Regulation & Assurance

DPDP: Data Fiduciary, Processor and Vendor Contracts

Map fiduciary and processor roles under India’s DPDP framework, distinguish statutory duties from contract choices, and prepare a practical vendor review.

Purpose and instructions connect to a processing scope, with a separate strip outside the agreed scope.
In this article 6 sections
ShareLinkedInWhatsAppEmail

A distinction that changes who is responsible for what

The DPDP framework has phased commencement. Check which provisions are in force for the relevant date and activity; the preparation steps below should not be read as a statement that every DPDP duty or penalty already applies.

Under section 2 of the DPDP Act, a data fiduciary determines the purpose and means of processing personal data; a processor processes it on a fiduciary’s behalf. Classify each processing activity using what actually happens. The same supplier may act differently for separate purposes, so the vendor label alone does not settle its role. DPDP Act: sections 2 and 8

Check whether the contract matches the actual processing

A confidentiality clause alone may leave operational questions unanswered: which data is processed, for what purpose, under whose authority, and who must act if an incident occurs? Compare the agreement with the real data flow before deciding what needs amendment.

The processing purpose and scope, stated specifically enough that it is clear what the processor is and is not authorised to do with the data, rather than a broad grant that could cover uses never actually intended.

Instructions and limits, making clear that the processor acts only on the fiduciary’s documented instructions, and what happens if the processor believes an instruction would create a compliance problem.

Agree incident escalation terms that let the fiduciary assess its applicable obligations promptly. Specify the contact, initial facts, updates and cooperation required. A negotiated processor notification interval is not itself the DPDP Board’s statutory reporting deadline.

Sub-processing terms, since a processor frequently relies on its own vendors, and the fiduciary needs visibility into that chain rather than discovering it after an incident.

Deletion and return of data at the end of the engagement, specified with enough detail that “we deleted it” can actually be verified rather than taken on trust.

Where to start if you have not reviewed this yet

Prioritise vendors using the harm that misuse or disruption could cause, data volume and access. Health or financial information may warrant stronger practical protection, but do not present this prioritisation as a separate DPDP statutory category of sensitive personal data.

Section 8 addresses fiduciary responsibility and engagement of processors under a valid contract. The operational fields below are suggested drafting inputs, not a claim that the Act prescribes this exact clause list. Core duties have phased commencement under G.S.R. 843(E).

  • Role and purpose: list each processing activity, its business purpose, the data involved and who decides its use. If a supplier proposes independent analytics or marketing, review that purpose separately rather than burying it in a processor clause.
  • Instruction and access: identify authorised instructions, permitted users, access locations and how changes are approved. Ask the technical team to confirm the arrangement can be implemented; an impressive restriction that the service cannot enforce creates a misleading record.
  • Incident cooperation: name primary and backup contacts, the information needed initially and the update route. Exercise an incomplete-information scenario. Preserve the fiduciary’s ability to assess other reporting duties, including CERT-In, independently.
  • Subcontracting and exit: document the processing chain, change-notification process, data return and deletion approach. Identify backup retention, legal preservation and inaccessible copies explicitly, and agree what evidence of completion can reasonably be supplied.
  • Review and acceptance: assign unresolved clauses to an owner and decision date. Keep statutory obligations, contractual commitments and recommended safeguards in separate fields so a negotiator does not accidentally describe advice as law.

Use one high-impact vendor as a pilot, reconcile its agreement with the service configuration and then apply the reviewed method to other relationships. Involve legal, procurement and the system owner: none can confirm the whole operating arrangement alone. Keep the current commencement position with the review so future obligations are not described as already enforceable.

Sources and further guidance

Regulatory applicability depends on the organisation and the provisions in force. Check the linked primary sources before acting.

Related reading and capabilities

Frequently asked questions

Is every vendor a processor?

No. Determine the purpose and means of each activity and who controls them. A supplier can have a processor role for one activity and an independent fiduciary role for another.

Does a processor contract remove fiduciary responsibility?

No. Section 8’s allocation of fiduciary responsibility is not displaced simply by outsourcing. Review the applicable provision and commencement position alongside the agreement.

Is a specific vendor notification deadline prescribed here?

No. Negotiate an escalation interval that supports applicable reporting and response duties. Do not confuse that contractual commitment with the separate statutory notification stages.