[HEADER — replace with your organisation’s letterhead, if used]
Data Processing Agreement
Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
A processing agreement is only as good as the instructions in it. Draft the schedule describing what is processed, why, and for how long with real care — a well-drafted set of obligations attached to a vague description of the processing protects nobody.
This Data Processing Agreement (this "DPA") is made at [PLACE OF EXECUTION] on [DATE] (the "Effective Date").
BY AND BETWEEN
[DATA FIDUCIARY NAME], a company incorporated under the Companies Act, 2013 bearing CIN [CIN], having its registered office at [REGISTERED OFFICE ADDRESS] (the "Data Fiduciary") of the ONE PART;
AND
[DATA PROCESSOR NAME], [CONSTITUTION] bearing [CIN / LLPIN], having its registered office at [REGISTERED OFFICE ADDRESS] (the "Data Processor") of the OTHER PART.
Recitals
A.The Parties have entered into an agreement dated [DATE OF PRINCIPAL AGREEMENT] for the provision of [DESCRIBE SERVICES] (the "Principal Agreement").
B.In the course of providing services under the Principal Agreement, the Data Processor will process personal data on behalf of the Data Fiduciary.
C.Section 8(2) of the Digital Personal Data Protection Act, 2023 permits a Data Fiduciary to engage a Data Processor to process personal data on its behalf only under a valid contract. This DPA is that contract.
D.The Parties record that the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and are being brought into force in phases, with the principal substantive obligations relating to notice, consent, security safeguards, breach intimation, retention and Data Principal rights taking effect on 13 May 2027. The Parties intend this DPA to operate on a compliant basis from the Effective Date.
NOW THEREFORE the Parties agree as follows:
1. Definitions
1.1Terms defined in the Act have the same meaning in this DPA. In particular:
(a)"Act" means the Digital Personal Data Protection Act, 2023;
(b)"Rules" means the Digital Personal Data Protection Rules, 2025 notified under Section 40 of the Act;
(c)"Board" means the Data Protection Board of India constituted under Section 18 of the Act;
(d)"Data Principal" means the individual to whom the Personal Data relates, and where the individual is a child, includes the parent or lawful guardian;
(e)"Personal Data" means any data about an individual who is identifiable by or in relation to such data, processed by the Data Processor on behalf of the Data Fiduciary under the Principal Agreement, as described in Annexure A;
(f)"Personal Data Breach" means any unauthorised processing of Personal Data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to Personal Data, that compromises its confidentiality, integrity or availability;