How to Draft a Data Processing Agreement Under the Digital Personal Data Protection Act 2023
- Kaustav Chowdhury

- 22 hours ago
- 8 min read
The Digital Personal Data Protection Act, 2023 (DPDP Act), published on August 11, 2023, has introduced a comprehensive framework for data protection in India. With the DPDP Rules notified on November 13, 2025, and full enforcement expected by mid-2027 under a phased approach, organisations must prepare their contractual frameworks to meet the new statutory requirements. A Data Processing Agreement (DPA) is an essential contract between a Data Fiduciary and a Data Processor, governing how personal data will be handled and ensuring that processing activities comply with the DPDP Act and its Rules.
Whether you are engaging a cloud service provider, an HR outsourcing vendor, or a marketing analytics firm, a well-drafted DPA is now a legal necessity. This guide provides a step-by-step approach to drafting a DPA that satisfies the requirements of the DPDP Act 2023 and the DPDP Rules. It is designed for corporate lawyers, compliance officers, and business professionals who need to put these agreements in place.
Understanding the Key Roles Under the DPDP Act
Before drafting a DPA, it is critical to understand the two key roles that the DPDP Act defines.
Data Fiduciary: The entity that determines the purpose and means of processing personal data. Under Section 8 of the DPDP Act, the Data Fiduciary retains ultimate responsibility for data protection compliance, regardless of whether it delegates processing tasks to a third party.
Data Processor: The entity that processes personal data on behalf of, and under the instructions of, the Data Fiduciary. The Data Processor does not independently determine the purpose or manner of processing.
This distinction is fundamental because the DPDP Act places primary compliance obligations on the Data Fiduciary. However, Rule 6(f) of the DPDP Rules specifically requires that contracts with Data Processors must impose equivalent security safeguards. A well-drafted DPA is the vehicle for achieving this contractual compliance.
Step-by-Step Guide to Drafting a DPDP-Compliant DPA
Step 1: Define the Scope and Purpose
Every DPA must begin with a clear statement of scope. This section should identify the type of personal data being processed, the categories of Data Principals (individuals whose data is processed), the purposes for which processing is permitted, and the duration of processing activities.
Model Clause: "This Agreement governs the processing of personal data by the Data Processor on behalf of the Data Fiduciary for the purposes specified in Schedule 1, and for such duration as set out in the Master Services Agreement."
Practical tip: Attach a schedule that lists the specific categories of data, the types of Data Principals, and the nature of processing operations. This approach provides clarity and allows the schedule to be updated without amending the main agreement.
Step 2: Incorporate Clear Definitions
Your DPA should define all key terms in alignment with the DPDP Act. At a minimum, include definitions for Data Fiduciary, Data Processor, Data Principal, personal data, processing, consent, Data Protection Board, and Significant Data Fiduciary. Aligning your definitions with the statutory language avoids ambiguity and ensures that contractual obligations are interpreted consistently with the Act.
Model Clause: "For the purposes of this Agreement, 'personal data,' 'Data Fiduciary,' 'Data Processor,' 'Data Principal,' and 'consent' shall have the meanings assigned to them under the Digital Personal Data Protection Act, 2023, and the Rules made thereunder."
Step 3: Specify the Obligations of the Data Processor
The core of any DPA lies in the obligations imposed on the Data Processor. Under the DPDP Act framework, these obligations should cover the following areas.
Processing personal data only in accordance with the written instructions of the Data Fiduciary
Ensuring that personnel authorised to process personal data are bound by confidentiality obligations
Implementing reasonable security safeguards as required under Rule 6 of the DPDP Rules
Assisting the Data Fiduciary in responding to requests from Data Principals to exercise their rights
Deleting or returning all personal data upon termination or expiry of the agreement, unless retention is required by law
Making available all information necessary to demonstrate compliance and allowing audits
Step 4: Address Security Safeguards
Rule 6 of the DPDP Rules requires Data Fiduciaries (and by extension, their Data Processors through contractual provisions) to implement reasonable security safeguards to prevent personal data breaches. Your DPA must address this requirement explicitly. The penalties for failing to maintain adequate security safeguards are severe, reaching up to Rs 250 crore under the DPDP Act.
Model Clause: "The Data Processor shall implement and maintain reasonable security safeguards, including technical and organisational measures, that are appropriate to the nature and volume of personal data processed. These safeguards shall comply with Rule 6 of the DPDP Rules and shall include, at minimum: encryption of personal data in transit and at rest; access controls and authentication mechanisms; regular security assessments and vulnerability testing; and incident response procedures."
Step 5: Data Breach Notification
The DPDP Act requires that personal data breaches be notified to the Data Protection Board and affected Data Principals within 72 hours. Your DPA must establish a clear notification chain between the Data Processor and the Data Fiduciary. Failure to notify a breach can attract penalties of up to Rs 200 crore.
Model Clause: "The Data Processor shall notify the Data Fiduciary of any personal data breach without undue delay, and in any event within 24 hours of becoming aware of such breach. The notification shall include: the nature of the breach; the categories and approximate number of Data Principals affected; the likely consequences; and the measures taken or proposed to address the breach."
Note that the 24-hour window for notification from the Data Processor to the Data Fiduciary is deliberately shorter than the 72-hour statutory deadline. This gives the Data Fiduciary sufficient time to assess the incident and make the required notification to the Data Protection Board and affected individuals.
Step 6: Cross-Border Data Transfer Clauses
The DPDP Act allows the Central Government to restrict transfers of personal data to certain jurisdictions by notification under Section 16. Until such restrictions are notified, cross-border transfers are generally permissible. However, your DPA should anticipate future restrictions and include appropriate safeguards to ensure compliance regardless of how the regulatory landscape evolves.
Model Clause: "The Data Processor shall not transfer personal data outside India unless such transfer is in compliance with Section 16 of the DPDP Act and any notifications issued by the Central Government restricting transfers to specific jurisdictions. The Data Processor shall promptly inform the Data Fiduciary of any changes in the jurisdictions from which or to which personal data is transferred."
Step 7: Sub-Processing Provisions
Many Data Processors engage sub-processors, such as cloud infrastructure providers or specialised analytics vendors. Your DPA must address this chain of processing and ensure that obligations flow down to every entity in the processing chain.
Model Clause: "The Data Processor shall not engage any sub-processor without the prior written consent of the Data Fiduciary. Where a sub-processor is engaged, the Data Processor shall enter into a written agreement with the sub-processor that imposes obligations equivalent to those set out in this Agreement. The Data Processor shall remain fully liable to the Data Fiduciary for the acts and omissions of any sub-processor."
In practice, consider the following additional safeguards for sub-processing arrangements.
Maintain a register of all sub-processors and share it with the Data Fiduciary on request
Include a right for the Data Fiduciary to object to new sub-processors within a specified timeframe
Require the Data Processor to conduct due diligence on all sub-processors before engagement
Ensure that sub-processor agreements include equivalent breach notification and audit rights
Step 8: Audit Rights
The Data Fiduciary must be able to verify that the Data Processor complies with its obligations. Audit rights are an essential mechanism for this purpose and should be drafted broadly enough to allow meaningful oversight.
Model Clause: "The Data Fiduciary, or an independent auditor appointed by the Data Fiduciary, shall have the right to conduct audits and inspections of the Data Processor's processing activities, facilities, and records, upon reasonable notice of not less than 15 business days. The Data Processor shall cooperate fully with any such audit and shall make available all information, systems, and personnel necessary to verify compliance with this Agreement and with the DPDP Act."
Specify audit frequency (for example, at least once per year and additionally following any data breach or complaint)
Require the Data Processor to promptly remediate any non-compliance identified during an audit
Address allocation of audit costs (typically borne by the Data Fiduciary unless the audit reveals material non-compliance)
Step 9: Term, Termination, and Data Return
The DPA should clearly address what happens to personal data when the agreement ends. This is a frequently overlooked aspect of data processing arrangements, but it is critical from a compliance perspective.
Model Clause: "Upon termination or expiry of this Agreement, the Data Processor shall, at the Data Fiduciary's election, either return all personal data to the Data Fiduciary in a commonly used and machine-readable format, or securely delete all personal data and certify such deletion in writing. This obligation shall be completed within 30 days of termination or expiry, unless a longer period is required by applicable law."
Specify the format for data return (for example, CSV, JSON, or encrypted archives)
Require a certificate of deletion signed by an authorised representative of the Data Processor
Address any data that must be retained under applicable law, specifying clear retention periods and the legal basis for retention
Consent Requirements and the DPA
Under the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous. While consent is primarily the responsibility of the Data Fiduciary (as it interfaces with the Data Principal), the DPA should require the Data Processor to process data only to the extent permitted by the consent obtained by the Data Fiduciary or another lawful basis under the Act.
Model Clause: "The Data Processor acknowledges that personal data processed under this Agreement is collected by the Data Fiduciary on the basis of the consent of the Data Principal or another lawful basis under the DPDP Act. The Data Processor shall not process personal data for any purpose beyond the scope of such consent or lawful basis, and shall immediately inform the Data Fiduciary if, in the Data Processor's opinion, an instruction from the Data Fiduciary infringes the DPDP Act."
Indemnification and Liability
Given the significant penalties under the DPDP Act, the DPA should include robust indemnification provisions. The Data Processor should indemnify the Data Fiduciary for any losses, penalties, or claims arising from the Data Processor's failure to comply with its obligations under the DPA or the DPDP Act.
Specify that the Data Processor shall indemnify the Data Fiduciary for penalties imposed by the Data Protection Board due to the Data Processor's non-compliance
Address whether liability caps apply and, if so, whether they exclude regulatory penalties and data breach remediation costs
Include a right for the Data Fiduciary to recover costs of breach investigation, notification, and remediation from the Data Processor
Practical Checklist for DPA Readiness
Before finalising your DPA, confirm that it addresses each of the following areas.
Clear scope, purpose, and duration of processing
Definitions aligned with the DPDP Act 2023 and the DPDP Rules
Data Processor obligations covering instructions, confidentiality, security, cooperation, and deletion
Security safeguards in compliance with Rule 6 of the DPDP Rules
Breach notification within 24 hours to the Data Fiduciary (allowing for the 72-hour statutory window)
Cross-border transfer restrictions and compliance mechanisms
Sub-processing controls with prior written consent requirements
Audit rights with specified frequency, scope, and cost allocation
Term, termination, and data return or secure deletion provisions
Indemnification and liability provisions, including treatment of regulatory penalties
Consent and lawful basis acknowledgement
Penalties at a Glance
The DPDP Act imposes substantial penalties that make a robust DPA not just good practice, but a business imperative.
Inadequate security safeguards leading to a data breach: penalty of up to Rs 250 crore
Failure to notify a data breach: penalty of up to Rs 200 crore
These penalties apply to the Data Fiduciary, which is precisely why the DPA must contractually shift responsibility to the Data Processor where the breach or failure originates from the Data Processor's actions or omissions. Without a properly drafted DPA, the Data Fiduciary bears the full weight of these penalties with no contractual recourse against the party that may have caused the violation.
Conclusion
Drafting a Data Processing Agreement under the DPDP Act 2023 is not merely a contractual formality; it is a critical compliance measure. With penalties reaching up to Rs 250 crore for security failures and Rs 200 crore for breach notification failures, the stakes are significant. Organisations should begin drafting and implementing DPAs now, well ahead of the anticipated full enforcement by mid-2027.
A well-drafted DPA protects both the Data Fiduciary and the Data Processor by establishing clear responsibilities, setting enforceable standards, and creating mechanisms for accountability. By following the step-by-step approach outlined in this guide and adapting the model clauses to your specific requirements, you can build a contractual framework that meets the requirements of the DPDP Act and positions your organisation for compliance. The time to act is now; waiting until enforcement begins is a risk that no prudent business can afford to take.

Comments