India's Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changed the obligations of any business that collects, processes, or transfers personal data. For businesses that engage third parties to process personal data on their behalf - cloud service providers, payroll processors, marketing analytics platforms, customer support software - a Data Processing Agreement (DPA) is now not just good practice but a compliance requirement. This article covers what the DPDP Act requires of data fiduciaries and data processors, what a DPDP-compliant DPA must contain, and the specific provisions Indian businesses must pay attention to.
The Dpdp Act 2023: Core Concepts
DATA PRINCIPAL: The individual to whom the personal data relates. The data principal has rights under the Act: the right to access information about processing, the right to correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise rights on their behalf. DATA FIDUCIARY: Any person who determines the purpose and means of processing personal data. In a typical business context, the business that collects data from customers, employees, or users is the data fiduciary. The data fiduciary has primary compliance obligations under the Act - obtaining consent, implementing security measures, appointing a Data Protection Officer (if a Significant Data Fiduciary), and establishing grievance redressal mechanisms. DATA PROCESSOR: Any person who processes personal data on behalf of a data fiduciary. A payroll software company processes employee data on behalf of the employer (data fiduciary). A cloud hosting provider processes customer data stored by a SaaS company (data fiduciary). Under the DPDP Act, data processors process data under a contract with the data fiduciary and must follow the data fiduciary's instructions. SIGNIFICANT DATA FIDUCIARY: A data fiduciary notified as such by the Central Government based on the volume and sensitivity of data processed, the risk to data principals, national security implications, and other factors. Significant Data Fiduciaries have additional obligations including appointing a Data Protection Officer, an independent data auditor, and conducting data protection impact assessments.
When Is A Data Processing Agreement Required?
Under Section 8(2) of the DPDP Act, a data fiduciary may engage a data processor to process personal data on its behalf only pursuant to a valid contract. Without a written contract, the engagement of any third party to process personal data violates the Act.
A Dpa Is Required Whenever:
A business (data fiduciary) engages a cloud service provider, SaaS platform, payroll processor, customer support tool, marketing analytics service, or any other third party that processes personal data the business has collected A software company (data fiduciary) uses sub-processors - third-party services that process user data as part of the software's functionality
Purpose And Scope Of Processing
The DPA must specify exactly what personal data the processor will process, for what purpose, and on what legal basis. The processor may not process personal data for any purpose beyond what is specified in the DPA. Any instruction from the data fiduciary that would cause the processor to violate the DPDP Act must be refused by the processor and notified to the data fiduciary.
Under The Dpdp Act, The Data Processor'S Obligations Include:
Processing personal data only on documented instructions from the data fiduciary Implementing appropriate security safeguards to protect the personal data Notifying the data fiduciary of any personal data breach (without undue delay - and the data fiduciary must notify the Data Protection Board of India and affected data principals of significant breaches) Not engaging sub-processors without the data fiduciary's prior written consent Returning or deleting all personal data on termination of the DPA (at the data fiduciary's choice) Making available all information necessary to demonstrate compliance with the Act's requirements
Security Measures
The DPA must require the data processor to implement appropriate technical and organisational security measures to protect the personal data. The DPDP Act does not prescribe specific technical standards, but the data fiduciary must ensure that the processor's security practices are adequate for the sensitivity of the data being processed. Key security provisions to include: Encryption of personal data at rest and in transit Access controls - limiting access to personal data to authorised personnel with a need-to-know Regular security audits and penetration testing Incident response procedures Employee training on data protection
Data Breach Notification
The DPA must require the data processor to notify the data fiduciary of any personal data breach - a breach of security leading to accidental or unauthorised destruction, loss, alteration, disclosure of, or access to, personal data - as quickly as possible and no later than a specified period after the processor becomes aware. The DPDP Act requires the data fiduciary to notify the Data Protection Board of India of significant breaches; the DPA ensures the data fiduciary receives timely information to fulfil this obligation.
Sub-Processors
The DPA must address whether the data processor may engage sub-processors to assist in processing the data fiduciary's personal data. Typical provisions: The processor may not engage sub-processors without the data fiduciary's prior written consent The processor must impose on sub-processors the same obligations that the DPA imposes on the processor The processor remains liable to the data fiduciary for the acts and omissions of sub-processors
When to obtain a review
A review is especially useful when…
- — You are about to sign, send, rely on or respond to this document.
- — The draft was copied from an old template or another state.
- — There is money, property, business control, statutory deadline or reputation risk involved.
- — You need Surat/Gujarat-specific drafting, review or negotiation support.
Legal information notice
This article is general legal information for India and Gujarat. It is not a substitute for advice on your specific facts, documents, limitation period, stamp duty position or court strategy.

