Digital & E-Commerce Legal Support7 min readUpdated 18 June 2026

Data Processing Agreement Under DPDP Act: India 2025

Draft a DPDP Rules 2025-compliant DPA - fiduciary vs processor & breach notification. Expert help in Surat, Gujarat.

Tirth Inamdar, founder of Inamdar Legal

Tirth Inamdar

Founder · Inamdar Legal

Founder-reviewed legal guidanceSurat · India · Global clients

India's Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changed the obligations of any business that collects, processes, or transfers personal data. For businesses that engage third parties to process personal data on their behalf - cloud service providers, payroll processors, marketing analytics platforms, customer support software - a Data Processing Agreement (DPA) is now not just good practice but a compliance requirement. This article covers what the DPDP Act requires of data fiduciaries and data processors, what a DPDP-compliant DPA must contain, and the specific provisions Indian businesses must pay attention to.

The Dpdp Act 2023: Core Concepts

DATA PRINCIPAL: The individual to whom the personal data relates. The data principal has rights under the Act: the right to access information about processing, the right to correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise rights on their behalf. DATA FIDUCIARY: Any person who determines the purpose and means of processing personal data. In a typical business context, the business that collects data from customers, employees, or users is the data fiduciary. The data fiduciary has primary compliance obligations under the Act - obtaining consent, implementing security measures, appointing a Data Protection Officer (if a Significant Data Fiduciary), and establishing grievance redressal mechanisms. DATA PROCESSOR: Any person who processes personal data on behalf of a data fiduciary. A payroll software company processes employee data on behalf of the employer (data fiduciary). A cloud hosting provider processes customer data stored by a SaaS company (data fiduciary). Under the DPDP Act, data processors process data under a contract with the data fiduciary and must follow the data fiduciary's instructions. SIGNIFICANT DATA FIDUCIARY: A data fiduciary notified as such by the Central Government based on the volume and sensitivity of data processed, the risk to data principals, national security implications, and other factors. Significant Data Fiduciaries have additional obligations including appointing a Data Protection Officer, an independent data auditor, and conducting data protection impact assessments.

When Is A Data Processing Agreement Required?

Under Section 8(2) of the DPDP Act, a data fiduciary may engage a data processor to process personal data on its behalf only pursuant to a valid contract. Without a written contract, the engagement of any third party to process personal data violates the Act.

A Dpa Is Required Whenever:

A business (data fiduciary) engages a cloud service provider, SaaS platform, payroll processor, customer support tool, marketing analytics service, or any other third party that processes personal data the business has collected A software company (data fiduciary) uses sub-processors - third-party services that process user data as part of the software's functionality

Purpose And Scope Of Processing

The DPA must specify exactly what personal data the processor will process, for what purpose, and on what legal basis. The processor may not process personal data for any purpose beyond what is specified in the DPA. Any instruction from the data fiduciary that would cause the processor to violate the DPDP Act must be refused by the processor and notified to the data fiduciary.

Under The Dpdp Act, The Data Processor'S Obligations Include:

Processing personal data only on documented instructions from the data fiduciary Implementing appropriate security safeguards to protect the personal data Notifying the data fiduciary of any personal data breach (without undue delay - and the data fiduciary must notify the Data Protection Board of India and affected data principals of significant breaches) Not engaging sub-processors without the data fiduciary's prior written consent Returning or deleting all personal data on termination of the DPA (at the data fiduciary's choice) Making available all information necessary to demonstrate compliance with the Act's requirements

Security Measures

The DPA must require the data processor to implement appropriate technical and organisational security measures to protect the personal data. The DPDP Act does not prescribe specific technical standards, but the data fiduciary must ensure that the processor's security practices are adequate for the sensitivity of the data being processed. Key security provisions to include: Encryption of personal data at rest and in transit Access controls - limiting access to personal data to authorised personnel with a need-to-know Regular security audits and penetration testing Incident response procedures Employee training on data protection

Data Breach Notification

The DPA must require the data processor to notify the data fiduciary of any personal data breach - a breach of security leading to accidental or unauthorised destruction, loss, alteration, disclosure of, or access to, personal data - as quickly as possible and no later than a specified period after the processor becomes aware. The DPDP Act requires the data fiduciary to notify the Data Protection Board of India of significant breaches; the DPA ensures the data fiduciary receives timely information to fulfil this obligation.

Sub-Processors

The DPA must address whether the data processor may engage sub-processors to assist in processing the data fiduciary's personal data. Typical provisions: The processor may not engage sub-processors without the data fiduciary's prior written consent The processor must impose on sub-processors the same obligations that the DPA imposes on the processor The processor remains liable to the data fiduciary for the acts and omissions of sub-processors

When to obtain a review

A review is especially useful when…

  • You are about to sign, send, rely on or respond to this document.
  • The draft was copied from an old template or another state.
  • There is money, property, business control, statutory deadline or reputation risk involved.
  • You need Surat/Gujarat-specific drafting, review or negotiation support.

Legal information notice

This article is general legal information for India and Gujarat. It is not a substitute for advice on your specific facts, documents, limitation period, stamp duty position or court strategy.

Questions, answered clearly

Common questions

Do I need a lawyer for data processing agreement under dpdp act in Surat?+

You should consider legal help when money, property, business rights, statutory timelines, compliance exposure or future enforcement is involved. A lawyer can tailor the document or notice to the facts instead of relying on a generic template.

Is a template enough for this document?+

A template may help with structure, but it often misses party-specific facts, Gujarat stamp or registration issues, statutory timelines, evidence requirements and negotiation points. Use it only after checking whether it fits the transaction.

What should I share before asking Inamdar Legal to review or draft it?+

Share the existing draft, transaction summary, dates, payment details, party information, supporting documents and the exact concern you want addressed. For urgent notices, also share the limitation or statutory deadline.

A practical next step

Need Help With Data Processing Agreement under DPDP Act In Surat?

Share the draft, documents and timeline. Inamdar Legal can help review, redline or prepare data processing agreement under dpdp act with Surat and Gujarat-specific legal checks.