists mandatory processor-contract terms directly in the statute: sub-processor authorisation, audit rights, breach-assistance. The DPDP Act leaves most of that to the contract and the Rules, so a DPDP-only contract repeating the Act's language is thinner than a GDPR-compliant one by default. Cross-border transfer is the sharpest contrast: GDPR restricts transfers unless pre-approved, while Section 16 permits transfer unless specifically restricted, none are yet, which is exactly why an Indian contract needs to say more about location than a GDPR clause has to.
FAQ
Do I need a separate Data Processing Agreement, or can this sit inside my main contract? The Act does not mandate a standalone document. Section 8(2) requires "a valid contract," and the required terms can sit inside the main services agreement as a clause or schedule. Larger, higher-risk engagements typically move these into a dedicated DPA; see Data Processing Agreement (DPA) Clauses Explained for India.
Which contracts actually need DPDP terms added? Any contract under which personal data will be processed by the other party: SaaS agreements, payroll and HR vendor contracts, marketing agencies, IT support, and outsourcing contracts. A pure equipment-supply contract with no personal data involved generally does not need this clause.
What penalty applies if my vendor causes a data breach? The Board can penalise the Data Fiduciary, not the vendor directly, up to Rs 250 crore under the Schedule to Section 33 for failing security safeguards under Section 8(5), since Section 8(1) makes the fiduciary responsible for processing done on its behalf. A well-drafted indemnity clause is what lets the fiduciary recover that cost from the vendor.
Is my company a Data Fiduciary or a Data Processor? It depends on the data and relationship, not your industry. Deciding why and how data is processed makes you the Data Fiduciary for that data under Section 2(j); processing on someone else's instructions makes you the Data Processor under Section 2(k). A single company is commonly both.
What triggers Significant Data Fiduciary obligations, and do they affect my vendor contracts? Designation under Section 10 depends on factors the government sets, including the volume and sensitivity of data processed and the risk to Data Principals. If either party could be designated, build audit-cooperation and DPIA-input obligations into the contract now, since an SDF's auditor and DPIA under Rule 13 will need information from any processor handling that data.
Does the DPDP Act apply if the substantive provisions are not fully in force yet? The Act and Rules are notified, and commencement is staggered through 14 May 2027. Contracts signed now will typically still be running when the obligations take effect, so building these clauses in now avoids renegotiating a live contract later.
This guide gets you to understanding what the DPDP Act requires your contracts to say, and a checklist to work through before you sign. It does not tell you whether your specific contract or data flows meet your compliance obligations, that depends on facts a lawyer needs to review, and is not legal advice. Talk to a lawyer before you finalise DPDP-related terms in a contract that matters.
Frequently asked questions
- Do I need a separate Data Processing Agreement, or can this sit inside my main contract?
- The DPDP Act does not mandate a standalone document. Section 8(2) requires 'a valid contract,' and the required terms, processing scope, security, breach notice, deletion, can sit inside the main services agreement as a clause or schedule. Larger, higher-risk engagements typically move these terms into a dedicated Data Processing Agreement for clarity.
- Which contracts actually need DPDP terms added?
- Any contract under which personal data, employee, customer, patient, or user data, will be processed by the other party: SaaS agreements, payroll and HR vendor contracts, marketing and analytics agencies, IT support and managed-services agreements, and outsourcing contracts. A pure equipment-supply or construction contract with no personal data involved generally does not need this clause.
- What penalty applies if my vendor causes a data breach?
- The Data Protection Board can penalise the Data Fiduciary, not the vendor directly, up to Rs 250 crore under the Schedule to Section 33 for failing to take reasonable security safeguards under Section 8(5), because Section 8(1) makes the fiduciary responsible for processing done on its behalf. A well-drafted indemnity clause is what lets the fiduciary recover that cost from the vendor; the DPDP Act itself does not create that recovery route.
- Is my company a Data Fiduciary or a Data Processor?
- It depends on the specific data and relationship, not your industry. If you decide why and how personal data is processed, you are the Data Fiduciary for that data under Section 2(j) of the DPDP Act. If you process it on someone else's instructions for their purposes, you are the Data Processor under Section 2(k), for that same data. A single company is commonly both: fiduciary for its own employee records, processor for a client's customer data it handles under a service contract.
- What triggers Significant Data Fiduciary obligations, and do they affect my vendor contracts?
- Designation under Section 10 depends on factors the Central Government sets, including the volume and sensitivity of personal data processed and the risk to Data Principals' rights. If either party could be designated a Significant Data Fiduciary, build audit-cooperation and DPIA-input obligations into the contract now: an SDF's independent auditor and periodic Data Protection Impact Assessment under Rule 13 of the DPDP Rules, 2025 will need information from any processor handling that data.
- Does the DPDP Act apply if the substantive provisions are not fully in force yet?
- The Act and the DPDP Rules, 2025 are notified, and commencement of the operative provisions is staggered through 14 May 2027 on the government's own timeline. Contracts signed now will typically still be running when the obligations, consent, security, breach notice, take effect, so building these clauses in now avoids renegotiating a live contract later.
Sources
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), official text, Ministry of Electronics and IT
- Section 6, Digital Personal Data Protection Act, 2023 (Consent) - Indian Kanoon
- Section 10, Digital Personal Data Protection Act, 2023 (Additional obligations of Significant Data Fiduciary) - Indian Kanoon
- Section 33 and Schedule, Digital Personal Data Protection Act, 2023 (Penalties by Board), dpdpa.com
- Digital Personal Data Protection Rules, 2025, notified 14 November 2025 (PIB press release)
- Article 28, GDPR (Processor)
- Data Protection Clauses in Indian Contracts Under the DPDP Act - Adira Journal
- Data Processing Agreement (DPA) Clauses Explained for India - Adira Journal
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free