Home/Services/Contract Review & Data Processing Agreements
SECTION 8(2) MANDATORY VENDOR CONTRACTING

Contract Review & Data Processing Agreements — The Legal Foundation of Vendor Compliance

Every payment gateway, cloud provider, CRM, email platform, analytics tool, and payroll vendor that processes personal data on your behalf is your compliance liability under DPDPA. Section 8(2) requires a valid contract. Section 8(1) makes your compliance responsibility non-delegable. If your vendor suffers a breach, misuses data, or ignores an erasure request — you face the penalty, not them.

A signed NDA is not a DPA. A standard service agreement is not a DPA. A vendor's "we are GDPR compliant" claim is not a DPA. A Data Processing Agreement is a specific, data-protection-focused contract that defines exactly what the vendor can do with personal data, what security they must implement, how they report breaches, what happens to data when the contract ends, and what audit rights you retain.

Most organisations have DPA gaps they do not know about. PrivacyOS provides DPA drafting, clause-by-clause review of existing vendor contracts, gap analysis against DPDPA requirements, lifecycle tracking, and integration with vendor risk management — so your contractual foundation is as strong as your technical controls.

Schedule Consultation
12 Clauses
Mandatory Framework
Sec 8(2)
Statutory Requirement
Non-Delegable
Section 8(1) Shield
DPA Readiness Evaluation
· DPDPA Compliance · Trust Assured
FAST TRACK APPLICATION

Apply for DPDPA Assessment

Fill the details to get started with our corporate panel.

Representative PortraitRepresentative PortraitRepresentative PortraitRepresentative Portrait
4.9/5

Trusted by 1,000+ compliance teams

Why Every Vendor Needs a DPA Under DPDPA

Section 8(2) of the DPDP Act is explicit — a Data Fiduciary may engage a Data Processor only under a valid contract. This is not guidance. It is a statutory requirement. Processing personal data through a vendor without a compliant contract is itself a violation.

The obligation is broad. It covers:

Cloud hosting providers

AWS, Azure, GCP, Indian hosting

Storage, compute instances, database backups containing personal data.

Payment gateways & card processors

Razorpay, PayU, Stripe

Customer names, cards, transaction histories, billing details.

CRM platforms

Salesforce, HubSpot, Zoho

Prospect, lead, customer contact details, communications, deal logs.

Email and marketing tools

SendGrid, Mailchimp, CleverTap

Marketing lists, email open trackers, behavioural triggers.

Analytics platforms

Google Analytics, Mixpanel, Amplitude

IP addresses, user journey identifiers, event properties.

Customer support tools

Zendesk, Freshdesk, Intercom

Ticket contents, live chat transcripts, user profiles.

HR and payroll systems

Keka, Darwinbox, greytHR

Employee PAN, Aadhaar, salary data, bank credentials.

Logistics and delivery partners

Delhivery, BlueDart

Customer delivery addresses, phone numbers, delivery signatures.

KYC verification vendors

For BFSI sectors

Identity proofs, biometric validation, video KYC recordings.

Diagnostic and insurance partners

For healthcare providers

Diagnostic test results, patient medical records, policy numbers.

Content delivery and EdTech tools

For education institutions

Student progress, assessment scores, under-18 student credentials.

Bottom line: If a vendor touches personal data — even indirectly through logs, backups, or analytics — they need a DPA.

What Most Vendor Contracts Get Wrong

Standard commercial agreements routinely fail statutory DPDPA requirements in six critical areas:

Problem 1

No DPA exists at all

The most common failure. Teams adopt SaaS tools, sign the vendor's standard terms, and never add data processing provisions. The standard terms protect the vendor. A DPA protects you.
Problem 2

NDA treated as DPA

An NDA covers confidentiality — who can know about the information. A DPA covers processing — what can be done with the data, how it must be secured, when it must be deleted, and what happens during a breach. These are different obligations.
Problem 3

Generic scope

A DPA that permits "processing of all personal data for all purposes" is overbroad and likely non-compliant with DPDPA's purpose limitation principle. The scope must be specific — what data categories, what Data Principal categories, what processing purposes, what retention periods.
Problem 4

No breach notification chain

Your vendor detects a breach on Friday evening. When do they tell you? If the DPA does not specify a notification timeline (24 hours is the recommended maximum), you may not learn about it until after your CERT-In 6-hour window has closed.
Problem 5

No sub-processor controls

Your vendor uses its own vendors. Your customer's data flows through a chain you never approved. Without sub-processor disclosure and approval clauses, you have no visibility or control over the chain.
Problem 6

No deletion clause

When the contract ends, what happens to the data? Without a deletion-upon-termination clause, your vendor may retain customer data indefinitely — violating your retention obligations.
COMPLIANCE SPECIFICATION

The 12 Mandatory Clauses of a DPDPA-Compliant DPA

Missing any of these 12 clauses creates a gap that the Data Protection Board can identify during an inquiry. PrivacyOS tracks clause completeness for every vendor DPA and flags gaps automatically.

#ClauseWhat It Must Cover
1Processing Scope & PurposeSpecific data categories, Data Principal categories, processing purposes. No open-ended "all data for all purposes."
2Instructions LimitationProcessor acts only on Fiduciary's written instructions. No autonomous use of data.
3Security Safeguards (Rule 6)Encryption, access controls, audit logging, vulnerability management, breach detection — specific to the data being processed.
4Breach NotificationProcessor must notify Fiduciary within a defined timeline (recommended: 24 hours max). Include notification content requirements and cooperation obligations.
5Sub-Processor RestrictionsPrior written approval required. Processor must disclose all sub-processors. Processor remains liable for sub-processor failures.
6Data Retention & DeletionRetention aligned to Fiduciary's retention policy. Mandatory deletion or return upon contract termination. Proof of deletion required.
7DSR CooperationProcessor must assist Fiduciary in fulfilling Data Principal rights requests — access, correction, erasure — within agreed timelines.
8Cross-Border Transfer ControlsDocument where data is hosted and processed. Restrictions on transfers outside India. Notification obligations if hosting changes.
9Audit RightsFiduciary's right to audit Processor's compliance — through certifications (ISO 27001, SOC 2), third-party audits, or on-site inspections.
10ConfidentialityPersonnel handling data must be bound by confidentiality. Access restricted to those who need it for the processing purpose.
11Liability & IndemnificationProcessor indemnifies Fiduciary for losses arising from Processor's non-compliance. Liability caps aligned to risk exposure.
12Termination ProceduresData deletion/return timelines after termination. Transition period for service migration. Post-termination obligations.

What PrivacyOS Contract Review Covers

Four unified modules combining legal precision with ongoing software-driven lifecycle tracking:

DPA Templates

Pre-drafted, DPDPA-compliant DPA templates ready for use with your vendors. Templates cover common vendor categories — cloud hosting, SaaS tools, payment processors, marketing platforms, HR systems, logistics partners — with industry-specific clauses for BFSI, healthcare, and EdTech.

Templates are starting points. Our advisory team customises clauses based on the specific vendor relationship, data sensitivity, and processing scope.

Clause-by-Clause Gap Analysis

Already have vendor contracts? PrivacyOS reviews your existing agreements against the 12 mandatory clauses. For each vendor, you receive a gap report showing which clauses are present, which are missing, which are inadequate, and what specific language changes are needed.

Gaps are scored by risk level — a missing breach notification clause is critical. A generic scope definition is high. A missing audit right is medium. Prioritisation ensures you fix the highest-risk gaps first.

Sub-Processor Disclosure Review

Your vendor's DPA may be compliant, but what about their vendors? PrivacyOS reviews sub-processor disclosure provisions, evaluates whether the approval process is adequate, and tracks the sub-processor chain for your highest-risk vendors.

When a vendor adds a new sub-processor, the system flags it for your review, safeguarding your supply chain visibility.

DPA Lifecycle Tracking

Through the vendor risk management module, PrivacyOS tracks:

  • DPA status for every vendor (signed, under review, expired, missing)
  • DPA version and last update date
  • Key clause summary per vendor
  • Renewal and expiry alerts (30-day, 60-day advance notice)
  • Gap remediation status (open, in progress, closed)

DPA Lifecycle Management

A DPA is not a sign-and-forget document. It requires active management across 4 continuous phases:

01

Initial Review

Before onboarding any new vendor that will process personal data. No data sharing until a compliant DPA is signed.

02

Periodic Review

Annual review of all vendor DPAs to ensure clauses remain current and aligned to regulatory changes. DPDP Rules amendments, new Board guidance, or changes in your processing activities may require DPA updates.

03

Event-Triggered Review

When a vendor changes sub-processors, hosting locations, or service scope. When your organisation changes its data processing activities, consent notices, or retention policies. After a vendor breach.

04

Termination Management

When a vendor relationship ends, the DPA's deletion/return clause must be enforced. PrivacyOS tracks termination actions — data deletion confirmation, proof of deletion, and final audit — as part of the vendor offboarding process.

When to Review or Renegotiate

Keep your vendor governance continuously aligned with business and operational triggers:

TriggerAction Required
New vendor onboardingDPA required before any data sharing
Annual review cycleAll existing DPAs reviewed for clause currency
DPDP Rules amendmentAffected DPA clauses updated
Vendor changes sub-processorsSub-processor clause reviewed, approval obtained
Vendor changes hosting locationCross-border transfer clause reviewed
Vendor suffers a data breachBreach notification clause effectiveness assessed
Your consent notice changesVendor processing scope verified against new notice
Contract renewal approachingDPA renewed with updated terms
Vendor relationship endingDeletion/return clause enforced and documented

Frequently Asked Questions

Answers to critical questions regarding DPA validity, liability, and DPDPA mandates

PROTECT YOUR NON-DELEGABLE LIABILITY

Get Your Vendor Contracts Reviewed

Ensure every processor handling your personal data is bound by DPDPA-compliant terms. Get a clause-by-clause gap analysis and bespoke templates tailored to your risk profile.

Speak to an Advisory Partner