Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Do you need a contract with your Data Processor under DPDP?

Vendors

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 2 min read

Do I need a contract before engaging a Data Processor under DPDP?

The short answer

Yes, once section 8(2) commences, and only for activity related to offering goods or services to Data Principals. 2 anchors are explicit in the official text: a Data Fiduciary may engage a processor for activity related to offering goods or services only under a valid contract, and the reasonable security safeguards must include appropriate provisions in that contract for the processor to take reasonable safeguards. Around those anchors, the fiduciary's own duties make erasure flow down, 1 year log retention at the processor, and a contracted breach workflow the practical content of the agreement, because responsibility never transfers. None of it binds anyone yet: section 8 sits in the 18 month commencement group of notification G.S.R. 843(E) and Rules 6 and 8 in the 18 month group of Rule 1(4), computed as 13 May 2027, which is interpretation until officially confirmed.

More answered questions →

Summary infographic headed 'What DPDP processor contracts need'
The infographic states that a Data Processor may act only under a valid contract, that the contract should push the security safeguards down to the processor, that it should cover erasure, breach escalation and support for log retention, and that a contract with an offshore processor should leave room for transfer restrictions. A diagram puts a processor contract between the Data Fiduciary and the Data Processor, carrying security, erasure and breach obligations. The valid contract requirement is the Act's; what the contract should contain is drafting practice. Status as at 25 September 2026: the duties described here are not in force yet; they sit in the 18 month commencement group, computed 13 May 2027 and interpretation until officially confirmed.

Under this framework the processor contract is not paperwork; it is the legal mechanism through which most of your duties reach the vendor. This article covers what the statute itself requires in the contract. For the clause by clause drafting view, including which standard clauses have no statutory basis at all, see DPA clauses under the DPDP Act. If you are new to the framework as a whole, begin with what the DPDP Act and Rules are.

It also assumes the roles are already settled: the duty in section 8(2) is the Data Fiduciary's, and it bites only where the counterparty is a Data Processor for that processing. If that is still open, the role test decides it.

The 2 explicit anchors

DPDP Act 2023, s. 8, (2) · General obligations of Data Fiduciary · verbatim

"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract."

No valid contract, no lawful engagement. And Rule 6 makes the contract itself a safeguard: the listed minimums include appropriate provisions in the fiduciary to processor contract for taking reasonable security safeguards.

What your own duties push into the contract

Responsibility for compliance stays with you irrespective of any agreement to the contrary, which is precisely why the contract must make the processor deliver what you owe. Three flows matter most. Erasure: when your erasure duties bite, you must cause the processor to erase the data you made available, so the contract needs an erasure on instruction clause with timelines. Log retention: the 1 year retention of data, traffic data and logs reaches processing done on your behalf, and the rule's own illustration has the fiduciary ensuring its cloud provider keeps them. Breach: the intimation duties to individuals and the Board are yours and run on short clocks, so the contract should fix detection, notification to you, and cooperation within hours, not business days.

Cross border room

If the processor is offshore, leave contractual room for government orders on making data available to foreign states and for notified country restrictions.

When this starts

None of it binds anyone yet. Section 8 is in the 18 month group of commencement notification G.S.R. 843(E), and Rule 1(4) puts Rules 6 and 8 in the Rules' own 18 month group, so the contract duty and the rules specifying what the contract must carry commence together. That computes to 13 May 2027, interpretation until officially confirmed.

The contract work still has an earlier deadline than the law does, because it lands on renewal and procurement cycles rather than on a commencement date.

What to do

Work each engagement through the vendor and processor checklist; it maps every clause here to the exact provision. The Act text is at Section 8. If you sell software to other businesses and are unsure which side of the line you are on, read does DPDP apply to B2B SaaS companies. If you are on the receiving end of this contract, Data Processor obligations under DPDP sets out what the framework asks of you rather than of your customer.

Section 8, official text →

ContractsData ProcessorVendors

Share this: