Third-Party Vendor Risk Under DPDPA: What You Must Contractually Require of Processors
Every cloud provider, SaaS platform, and data partner you use is a Data Processor. Under DPDPA, your contracts with them must now say much more than they currently do.

Why Vendor Contracts Require a DPDPA Review
Modern businesses rely on a growing network of vendors that process personal data across CRM systems, email platforms, cloud storage, payment gateways, analytics tools, and AI systems. Under the DPDPA, maintaining visibility into these vendors is an important part of vendor compliance and data governance.
Under the Digital Personal Data Protection Act, 2023, vendors that process personal data on behalf of a Data Fiduciary may qualify as Data Processors. Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. When Section 8 becomes operative, the Data Fiduciary will remain responsible for compliance in respect of processing undertaken by it or on its behalf by a Processor, irrespective of any agreement to the contrary.
The DPDP framework is being implemented in phases. The substantive obligations discussed in this article under Section 8 and Rules 6, 7, 8 and 15 are scheduled to become operative in May 2027. Organisations can use this transition period to review vendor relationships and strengthen contractual controls. (MeitY)
Many existing vendor contracts were drafted before these requirements were finalised. Standard SaaS terms may focus primarily on uptime, payment, service delivery, and general security provisions, while areas such as breach escalation, deletion, Processor responsibilities, and sub-processing may require additional review. Assessing these agreements against the DPDPA helps identify contractual gaps before the operational requirements take effect.
What Qualifies as a Data Processor Under DPDPA?
Section 2(k) sets a broad test. An entity that processes personal data on behalf of a Data Fiduciary may qualify as a Data Processor under DPDPA, regardless of how the relationship is labelled commercially.
This can include CRM platforms, email marketing tools, cloud storage providers, analytics services, support desks holding chat logs, payment processors, data warehouses, and AI vendors that process personal data on behalf of an organisation.
The distinction between Data Fiduciary and Data Processor turns on who determines the purpose and means of processing. Section 2(i) assigns that role to the Data Fiduciary. Where a Processor independently determines the purpose and means of a processing activity, its role may need to be reassessed under the Act.
What Should DPDPA Vendor Contracts Cover?
Section 8(2), once operative, requires a valid contract when a Data Fiduciary engages a Data Processor for processing connected with offering goods or services to Data Principals.
Existing master service agreements should therefore be reviewed to confirm that their data-processing provisions address the obligations relevant to the vendor relationship. Where needed, organisations can use a formal Data Processing Agreement or appropriate contractual clauses to define processing instructions, security responsibilities, breach escalation, deletion, and oversight.
Scope of processing. The agreement should clearly define the processing activities being undertaken on behalf of the Data Fiduciary and the purposes for which personal data may be processed.
Security obligations. From May 2027, Rule 6 of the DPDP Rules, 2025 will require reasonable security safeguards. These include appropriate data-security measures, access controls, logging and monitoring, continuity measures, and contractual provisions addressing security safeguards where processing is carried out by a Data Processor.
Breach notification. Rule 7 will require the Data Fiduciary to notify affected Data Principals without delay and intimate the Data Protection Board without delay after becoming aware of a personal data breach. Specified detailed information must then be provided to the Board within seventy-two hours, unless the Board permits a longer period. Vendor contracts should therefore establish prompt Processor-to-Fiduciary breach notification and escalation procedures.
Retention and deletion. Section 8(7) provides for erasure when consent is withdrawn or the specified purpose is no longer being served, unless retention is necessary for compliance with law. It also requires the Data Fiduciary to cause its Processor to erase relevant personal data made available for that processing. The final Rules also prescribe retention requirements for certain personal data and processing logs, so vendor contracts should address both deletion and applicable retention obligations.
Sub-processor controls. The Act and Rules do not prescribe a detailed sub-processor approval framework. Organisations may therefore choose to address sub-processing through contractual provisions covering disclosure, notification or approval mechanisms, security requirements, accountability, and flow-down obligations.
Oversight and cross-border processing. Organisations may also include suitable assessment, reporting, or audit rights to verify contractual obligations. Where vendors are involved in transferring or processing personal data outside India, agreements should account for applicable requirements under Section 16 and Rule 15 once those provisions become operative.
The Sub-Processor Gap
Processors rarely operate alone. Many rely on their own vendors, including cloud infrastructure providers and specialised technology services beneath the primary service.
Sub-processors can extend the processing chain beyond the vendor named in the primary agreement, making visibility and contractual flow-down important elements of third-party risk management.
Organisations can address this through clear contractual controls covering disclosure, oversight, security obligations, and responsibility across the processing chain. Every Data Processing Agreement should define how sub-processing will be managed where it is relevant to the service.
How to Prioritise a DPDPA Vendor Contract Review
A risk-based review allows organisations to prioritise vendor contracts according to the nature, volume, purpose, and location of the personal data being processed.
Begin with vendors handling higher-risk data or processing activities, including health or financial information, large volumes of personal data, operationally critical systems, and vendors involved in processing or transferring personal data outside India.
For higher-risk vendors, organisations should consider a formal Data Processing Agreement aligned with the applicable DPDPA requirements and include the review within their broader vendor compliance management and data governance processes.
Lower-risk vendors can follow a proportionate review process. Where the vendor qualifies as a Data Processor within Section 8(2), however, the processing relationship will still need to be governed by a valid contract once the provision becomes operative.
Vendor Compliance Is Ongoing
DPDPA vendor compliance works best as an ongoing governance process because vendor relationships and processing activities change over time.
New vendors enter the technology stack as teams adopt new platforms, services, and tools. Each relationship should be assessed to determine whether the vendor acts as a Data Processor and what contractual controls apply before personal data begins to flow.
Embedding this review into vendor onboarding reduces the volume of retroactive work required later. Linking onboarding with third-party risk management, contract review, processing inventories, and data governance also gives compliance teams better visibility into how personal data moves through the organisation.
Accountability and Penalties
Once the relevant provisions become operative, Section 8 will place accountability on the Data Fiduciary for processing undertaken by it or on its behalf, making effective Processor oversight an important part of DPDPA compliance.
A breach of the reasonable security safeguards obligation under Section 8(5) may attract a penalty of up to ₹250 crore under the Schedule to the Act. Failure to meet the breach-notification obligation under Section 8(6) may attract a penalty of up to ₹200 crore, while breach of another provision not separately listed may attract a penalty of up to ₹50 crore.
Existing master service agreements should therefore be assessed specifically against Section 8(2) and the applicable DPDP Rules to confirm that relevant Processor obligations are adequately covered.
Vendor governance forms one part of a broader DPDPA operating model. Organisations reviewing their wider consent infrastructure can also refer to OneConsent’s guide on how to implement a consent management system under the DPDP Act. The guide covers consent records, processing systems, withdrawals, integration, and broader consent governance.
Strong contracts address one part of DPDPA readiness. Organisations also need visibility into consent status, processing purposes, third-party relationships, and records showing how personal data moves through their systems. A consent management platform can support this governance by connecting consent records, processing activities, and audit evidence within a more structured data governance framework.
For organisations looking to strengthen consent management and maintain better visibility across vendors and data-processing activities, OneConsent provides infrastructure designed to support DPDPA compliance. Request a demo to explore how OneConsent can support a more structured and auditable approach to consent and data governance.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.