Digital & E-Commerce Legal Support8 min readUpdated 18 June 2026

DPDP Clauses for Vendor & SaaS Contracts: India 2025

Add DPDP Rules 2025 clauses to vendor and SaaS contracts - 7 mandatory provisions. Expert help in Surat, Gujarat.

Tirth Inamdar, founder of Inamdar Legal

Tirth Inamdar

Founder · Inamdar Legal

Founder-reviewed legal guidanceSurat · India · Global clients

Quick answer

For dpdp clauses for vendor and saas contracts in Surat, the safest approach is to combine the correct legal rule with a clean factual record, proper documents and a draft that matches the real transaction. This updated article uses the Excel source content and adds Surat/Gujarat SEO context so the reader can understand the law, collect the right papers and decide when to get drafting or review help.

UPDATE - NOVEMBER 2025: The Digital Personal Data Protection Rules, 2025 (DPDP Rules) were notified by MeitY on 14 November 2025 and are now in force on a phased timeline: immediate effect from November 2025 for foundational provisions; Consent Manager Framework from November 2026; full compliance obligations (notices, security safeguards, breach notification, children's data protections, cross-border transfer rules) from May 2027. The Data Protection Board of India has been established. The references in this article to rules being finalised should be read as updated accordingly - the Rules are now notified and businesses should be building their DPDP compliance programme actively. India's Digital Personal Data Protection Act 2023 (DPDP Act) requires businesses to include specific data protection provisions in any contract under which a third party processes personal data on their behalf. This applies to vendor agreements, SaaS contracts, IT services agreements, cloud hosting contracts, and any other commercial arrangement where personal data flows to a third-party processor.

Quick Surat-Focused Answer

  • 01Primary topic: DPDP Clauses for Vendor and SaaS Contracts
  • 02Location focus: Surat, Gujarat and India
  • 03Updated for current legal references and practical client preparation
  • 04Designed for service-intent SEO, not generic legal theory

Why Standard Contracts Need Updating For Dpdp

Most existing vendor agreements and SaaS contracts in India were drafted before the DPDP Act came into force. They do not contain the specific data processing obligations the Act requires. Using contracts that predate the DPDP Act for new engagements involving personal data is a compliance gap that regulators can penalise. The DPDP Act creates financial penalties of up to Rs.250 crore for data fiduciaries who fail to ensure that their data processors handle personal data in compliance with the Act. The contractual mechanism through which data fiduciaries enforce this compliance is the DPA - the data protection clauses in their vendor and SaaS contracts. THE SEVEN DPDP CLAUSES EVERY VENDOR AND SaaS CONTRACT NEEDS

Clause 1: Purpose Limitation

"The Vendor/Service Provider shall process Personal Data only for the purpose of providing the services described in this Agreement and strictly in accordance with the written instructions of the Client. The Vendor shall not process Personal Data for any other purpose, including for the Vendor's own commercial purposes, marketing, or analytics, without the Client's prior written consent." Why it matters: Prevents the vendor from using your customer or employee data for their own benefit - including training AI models, building competitive intelligence, or reselling data insights.

Clause 2: Security Obligations

"The Vendor shall implement and maintain appropriate technical and organisational security measures to protect Personal Data against accidental or unauthorised destruction, loss, alteration, disclosure, or access. Such measures shall include at minimum: (a) encryption of Personal Data at rest and in transit using industry-standard protocols; (b) access controls limiting Personal Data access to authorised personnel on a need-to-know basis; (c) regular security vulnerability assessments; and (d) a documented information security policy." Why it matters: The DPDP Act requires data fiduciaries to ensure their processors implement reasonable security safeguards. Specifying the minimum security requirements in the contract creates an enforceable standard.

Clause 3: Personal Data Breach Notification

"The Vendor shall notify the Client of any Personal Data Breach as soon as reasonably practicable and in any event within [48/72] hours of becoming aware of the breach. The notification shall include: (a) the nature of the breach; (b) the categories and approximate number of Personal Data records affected; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach." Why it matters: The DPDP Act requires data fiduciaries to notify the Data Protection Board of India of significant breaches. A 48-72 hour notification obligation from the processor to the data fiduciary gives the data fiduciary enough time to assess and comply with its own notification obligation.

Clause 4: Sub-Processor Restrictions

"The Vendor shall not engage any sub-processor to process Personal Data without the Client's prior written consent. The Vendor shall impose on all sub-processors data protection obligations equivalent to those in this Agreement. The Vendor shall remain liable to the Client for the acts and omissions of its sub-processors as if the acts and omissions were the Vendor's own." Why it matters: Many SaaS vendors use sub-processors (cloud infrastructure providers, analytics tools, customer support software). This clause ensures your data is protected throughout the chain, not just at the top level.

Clause 5: Data Principal Rights Assistance

"The Vendor shall, at the Client's request and at no additional charge, assist the Client in responding to requests from Data Principals exercising their rights under the DPDP Act - including the right to access, correct, erase, or obtain information about their Personal Data held by the Vendor." Why it matters: When your customers or employees exercise their rights under the DPDP Act (e.g., requesting deletion of their data), you need your vendors to cooperate in fulfilling those requests promptly. Without this clause, vendors may resist or charge for compliance assistance.

Clause 6: Cross-Border Transfer Restrictions

"The Vendor shall not transfer Personal Data outside India except to countries or territories that the Central Government has not restricted under Section 16 of the DPDP Act, or as otherwise expressly authorised by the Client in writing. The Vendor shall promptly notify the Client if any Central Government restriction on cross-border transfer affects the services provided under this Agreement." Why it matters: Section 16 of the DPDP Act empowers the Central Government to restrict data transfers to certain countries. This clause ensures the vendor actively monitors and complies with these restrictions - and notifies you if their infrastructure needs to change.

Clause 7: Data Return And Deletion On Termination

"On expiry or termination of this Agreement, the Vendor shall, at the Client's election, either: (a) return to the Client all Personal Data in a portable, machine-readable format within [30] days; or (b) securely delete all Personal Data and certify the deletion in writing within [30] days. The Vendor shall retain no copies of Personal Data except to the extent required by applicable law, and shall notify the Client of any such retention." Why it matters: Ensures your customer and employee data does not persist with the vendor after you stop using their services. The certification of deletion gives you documentary evidence of compliance.

Surat And Gujarat Practice Notes

People searching for DPDP clauses vendor contracts India 2025 usually need more than a definition. They need to know what documents to collect, which facts matter, how the Surat or Gujarat process affects timing, and what should be changed before a draft is signed or a notice is sent. For Surat digital businesses, websites and online platforms, the legal risk is often hidden inside product flows: sign-up forms, checkout screens, refund policies, data collection, user uploads, vendor onboarding and support promises. The DPDP Act, IT Rules, consumer expectations and contract law should be translated into clear website terms, privacy notices, marketplace rules and SaaS clauses that a user can actually understand. A strong article should help a local founder see what needs to be displayed online, what should sit in the contract and what evidence should be saved. This is why every client file should be built around a clear chronology, a document index and a practical risk note. That approach makes the article useful for search readers and also mirrors how a lawyer would prepare the matter for drafting, negotiation, settlement or court.

  • Keep party names, addresses, dates, amounts and document numbers consistent across the draft.
  • Collect supporting proof before final drafting instead of after a dispute starts.
  • Check whether stamp duty, registration, statutory notice or board approval changes the timeline.
  • Use Surat-specific facts such as property location, business branch, vendor address, bank branch or project details where relevant.

Client Checklist Before You Ask For Drafting

Before asking for help with DPDP Clauses for Vendor and SaaS Contracts, prepare a short brief. State who the parties are, what has happened so far, what document already exists, what result you want and what deadline is approaching. For SEO readers in Surat, this checklist is useful because it turns a broad search query into an immediate next step. For the lawyer, it reduces back-and-forth and helps produce a draft or review note that is specific rather than generic.

  • Existing draft, agreement, notice, invoice, title paper, policy or email chain.
  • Government IDs, business registration details, GST details or property identifiers where relevant.
  • Chronology of events with dates, payments, defaults, reminders and responses.
  • Your preferred outcome: draft, review, redline, settlement notice, compliance correction or negotiation support.

When to obtain a review

A review is especially useful when…

  • You are about to sign, send, rely on or respond to this document.
  • The draft was copied from an old template or another state.
  • There is money, property, business control, statutory deadline or reputation risk involved.
  • You need Surat/Gujarat-specific drafting, review or negotiation support.

Legal information notice

This article is general legal information for India and Gujarat. It is not a substitute for advice on your specific facts, documents, limitation period, stamp duty position or court strategy.

Questions, answered clearly

Common questions

Do I need a lawyer for dpdp clauses for vendor and saas contracts in Surat?+

You should consider legal help when money, property, business rights, statutory timelines, compliance exposure or future enforcement is involved. A lawyer can tailor the document or notice to the facts instead of relying on a generic template.

Is a template enough for this document?+

A template may help with structure, but it often misses party-specific facts, Gujarat stamp or registration issues, statutory timelines, evidence requirements and negotiation points. Use it only after checking whether it fits the transaction.

What should I share before asking Inamdar Legal to review or draft it?+

Share the existing draft, transaction summary, dates, payment details, party information, supporting documents and the exact concern you want addressed. For urgent notices, also share the limitation or statutory deadline.

A practical next step

Need Help With DPDP Clauses for Vendor and SaaS Contracts In Surat?

Share the draft, documents and timeline. Inamdar Legal can help review, redline or prepare dpdp clauses for vendor and saas contracts with Surat and Gujarat-specific legal checks.