DPDP for IT services firms: what your clients now demand
Enterprise clients in BFSI, healthcare, and e-commerce are passing DPDP obligations to IT vendors through contracts. Here is exactly what they expect — and the practical minimum you need to demonstrate.
The compliance requirements of large enterprises do not stay within their own walls for long. Regulatory pressure on banks, hospitals, insurers, and large e-commerce platforms has a well-documented tendency to flow downstream — to their technology vendors, BPO partners, and IT service providers. GDPR did this in Europe. India's DPDP Act 2023 is doing the same thing, faster, because Indian enterprise procurement teams learned the pattern from watching European peers.
If you run or lead compliance at an Indian IT services firm — application development, managed services, cloud operations, testing, or analytics — your enterprise clients are almost certainly either already asking about DPDP compliance or will be within the next two quarters. Understanding precisely what they are asking for, and what evidence satisfies their requirements, is the difference between a smooth contract renewal and a painful six-week delay.
If you are still trying to understand why you have started receiving DPDP security questionnaires from clients, start there. This post assumes you understand the context and want to know specifically what your clients' procurement teams are looking for.
Why BFSI, healthcare, and e-commerce clients are leading this push
Not all enterprise clients are at the same stage of DPDP enforcement. The sectors pushing hardest on vendor compliance are those with the most exposure to regulatory scrutiny.
BFSI (Banking, Financial Services, Insurance): Banks regulated by RBI and insurers regulated by IRDAI already operate under stringent data governance frameworks. The DPDP Act adds another layer — and RBI has already signalled that third-party data governance will be a focus area for bank audits. A bank that cannot demonstrate that its IT vendors have DPDP compliance in place is exposed in its next RBI inspection. This creates strong downstream pressure on every vendor that processes customer account data, transaction data, or KYC information.
Healthcare: Health data is among the most sensitive categories under DPDP, and hospitals and diagnostics chains are acutely aware of the reputational risk of a health data breach. IT vendors who handle electronic health records, diagnostic imaging systems, or patient management software are being asked to demonstrate compliance early, well ahead of the 2027 deadline.
E-commerce: Large e-commerce platforms process enormous volumes of consumer data — purchase history, delivery addresses, payment methods — and face class-action style complaints from consumers under the consumer protection framework as well as DPDP. These platforms are treating vendor compliance as a liability management measure: if a vendor breach exposes their customer data, they want contractual proof that the vendor was compliant and they can pass liability downstream.
The most common clauses clients are inserting into vendor contracts
Here are the specific contract clauses that IT vendors are encountering most frequently when enterprise clients enforce DPDP requirements:
Data processing purpose limitation
The client inserts a clause stating that the vendor may only process the client's personal data for the specific purpose defined in the statement of work, and may not use it for any other purpose — including training the vendor's own AI models, internal analytics, or benchmarking — without prior written consent. For SaaS vendors who collect aggregate usage data, this clause can conflict with existing product terms and requires careful legal review.
Sub-processor approval requirement
The vendor must list all sub-processors (cloud providers, offshore teams, subcontractors) who will access the client's personal data, obtain prior written approval before adding new sub-processors, and flow down the same DPDP obligations. For mid-size IT firms using AWS, Azure, or GCP and offshore development teams, this clause requires building a sub-processor register and a notification process that most firms do not currently have.
Breach notification SLA
The most common requirement is notification to the client within 24–48 hours of a personal data breach discovery — regardless of whether the breach is confirmed or still under investigation. This is because the client's own notification obligation to the Data Protection Board runs from the moment the Fiduciary becomes aware of the breach, and they cannot afford to have that clock running while their vendor deliberates about whether to escalate. Vendors without a documented incident detection and escalation process will struggle to meet this SLA.
Audit rights
Enterprise contracts increasingly include a right for the client to audit the vendor's data protection practices — either directly or through a third-party auditor — with reasonable notice. This clause is negotiable: vendors typically push for audit notice periods (30 days minimum), cost allocation (audits at the client's cost), frequency limits (once per year absent a breach), and audit-by-questionnaire as an alternative to on-site visits. Most enterprise clients will accept reasonable audit right limitations if the vendor negotiates them at the contract stage rather than resisting the clause entirely.
Compliance representations and warranties
Some contracts require the vendor to represent and warrant — meaning legally assert — that it complies with the DPDP Act at the time of contract signing and will maintain compliance throughout the engagement. If this representation is false, it can be a ground for termination and damages. Vendors must not sign this clause without having actually assessed their DPDP compliance status. Signing a warranty you cannot support is worse than disclosing a gap and committing to a remediation timeline.
What "DPDP-ready" actually means to a procurement team
When a client's vendor risk team reviews a vendor's DPDP compliance documentation, they are not expecting perfection. They are making a risk assessment: is this vendor's compliance posture good enough that we are comfortable sharing personal data with them? The bar is proportionate to the sensitivity of the data and the scale of the engagement. Here is what passes that assessment for most enterprise clients in India right now:
- A written applicability assessment: A document showing that you have formally asked the question "does DPDP apply to us and in what capacity?" and answered it. This does not need to be a legal opinion — a structured self-assessment (using the DPDP Readiness Score tool, for example) is sufficient for most clients.
- A record of processing activities: A simple register listing what personal data you process, for what purpose, on whose behalf, where it is stored, and how long you keep it. A well-formatted spreadsheet works. Most enterprise clients have a template they will share if you ask.
- A Data Processing Agreement: A signed DPA or a DPA template you are willing to sign. Clients whose legal team drafted the DPA want their template signed; the negotiation is about specific clauses, not the existence of the document.
- A breach notification procedure: A one-page document describing how your team detects, escalates, and reports a personal data breach. It needs to be specific enough to demonstrate that someone has actually thought about it — not a generic "we take security seriously" statement.
- Evidence of security controls: Either a security certification (ISO 27001, SOC 2) or a completed security questionnaire describing your controls. Enterprise clients in BFSI typically have their own questionnaire; smaller clients often accept a vendor-completed standard questionnaire.
- A named data protection contact: A name, job title, and email address for the person at your company responsible for data protection queries. This signals accountability and is trivially easy to provide — yet many vendors leave the questionnaire field blank.
The minimum viable compliance programme for a mid-size IT firm
You do not need a full-time Data Protection Officer, a dedicated compliance team, or expensive third-party certification to pass an enterprise vendor review. What you need is systematic documentation of practices you are already likely following informally. The practical minimum includes:
- A completed DPDP applicability assessment on file
- A record of processing activities — even a spreadsheet
- A signed or signable DPA template
- A written breach notification procedure (24-hour internal, 48-hour to client)
- A privacy policy on your website
- Employee confidentiality agreements that cover personal data
- A named internal owner for data protection
This foundation can be built in two to four weeks with focused effort. The vendors who are losing deals to DPDP requirements are mostly losing them not because compliance is genuinely hard to achieve, but because no one has been assigned to build even this minimum foundation. As we cover in our post on how DPDP compliance affects enterprise deals, the revenue cost of that gap is now quantifiable.
Understanding your classification — whether you are a Data Fiduciary or Data Processor for each client engagement — is the first step in building a compliance programme that is proportionate to your actual obligations.
Find out exactly how DPDP-ready your IT firm is right now
Our DPDP Readiness Score gives you a detailed assessment of your compliance posture across all key DPDP domains — with a prioritised action plan to close your gaps.
Get My Readiness Score — ₹999Frequently Asked Questions
Does every IT vendor in India need to comply with DPDP?
Any company that processes personal data of Indian residents — which includes virtually every company with Indian employees, customers, or client data — falls within the DPDP Act's scope. The obligations and their intensity vary: companies that are only Data Processors (not Fiduciaries) have fewer direct statutory obligations, though they have significant contractual obligations to their Fiduciary clients. There is no blanket exemption for small companies, though the government may designate certain low-risk categories differently in the Rules.
Do offshore development teams and outsourced IT staff need to comply with DPDP?
If your offshore teams process personal data of Indian residents — whether as part of a client delivery or for internal purposes — DPDP applies. The Act does not limit its scope to India-based entities; it follows the data. An IT firm with development teams in other countries but processing Indian customer data is in scope. The practical implication is that sub-processor agreements, access controls, and data transfer documentation need to cover offshore team members explicitly.
How long does it take to build a DPDP-compliant vendor posture?
For a mid-size IT firm starting from scratch, the minimum viable compliance documentation described in this post can typically be completed in two to four weeks of focused effort. A more comprehensive programme — including a full data inventory, employee training, DPA negotiations with your own sub-processors, and a security controls audit — typically takes three to six months. The urgency is determined by your client pipeline: if you have enterprise deals pending that require DPDP documentation, the minimum viable set is what you need first.