If you process personal data on behalf of another company, you are a Data Processor. Here is what the DPDP Act requires of you — and what your contracts must say.
The DPDP Act does not prescribe a standard DPA format, but a compliant DPA must at minimum: define the scope and purpose of processing, specify what personal data is being processed, set out security standards required of the Processor, include breach notification timelines and escalation paths, address sub-processor authorisation, specify data deletion/return obligations, and include audit rights for the Fiduciary.
NitiBharat's Vendor DPA Review service audits your existing contracts and provides a model DPA clause library for use with clients and vendors.
India's BPO and KPO sector processes personal data on behalf of clients worldwide — customer records, HR data, financial data, health information. Under the DPDP Act, every engagement where you process Indian personal data on a client's behalf triggers Data Processor obligations. The good news: if you already comply with GDPR Article 28 (processor requirements), you have a strong foundation — but DPDP-specific breach timelines and DPA requirements will still need updating.
A clause-by-clause DPA checklist for Data Processors under the DPDP Act 2023, with what each clause must cover and common drafting gaps.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.