DPDP for BPO/KPO: processor obligations explained

DPDP for BPO/KPO: Processor Obligations Explained
DPDP · BPO/KPO · Compliance

DPDP for BPO/KPO: Processor Obligations Explained

Your client is the Data Fiduciary. You are the Data Processor. Here is exactly what the Digital Personal Data Protection Act 2023 requires from you — and the contracts, controls, and procedures you need in place before enforcement begins.

Quick Answer: Under the DPDP Act 2023, BPO and KPO firms operate as Data Processors — they process personal data on behalf of a Data Fiduciary (the client) under a written contract. Processor obligations include implementing security safeguards, notifying the fiduciary of any breach, controlling sub-processors, and deleting all personal data at contract end. Processors do not interact directly with data principals, but they can face liability for breaches caused by their own negligence.

India's BPO and KPO sector processes enormous volumes of personal data every day — customer records, HR files, medical transcriptions, financial documents, legal research. Most of this work is done on behalf of clients who are incorporated in India or who serve Indian customers. When the Digital Personal Data Protection Act 2023 comes fully into force, the legal framework governing this work will shift substantially.

If you run a BPO or KPO firm, or if you advise one, this post explains the specific obligations your organisation must meet as a Data Processor under the DPDP Act.

The Processor vs. Fiduciary Distinction

The DPDP Act 2023 draws a clear line between two roles:

  • Data Fiduciary — the entity that determines the purpose and means of processing personal data. In the BPO context, this is typically your client: the bank, the insurer, the e-commerce company, the hospital.
  • Data Processor — the entity that processes personal data on behalf of, and under the instructions of, the Data Fiduciary. This is your BPO or KPO firm.

This distinction matters enormously. The fiduciary is responsible for obtaining consent from data principals, issuing privacy notices, and responding to data principal rights requests. As a processor, you generally do not interact directly with the individuals whose data you handle. You operate under a contract with the fiduciary, and that contract governs almost everything.

That said, the processor role is not passive. The DPDP Act and the draft Rules impose specific obligations on processors, and failure to meet them can expose you to regulatory action and civil liability.

Obligation 1: The Data Processing Agreement (DPA)

Every engagement in which your firm processes personal data on behalf of a client must be governed by a written Data Processing Agreement. A standard master service agreement or NDA is not sufficient. The DPA must specify:

  • The categories of personal data being processed
  • The purpose and duration of processing
  • The security standards your firm will maintain
  • Your obligations regarding breach notification
  • Whether and how sub-processors may be engaged
  • What happens to data when the contract ends

Many BPO firms rely on client-drafted contracts and assume the client has covered the DPDP angle. This is a risky assumption. Audit your existing client contracts now and identify which ones lack a proper DPA. For a related discussion of vendor contract requirements, see our post on DPA contracts under DPDP.

Obligation 2: Security Safeguards

Section 8(4) of the DPDP Act requires Data Fiduciaries to ensure that processors implement "reasonable security safeguards." In practice, this means fiduciaries will contractually require you to meet specific security standards — and you must actually implement them, not just sign off on them.

The draft DPDP Rules reference internationally accepted standards. Expect clients (especially those in BFSI, healthcare, and e-commerce) to require:

  • Encryption of personal data at rest and in transit
  • Access controls and role-based permissions
  • Regular vulnerability assessments and penetration testing
  • Employee training on data handling and confidentiality
  • Audit logs for all access to personal data

If your firm already holds ISO 27001 or SOC 2 certification, you have a strong head start. If not, closing the gap before May 2027 should be a priority. Use our DPDP security safeguards overview as a starting checklist.

Obligation 3: Breach Notification to the Fiduciary

Under the DPDP Act, a Data Fiduciary is required to notify the Data Protection Board of India of any personal data breach "in such form and manner as may be prescribed." To fulfil this obligation, fiduciaries must first learn about the breach — and they will learn about it from you, the processor.

Your DPA must therefore require you to notify the fiduciary of any suspected or confirmed breach promptly. The draft Rules suggest a 72-hour window is likely, mirroring GDPR practice. Your internal breach response procedure should include:

  • A dedicated incident response team or contact
  • A documented escalation process from discovery to fiduciary notification
  • Template notification messages that can be completed and sent quickly
  • A breach register to document all incidents, even minor ones

Critically, you must notify even when you are not certain a breach has occurred. If you have reasonable grounds to suspect a breach, the clock starts. See our detailed guide on breach notification timelines under DPDP for the full procedure.

Obligation 4: Sub-Processor Controls

Large BPO and KPO firms routinely sub-contract work — to captive units in other cities, to specialist transcription services, to technology vendors who have access to client data. Under DPDP, each of these relationships creates a sub-processor chain that the fiduciary must be able to trace and control.

Your DPA with the fiduciary will almost certainly require you to:

  • Obtain written approval before engaging any sub-processor
  • Flow down all DPDP obligations to sub-processors via your own DPA with them
  • Remain liable to the fiduciary for any breach or non-compliance by a sub-processor
  • Maintain a register of all sub-processors with the data they access

This is an area where informal arrangements — a developer you pay on Upwork who has access to a production database, a cloud vendor whose data residency is unclear — can create serious exposure. Map your sub-processor chain before your next client audit.

Obligation 5: Data Deletion on Contract End

When a client engagement ends — whether by completion, termination, or non-renewal — all personal data belonging to that client must be returned or securely deleted. The DPDP Act's erasure obligations apply to processors via the DPA.

In practice, this requires:

  • A data inventory for each client so you know what to delete
  • A documented deletion procedure (overwrite standards, certificate of destruction)
  • A timeline for deletion (typically 30–90 days from contract end, as agreed in the DPA)
  • Written confirmation to the fiduciary that deletion is complete

Many BPO firms accumulate years of client data in cold storage, backups, and email archives. A data inventory project before enforcement begins is far less costly than a post-breach audit. For additional context on how vendor relationships are assessed under DPDP, read our post on DPDP readiness self-assessment.

What Processors Do NOT Need to Do (That Fiduciaries Do)

To be clear about scope: as a processor, you are not required to:

  • Obtain consent from the data principals whose data you process (the fiduciary does this)
  • Issue a privacy notice to data principals (the fiduciary does this)
  • Respond directly to data principal rights requests — rights erasure, correction, nomination (the fiduciary handles this, though you may need to execute the deletion or correction on their behalf)
  • Appoint a Grievance Officer (only Significant Data Fiduciaries and fiduciaries above certain thresholds need this)

This is a meaningful distinction. Your compliance scope is narrower than a fiduciary's, but it is not trivial.

Score your vendor and processor risk in minutes

Our Vendor Risk Scorecard helps BPO/KPO firms and their fiduciary clients assess data processor risk across 20+ DPDP-specific parameters — security, contract coverage, breach readiness, sub-processor controls, and more.

Get Your Vendor Risk Scorecard — ₹1,499

Frequently Asked Questions

Is a BPO/KPO firm liable under DPDP even if the client (fiduciary) is responsible for consent?

Yes, partially. While the Data Fiduciary bears primary responsibility for obtaining consent and issuing privacy notices, a Data Processor can be held liable for breaches or non-compliance that arise from the processor's own negligence or failure to implement agreed security safeguards. The DPA between you and your client will typically allocate liability — but regulators may still look to the processor if the breach originated from your systems or processes. Implementing robust security and breach notification procedures is therefore both a contractual and a regulatory obligation.

Do we need a separate DPA with every client, or can we use a standard addendum?

A standard data processing addendum (DPA addendum) that is attached to your master service agreement is entirely acceptable and is in fact the most common approach. The addendum needs to cover all the mandatory elements — purpose, security obligations, breach notification, sub-processor controls, and deletion on contract end. A generic privacy clause buried in an MSA is not sufficient. We recommend creating a standard NB-compliant DPA addendum that you attach to all new engagements and retrofit to existing ones at the next renewal.

What is the penalty for a BPO that fails to notify its client of a data breach promptly?

The DPDP Act 2023 does not set a specific penalty for processors directly — penalties are framed primarily around Data Fiduciaries failing to notify the Data Protection Board. However, if a processor's failure to notify the fiduciary promptly causes the fiduciary to miss the notification deadline to the Board, the processor will almost certainly face breach-of-contract claims and indemnity obligations under the DPA. Additionally, as the Rules are finalised, direct processor penalties may be introduced. The financial and reputational risk is substantial — a single breach can cost a BPO firm a major client contract.

Previous Post Next Post

Get Free DPDP Checklist