Tool
Vendors and Data Processors
Not every vendor is a Data Processor. Answer 1 question about the actual engagement and get the actions the official text points to for that relationship, with owners and sources.
Definitions:
Answer how the vendor touches personal data to see the actions that fit the relationship.
Answers stay on this page. The right classification depends on the facts of each engagement; mixed engagements can put one vendor in more than one category at once.
The provisions this tool rests on
The provisions below are the sources for the legal statements on this page. Each links to the official document it was verified against, and to the provision on this site wherever this site publishes that provision. The label says whether the site is reporting a requirement, explaining it, reading it, recommending something, or pointing at a text it does not restate.
DPDP Act 2023, s. 8, (2)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.
DPDP Act 2023, s. 8, (1)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.
DPDP Rules 2025, r. 6
Official requirement · Verified 16 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum, — (a) appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data; (b) appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable; (c) visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence; (d) reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups; (e) for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise; (f) appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards; and (g) appropriate technical and organisational measures to ensure effective observance of security safeguards.
Rule 6 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 8, (5)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
DPDP Act 2023, s. 8, (7)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor.
DPDP Rules 2025, r. 8, (3)
Official requirement · Verified 16 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(3) Without prejudice to sub-rules (1) and (2), a Data Fiduciary shall retain, in respect of any processing of personal data undertaken by it or on its behalf by a Data Processor, such personal data, associated traffic data and other logs of the processing for a minimum period of one year from the date of such processing, for the purposes as specified in the Seventh Schedule, after which the Data Fiduciary shall cause such personal data and logs to be erased, unless further retention is required for compliance with any other law for the time being in force or notified by the Government.
Rule 8 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 8, (6)
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.
DPDP Rules 2025, r. 7
Official requirement · Verified 16 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary, — (a) a description of the breach, including its nature, extent and the timing of its occurrence; (b) the consequences relevant to her, that are likely to arise from the breach; (c) the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk; (d) the safety measures that she may take to protect her interests; and (e) business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal. (2) On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, — (a) without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact; (b) within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, — (i) updated and detailed information in respect of such description; (ii) the broad facts related to the events, circumstances and reasons leading to the breach; (iii) measures implemented or proposed, if any, to mitigate risk; (iv) any findings regarding the person who caused the breach; (v) remedial measures taken to prevent recurrence of such breach; and (vi) a report regarding the intimations given to affected Data Principals.
Rule 7 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Rules 2025, r. 15
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
Any personal data processed by a Data Fiduciary under the Act may be transferred outside the territory of India subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State.
Rule 15 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 16
Official requirement · Verified 17 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. (2) Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.
DPDP Rules 2025, r. 13, (4)
Official requirement · Verified 26 August 2026
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed
(4) A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India.
Rule 13 on this site Official source ↗ Also on MeitY (byte identical) ↗
DPDP Act 2023, s. 2(k)
Official requirement · Verified 17 August 2026
In force since 13 November 2025
“Data Processor” means any person who processes personal data on behalf of a Data Fiduciary
DPDP Act 2023, s. 2(i)
Official requirement · Verified 17 August 2026
In force since 13 November 2025
“Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (2), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (1), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
- [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (5), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [5]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (7), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [6]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, (3), p. 27. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
- [7]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, (6), p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [8]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 16 August 2026
- [9]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 15, p. 30. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026
- [10]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 16, p. 11. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [11]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, (4), p. 29. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 26 August 2026
- [12]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(k), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
- [13]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(i), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026
Read the guide
DPDP data processing agreement clauses The clause by clause drafting guide, including which clauses have no statutory basis at all.