==================================================================== STARTING TEMPLATE from dpdprules.org Data Processor engagement: contract checklist Practical recommendation, not legal advice. Have your legal counsel review and adapt this before use. Provisions tracked: section 8(2) of the DPDP Act 2023 (a Data Processor may be engaged only under a valid contract) and the wider duties of section 8 that the Data Fiduciary keeps regardless of any engagement. These sit in the commencement group due eighteen months from the notification gazette; the computed date 13 May 2027 is interpretation until officially confirmed. Verified source references: https://dpdprules.org/act/8 ==================================================================== Use this checklist when engaging, appointing, using or otherwise involving a Data Processor to process personal data on your behalf for any activity related to offering goods or services to Data Principals. -------------------------------------------------------------------- A. The contract itself -------------------------------------------------------------------- [ ] 1. There is a written, valid contract with the processor before any personal data flows. Section 8(2) permits engagement only under a valid contract. [ ] 2. The contract identifies the personal data covered, the processing activities, and the purposes they serve, matching your notice and consent records. [ ] 3. Processing on your behalf is limited to your documented instructions; anything beyond them needs your prior written agreement. -------------------------------------------------------------------- B. Duties you keep as Data Fiduciary -------------------------------------------------------------------- The Act holds the Data Fiduciary responsible for complying with its provisions and the rules, including for any processing undertaken on its behalf by a Data Processor. Build the contract so you can honour each duty: [ ] 4. Security safeguards: the processor commits to reasonable security safeguards appropriate to the data and processing, and to cooperate in preventing personal data breach. [ ] 5. Breach support: the processor informs you without delay of any personal data breach and gives you what you need for the intimations to affected persons and to the Board. [ ] 6. Erasure: on withdrawal of consent or when the specified purpose is no longer served, the processor erases the personal data you made available, unless retention is necessary for compliance with law; section 8(7)(b) requires you to cause your processor to erase it. [ ] 7. Accuracy support: where the data affects a decision about the Data Principal or goes to another Data Fiduciary, the processor supports your duty of completeness, accuracy and consistency. [ ] 8. Rights support: the processor assists with access, correction and erasure requests within your published response period. [ ] 9. Subprocessing: any further processor requires your prior written approval and a contract that passes these terms through. [ ] 10. Exit: on termination, data is returned or erased, with written confirmation, subject to legal retention duties. -------------------------------------------------------------------- C. Operations -------------------------------------------------------------------- [ ] 11. A named owner on each side for personal data matters. [ ] 12. A current record of which personal data each processor holds, for breach response and erasure at scale. [ ] 13. Periodic review of the processor's safeguards, matched to the sensitivity of the data.