Every payment gateway, cloud provider, CRM, email platform, analytics tool, and payroll vendor that processes personal data on your behalf is your compliance liability under DPDPA. Section 8(2) requires a valid contract. Section 8(1) makes your compliance responsibility non-delegable. If your vendor suffers a breach, misuses data, or ignores an erasure request — you face the penalty, not them.
A signed NDA is not a DPA. A standard service agreement is not a DPA. A vendor's "we are GDPR compliant" claim is not a DPA. A Data Processing Agreement is a specific, data-protection-focused contract that defines exactly what the vendor can do with personal data, what security they must implement, how they report breaches, what happens to data when the contract ends, and what audit rights you retain.
Most organisations have DPA gaps they do not know about. PrivacyOS provides DPA drafting, clause-by-clause review of existing vendor contracts, gap analysis against DPDPA requirements, lifecycle tracking, and integration with vendor risk management — so your contractual foundation is as strong as your technical controls.
Fill the details to get started with our corporate panel.
Trusted by 1,000+ compliance teams
Section 8(2) of the DPDP Act is explicit — a Data Fiduciary may engage a Data Processor only under a valid contract. This is not guidance. It is a statutory requirement. Processing personal data through a vendor without a compliant contract is itself a violation.
The obligation is broad. It covers:
AWS, Azure, GCP, Indian hosting
Storage, compute instances, database backups containing personal data.
Razorpay, PayU, Stripe
Customer names, cards, transaction histories, billing details.
Salesforce, HubSpot, Zoho
Prospect, lead, customer contact details, communications, deal logs.
SendGrid, Mailchimp, CleverTap
Marketing lists, email open trackers, behavioural triggers.
Google Analytics, Mixpanel, Amplitude
IP addresses, user journey identifiers, event properties.
Zendesk, Freshdesk, Intercom
Ticket contents, live chat transcripts, user profiles.
Keka, Darwinbox, greytHR
Employee PAN, Aadhaar, salary data, bank credentials.
Delhivery, BlueDart
Customer delivery addresses, phone numbers, delivery signatures.
Identity proofs, biometric validation, video KYC recordings.
Diagnostic test results, patient medical records, policy numbers.
Student progress, assessment scores, under-18 student credentials.
Bottom line: If a vendor touches personal data — even indirectly through logs, backups, or analytics — they need a DPA.
Standard commercial agreements routinely fail statutory DPDPA requirements in six critical areas:
Missing any of these 12 clauses creates a gap that the Data Protection Board can identify during an inquiry. PrivacyOS tracks clause completeness for every vendor DPA and flags gaps automatically.
| # | Clause | What It Must Cover |
|---|---|---|
| 1 | Processing Scope & Purpose | Specific data categories, Data Principal categories, processing purposes. No open-ended "all data for all purposes." |
| 2 | Instructions Limitation | Processor acts only on Fiduciary's written instructions. No autonomous use of data. |
| 3 | Security Safeguards (Rule 6) | Encryption, access controls, audit logging, vulnerability management, breach detection — specific to the data being processed. |
| 4 | Breach Notification | Processor must notify Fiduciary within a defined timeline (recommended: 24 hours max). Include notification content requirements and cooperation obligations. |
| 5 | Sub-Processor Restrictions | Prior written approval required. Processor must disclose all sub-processors. Processor remains liable for sub-processor failures. |
| 6 | Data Retention & Deletion | Retention aligned to Fiduciary's retention policy. Mandatory deletion or return upon contract termination. Proof of deletion required. |
| 7 | DSR Cooperation | Processor must assist Fiduciary in fulfilling Data Principal rights requests — access, correction, erasure — within agreed timelines. |
| 8 | Cross-Border Transfer Controls | Document where data is hosted and processed. Restrictions on transfers outside India. Notification obligations if hosting changes. |
| 9 | Audit Rights | Fiduciary's right to audit Processor's compliance — through certifications (ISO 27001, SOC 2), third-party audits, or on-site inspections. |
| 10 | Confidentiality | Personnel handling data must be bound by confidentiality. Access restricted to those who need it for the processing purpose. |
| 11 | Liability & Indemnification | Processor indemnifies Fiduciary for losses arising from Processor's non-compliance. Liability caps aligned to risk exposure. |
| 12 | Termination Procedures | Data deletion/return timelines after termination. Transition period for service migration. Post-termination obligations. |
Four unified modules combining legal precision with ongoing software-driven lifecycle tracking:
Pre-drafted, DPDPA-compliant DPA templates ready for use with your vendors. Templates cover common vendor categories — cloud hosting, SaaS tools, payment processors, marketing platforms, HR systems, logistics partners — with industry-specific clauses for BFSI, healthcare, and EdTech.
Templates are starting points. Our advisory team customises clauses based on the specific vendor relationship, data sensitivity, and processing scope.
Already have vendor contracts? PrivacyOS reviews your existing agreements against the 12 mandatory clauses. For each vendor, you receive a gap report showing which clauses are present, which are missing, which are inadequate, and what specific language changes are needed.
Gaps are scored by risk level — a missing breach notification clause is critical. A generic scope definition is high. A missing audit right is medium. Prioritisation ensures you fix the highest-risk gaps first.
Your vendor's DPA may be compliant, but what about their vendors? PrivacyOS reviews sub-processor disclosure provisions, evaluates whether the approval process is adequate, and tracks the sub-processor chain for your highest-risk vendors.
When a vendor adds a new sub-processor, the system flags it for your review, safeguarding your supply chain visibility.
Through the vendor risk management module, PrivacyOS tracks:
A DPA is not a sign-and-forget document. It requires active management across 4 continuous phases:
Before onboarding any new vendor that will process personal data. No data sharing until a compliant DPA is signed.
Annual review of all vendor DPAs to ensure clauses remain current and aligned to regulatory changes. DPDP Rules amendments, new Board guidance, or changes in your processing activities may require DPA updates.
When a vendor changes sub-processors, hosting locations, or service scope. When your organisation changes its data processing activities, consent notices, or retention policies. After a vendor breach.
When a vendor relationship ends, the DPA's deletion/return clause must be enforced. PrivacyOS tracks termination actions — data deletion confirmation, proof of deletion, and final audit — as part of the vendor offboarding process.
Keep your vendor governance continuously aligned with business and operational triggers:
| Trigger | Action Required |
|---|---|
| New vendor onboarding | DPA required before any data sharing |
| Annual review cycle | All existing DPAs reviewed for clause currency |
| DPDP Rules amendment | Affected DPA clauses updated |
| Vendor changes sub-processors | Sub-processor clause reviewed, approval obtained |
| Vendor changes hosting location | Cross-border transfer clause reviewed |
| Vendor suffers a data breach | Breach notification clause effectiveness assessed |
| Your consent notice changes | Vendor processing scope verified against new notice |
| Contract renewal approaching | DPA renewed with updated terms |
| Vendor relationship ending | Deletion/return clause enforced and documented |
Continuous vendor scoring, DPA lifecycle audits, and automated sub-processor tracking.
Comprehensive 6-phase advisory covering full legal frameworks, RoPA design, and pre-audit certification.
Single pane of glass tracking vendor DPA completion, DSR velocity, and regulatory health.
Answers to critical questions regarding DPA validity, liability, and DPDPA mandates
Ensure every processor handling your personal data is bound by DPDPA-compliant terms. Get a clause-by-clause gap analysis and bespoke templates tailored to your risk profile.