DPDP processor contracts: what must be in them
By dpdprules.org editorial team · Reviewed by dpdprules.org source verificationPublished · Last reviewed
The short answer
Two anchors are explicit in the official text: a Data Fiduciary may engage a processor for activity related to offering goods or services only under a valid contract, and the reasonable security safeguards must include appropriate provisions in that contract for the processor to take reasonable safeguards. Around those anchors, the fiduciary's own duties make erasure flow down, one year log retention at the processor, and a contracted breach workflow the practical content of the agreement, because responsibility never transfers.
Under this framework the processor contract is not paperwork; it is the legal mechanism through which most of your duties reach the vendor.
The two explicit anchors
"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract."
No valid contract, no lawful engagement. And Rule 6 makes the contract itself a safeguard: the listed minimums include appropriate provisions in the fiduciary to processor contract for taking reasonable security safeguards.
What your own duties push into the contract
Responsibility for compliance stays with you irrespective of any agreement to the contrary, which is precisely why the contract must make the processor deliver what you owe. Three flows matter most. Erasure: when your erasure duties bite, you must cause the processor to erase the data you made available, so the contract needs an erasure on instruction clause with timelines. Log retention: the one year retention of data, traffic data and logs reaches processing done on your behalf, and the rule's own illustration has the fiduciary ensuring its cloud provider keeps them. Breach: the intimation duties to individuals and the Board are yours and run on short clocks, so the contract should fix detection, notification to you, and cooperation within hours, not business days.
Cross border room
If the processor is offshore, leave contractual room for government orders on making data available to foreign states and for notified country restrictions.
What to do
Work each engagement through the vendor and processor checklist; it maps every clause here to the exact provision. The Act text is at Section 8.
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (2), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [2]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026Rule 6(1)(f): appropriate contract provisions for taking reasonable security safeguards.
- [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (7), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026The fiduciary must cause its processor to erase personal data made available to it.
- [4]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, (3), p. 27. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026One year retention of personal data, traffic data and logs covers processing on the fiduciary's behalf; the rule's illustration has the fiduciary ensuring its cloud provider retains them.
- [5]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 16 August 2026The breach intimation duties and their clocks.