Commercial Contracts

Data Processing Agreement (DPDP)

A processing agreement is only as good as the instructions in it. Draft the schedule describing what is processed, why, and for how long with real care — a well-drafted set of obligations attached to a vague description of the processing protects nobody.

Download as Word12 pages31 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Data Processing Agreement

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

A processing agreement is only as good as the instructions in it. Draft the schedule describing what is processed, why, and for how long with real care — a well-drafted set of obligations attached to a vague description of the processing protects nobody.

This Data Processing Agreement (this "DPA") is made at [PLACE OF EXECUTION] on [DATE] (the "Effective Date").

BY AND BETWEEN

[DATA FIDUCIARY NAME], a company incorporated under the Companies Act, 2013 bearing CIN [CIN], having its registered office at [REGISTERED OFFICE ADDRESS] (the "Data Fiduciary") of the ONE PART;

AND

[DATA PROCESSOR NAME], [CONSTITUTION] bearing [CIN / LLPIN], having its registered office at [REGISTERED OFFICE ADDRESS] (the "Data Processor") of the OTHER PART.

Recitals

A.The Parties have entered into an agreement dated [DATE OF PRINCIPAL AGREEMENT] for the provision of [DESCRIBE SERVICES] (the "Principal Agreement").

B.In the course of providing services under the Principal Agreement, the Data Processor will process personal data on behalf of the Data Fiduciary.

C.Section 8(2) of the Digital Personal Data Protection Act, 2023 permits a Data Fiduciary to engage a Data Processor to process personal data on its behalf only under a valid contract. This DPA is that contract.

D.The Parties record that the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and are being brought into force in phases, with the principal substantive obligations relating to notice, consent, security safeguards, breach intimation, retention and Data Principal rights taking effect on 13 May 2027. The Parties intend this DPA to operate on a compliant basis from the Effective Date.

NOW THEREFORE the Parties agree as follows:

1. Definitions

1.1Terms defined in the Act have the same meaning in this DPA. In particular:

(a)"Act" means the Digital Personal Data Protection Act, 2023;

(b)"Rules" means the Digital Personal Data Protection Rules, 2025 notified under Section 40 of the Act;

(c)"Board" means the Data Protection Board of India constituted under Section 18 of the Act;

(d)"Data Principal" means the individual to whom the Personal Data relates, and where the individual is a child, includes the parent or lawful guardian;

(e)"Personal Data" means any data about an individual who is identifiable by or in relation to such data, processed by the Data Processor on behalf of the Data Fiduciary under the Principal Agreement, as described in Annexure A;

(f)"Personal Data Breach" means any unauthorised processing of Personal Data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to Personal Data, that compromises its confidentiality, integrity or availability;

Generated from www.helionerp.com1

11 more pages in the Word file

Preview of the first page. Highlighted fields are the ones you fill in — they appear the same way in Word. Scroll the preview to read on; the full document runs to 12 pages.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Why this document is mandatory

Section 8(2) of the DPDP Act, 2023 permits a Data Fiduciary to engage a Data Processor only under a valid contract. A services agreement with a one-line confidentiality clause is not that contract. If you share personal data with a payroll bureau, a recruitment agency, a cloud provider, a support vendor or an offshore delivery arm, this document is the instrument that authorises it.

Commencement timeline

The Rules were notified on 13 November 2025 and commence in phases: definitions and the Data Protection Board from 13 November 2025; the Board’s enforcement and penalty powers and Consent Manager registration from 13 November 2026; and the substantive obligations on notice, consent, security safeguards, breach intimation, retention and Data Principal rights from 13 May 2027. Contracts signed today will be running when those obligations bite, so sign the compliant version now rather than repapering later.

Annexure A is the document

The clauses matter, but Annexure A is what auditors, counterparties and the Board will actually read. A DPA with an empty or generic Annexure A provides no protection, because the scope of authorised processing is undefined. It is set out in landscape so that seven columns remain legible — add rows, do not compress. Anything not listed there is unauthorised processing.

Twenty-four hours, not "promptly"

The Data Fiduciary’s own intimation obligations run on a short clock once it becomes aware of a breach. A processor who reports "without undue delay" consumes the whole of that clock. Clause 8.1 fixes twenty-four hours and Clause 8.3 forbids waiting for a complete investigation. Resist any request to soften either.

Log retention

Rule 8(3) carries a general obligation to retain personal data, associated traffic data and processing logs for a minimum of one year. This is not limited to government bodies. Clause 5.1(c) and Clause 9.3 reflect it — check that your processor’s log rotation is not set to thirty days.

Sub-processors

Most breaches in practice occur at the fourth party, not the third. Annexure C should include hosting, support, analytics and the processor’s own offshore group entities. If the processor will not name them, that is itself information about the level of control it exercises.

Liability carve-out

Clause 13.3 disapplies the general liability cap in the principal agreement to data protection liability, because a ₹250 crore penalty exposure sitting under a cap of twelve months’ fees is not a meaningful allocation of risk. Expect this to be negotiated; a separate, higher super-cap for data protection is the usual landing point.

Cross-border transfer

Section 16 of the Act operates on a negative-list basis — transfer is permitted except to countries restricted by the Central Government. That is more permissive than many international frameworks, but sectoral localisation rules, including for payments data, continue to apply independently. Record the actual countries in Annexure A.

If you are the processor

Read Clause 4.1(a) before signing. It prohibits use of the data for your own product development, analytics, benchmarking or model training. If your business model depends on any of those, negotiate it expressly and specifically — do not sign and hope.

Current as of

Reflects the DPDP Act, 2023 and the DPDP Rules, 2025 as at {{DATE OF USE}}. The phased commencement dates and any subsequent direction of the Board should be checked before you rely on this document.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, company secretary, or chartered accountant as relevant) before you rely on it.