DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

A BPO handling personal data on behalf of a client is a Data Processor under the DPDP Act 2023, not the Data Fiduciary — but this does not mean the BPO has no obligations. The client's contract with the BPO must specify what processing is permitted, and the BPO must process data strictly within those terms, implement adequate security safeguards, and notify the client promptly of any breach so the client can meet its own Data Protection Board notification timeline. This checker scores how well your BPO's client-data handling matches these processor obligations.

BPO Client Data Handling Under DPDP Act 2023

As a Data Processor, your obligations flow from your client contracts. Check how your BPO's data handling stacks up in 3 minutes.

Check your BPO's client data handling

DPDP checklist for BPOs handling client personal data

Data Processor obligations flow from the contract, not from the DPDP Act directly

A key structural feature of the DPDP Act is that most direct statutory obligations — notice, consent, breach notification to the regulator — fall on the Data Fiduciary. A BPO acting as a Data Processor for a client is bound by whatever the contract between them says. This makes the data processing agreement (DPA) the single most important compliance document for a BPO, because it is where processing scope, security requirements, sub-processor rules, and breach notification timelines are actually defined.

This does not mean BPOs are off the hook if something goes wrong. Clients — especially larger enterprise clients — are increasingly building DPDP-specific clauses into their vendor contracts and running security questionnaires before signing. A BPO that cannot produce a clear data processing agreement, evidence of access controls, and a tested breach notification process will struggle to win or retain enterprise engagements, independent of any regulatory risk.

Why breach notification speed matters more for BPOs than it seems

When a breach happens on a BPO's systems, the client (as Data Fiduciary) is the one accountable to the Data Protection Board within the notification timelines set out in the DPDP Rules 2025. That timeline starts running regardless of how quickly the BPO tells the client. A BPO with no documented, tested breach notification process can eat up hours or days of a client's limited response window simply figuring out what happened — turning a processor-side technical incident into a client-side regulatory failure. Niti Bharat's BPO/KPO Processor Pack builds this notification process, along with the client-facing DPA template and access-control baseline BPOs need for enterprise client audits.

Get the BPO Client DPA Checklist (free)

A practical checklist covering what a client-specific data processing agreement should include, and how to structure breach notification timelines.

Frequently Asked Questions

Is a BPO a Data Fiduciary or a Data Processor under DPDP?+
Almost always a Data Processor, since the BPO processes personal data on behalf of and under the instructions of its client, who determines the purpose. The client remains the Data Fiduciary with primary accountability, but the BPO has real contractual obligations under the DPA.
Can a BPO be penalised directly by the Data Protection Board?+
The DPDP Act's direct penalty provisions are structured primarily around Data Fiduciary obligations, but a BPO's failures can trigger penalties for its client and expose the BPO to contract termination, liability claims, and reputational damage that affects future client wins — the practical exposure is significant even where direct regulatory penalties are less clear-cut.
Do BPOs need their own privacy policy if they only process client data?+
Yes, at minimum covering their own employees' data and any data collected in their own right (e.g., website visitors, job applicants). For client data processed under a DPA, the client's own privacy notice to their end customers should reference that a processor is used.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
CA Firm DPDP Services IndiaChildren's Data Compliance AssessmentClient DPDP Risk Screener for CA Firms IndiaPayment Gateway Data Protection GuideSee all Reference & Checklists tools →📝 What Is Data Fiduciary DPDP📝 ICAI Data Breach DPDP