A distinction that changes who is responsible for what
The DPDP framework has phased commencement. Check which provisions are in force for the relevant date and activity; the preparation steps below should not be read as a statement that every DPDP duty or penalty already applies.
Under section 2 of the DPDP Act, a data fiduciary determines the purpose and means of processing personal data; a processor processes it on a fiduciary’s behalf. Classify each processing activity using what actually happens. The same supplier may act differently for separate purposes, so the vendor label alone does not settle its role. DPDP Act: sections 2 and 8
Check whether the contract matches the actual processing
A confidentiality clause alone may leave operational questions unanswered: which data is processed, for what purpose, under whose authority, and who must act if an incident occurs? Compare the agreement with the real data flow before deciding what needs amendment.
Recommended contract checks, alongside statutory duties
The processing purpose and scope, stated specifically enough that it is clear what the processor is and is not authorised to do with the data, rather than a broad grant that could cover uses never actually intended.
Instructions and limits, making clear that the processor acts only on the fiduciary’s documented instructions, and what happens if the processor believes an instruction would create a compliance problem.
Agree incident escalation terms that let the fiduciary assess its applicable obligations promptly. Specify the contact, initial facts, updates and cooperation required. A negotiated processor notification interval is not itself the DPDP Board’s statutory reporting deadline.
Sub-processing terms, since a processor frequently relies on its own vendors, and the fiduciary needs visibility into that chain rather than discovering it after an incident.
Deletion and return of data at the end of the engagement, specified with enough detail that “we deleted it” can actually be verified rather than taken on trust.
Where to start if you have not reviewed this yet
Prioritise vendors using the harm that misuse or disruption could cause, data volume and access. Health or financial information may warrant stronger practical protection, but do not present this prioritisation as a separate DPDP statutory category of sensitive personal data.
Separate the legal baseline from the negotiated mechanism
Section 8 addresses fiduciary responsibility and engagement of processors under a valid contract. The operational fields below are suggested drafting inputs, not a claim that the Act prescribes this exact clause list. Core duties have phased commencement under G.S.R. 843(E).
- Role and purpose: list each processing activity, its business purpose, the data involved and who decides its use. If a supplier proposes independent analytics or marketing, review that purpose separately rather than burying it in a processor clause.
- Instruction and access: identify authorised instructions, permitted users, access locations and how changes are approved. Ask the technical team to confirm the arrangement can be implemented; an impressive restriction that the service cannot enforce creates a misleading record.
- Incident cooperation: name primary and backup contacts, the information needed initially and the update route. Exercise an incomplete-information scenario. Preserve the fiduciary’s ability to assess other reporting duties, including CERT-In, independently.
- Subcontracting and exit: document the processing chain, change-notification process, data return and deletion approach. Identify backup retention, legal preservation and inaccessible copies explicitly, and agree what evidence of completion can reasonably be supplied.
- Review and acceptance: assign unresolved clauses to an owner and decision date. Keep statutory obligations, contractual commitments and recommended safeguards in separate fields so a negotiator does not accidentally describe advice as law.
Use one high-impact vendor as a pilot, reconcile its agreement with the service configuration and then apply the reviewed method to other relationships. Involve legal, procurement and the system owner: none can confirm the whole operating arrangement alone. Keep the current commencement position with the review so future obligations are not described as already enforceable.

