What must a cloud services DPA cover under the DPDP Act? A cloud services Data Processing Agreement under the DPDP Act 2023 must set out the processor's obligations in writing, as required by Section 8(2): the scope and purpose of processing, security safeguards matching the sensitivity of the data hosted, sub-processor consent and flow-down obligations, breach notification timelines to the client Data Fiduciary, and guaranteed deletion or return of data on contract termination. Because the Data Fiduciary remains liable for its processors' conduct, this agreement is the mechanism that shifts operational accountability onto the cloud provider while keeping the client legally covered.
Generate an India-compliant DPA for your cloud, hosting or managed services relationship — processor obligations, sub-processor rules, security schedule and deletion clauses.
This Agreement is entered into between [Client / Data Fiduciary] and [Cloud Provider / Data Processor] and governs all personal data processed by the Provider on the Fiduciary's behalf in connection with the cloud, hosting or managed services described in the Order Form or Statement of Work. For the purposes of the Digital Personal Data Protection Act, 2023 ('DPDP Act'), the Client is the Data Fiduciary and remains the party ultimately accountable to Data Principals and the Data Protection Board; the Provider acts strictly as a Data Processor, processing personal data only on the Fiduciary's documented instructions.
This clause also fixes the categories of personal data in scope (based on your intake: [auto-populated — general business data, customer PII, employee data, financial data, or sensitive personal data]), the purpose of processing (hosting, storage, computation or management of the Client's systems), and confirms that the Provider has no independent right to use, disclose or repurpose the personal data outside the scope defined here — addressing the Section 8(2) requirement that a Data Fiduciary's use of a processor be governed by a valid contract.
The Provider shall process personal data solely on the documented instructions of the Client, including with regard to transfers of personal data to a third country or international organisation, unless required to do so by Indian law — in which case the Provider shall inform the Client of that legal requirement before processing, unless prohibited from doing so. The Provider shall ensure that all personnel authorised to process the personal data are subject to a binding duty of confidentiality.
The Provider acknowledges that the Client remains liable under the DPDP Act for the Provider's processing of personal data on its behalf, and accordingly agrees to the security, audit, breach notification and deletion obligations set out in Clauses 3–7 of this Agreement, which operationalise the Client's ability to demonstrate reasonable security safeguards under Section 8 of the DPDP Act.
Safeguards selected for your Cloud DPA security schedule:
Under Section 8(2) of the DPDP Act 2023, a Data Fiduciary may only engage a Data Processor — including a cloud, hosting or managed services provider — under a valid contract. Generic MSAs or cloud terms-of-service drafted for GDPR or for generic Indian commercial law rarely include the specific elements a DPDP-aligned DPA needs: a documented processing scope, sub-processor consent mechanics, a breach notification clock tight enough to feed the Fiduciary's own 72-hour DPB obligation, and guaranteed deletion on termination.
This gap is especially costly because the Data Fiduciary remains liable for its processor's conduct — if your cloud provider suffers a breach and your only contract is a standard SaaS terms-of-service, you have little to point to when the Data Protection Board asks what safeguards you put in place. With enforcement approaching around May 2027, companies renewing or signing new cloud and hosting contracts should insist on a DPDP-specific DPA rather than relying on the provider's boilerplate.
Either party can and should generate this from their own vantage point. Cloud and managed services providers benefit from offering a ready DPDP-compliant DPA proactively — it shortens enterprise sales cycles and answers security questionnaires before they're asked. Clients engaging a cloud provider should not accept the provider's standard terms without checking for the specific clauses in Sections 3–7: sub-processor flow-down, a real breach notification timeline, and deletion certification.
Niti Bharat supports both sides of this relationship as part of fixed-price DPDP compliance engagements (₹75,000–₹3,20,000), including full vendor DPA reviews for companies managing dozens of cloud and SaaS relationships at once. Contact hello@nitibharat.com.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.