What a good vendor DPA looks like (with template)

What a good vendor DPA looks like (with template)
Shortlist Stage · Vendor Compliance

What a good vendor DPA looks like (with template)

An annotated walkthrough of a DPDP-compliant Data Processing Agreement — covering every must-have clause, with sample language for the three sections most organisations get wrong.

Quick Answer: A DPDP-compliant vendor DPA must include: purpose limitation, security obligations with specific standards, sub-processor requirements with prior notice, breach notification within 6 hours, data deletion on termination with certification, and audit rights. A boilerplate GDPR DPA fails most of these requirements because Indian law has different timelines and scope.

Most organisations execute dozens of vendor contracts every year. Very few of those contracts contain a Data Processing Agreement that is actually compliant with the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The gap is not malicious — it is simply that legal teams grab the first DPA template they find online, which is almost always a GDPR template, and assume it will work for Indian law.

It won't. This post walks through the seven clauses every DPDP DPA must contain, shows you sample language for three of the most commonly missing sections, and explains why you should be nervous if your vendor sends you a generic online template.

If you've completed a gap analysis (see our post on what a DPDP gap analysis report looks like), processor agreements are almost always one of the top three findings. If you're wondering how Indian DPA requirements compare to European law, see our post on GDPR vs DPDP.

Why boilerplate DPAs fail

A GDPR-compliant DPA is a good starting point, but it fails DPDP Rules 2025 on at least four specific points:

  • Breach notification timeline: GDPR allows 72 hours. DPDP Rules require notification to the Data Protection Board within 6 hours of becoming aware of a breach. A DPA that references "72 hours" is non-compliant from day one.
  • Grievance Officer mention: DPDP requires processors to cooperate with the Data Fiduciary's Grievance Officer on complaints. GDPR DPAs have no equivalent concept.
  • Data Principal rights: DPDP gives Indian data principals specific rights (access, correction, erasure, nomination) that must be referenced in the DPA, including the processor's obligation to assist the fiduciary in responding to these requests.
  • Significant Data Fiduciary obligations: If either party is or may become a Significant Data Fiduciary under Section 10, the DPA must address additional obligations including DPIA cooperation. Most GDPR templates omit this entirely.
Red flag: If your vendor sends you a DPA that mentions "GDPR Article 28" anywhere in its body, that document was not drafted for DPDP compliance. Request a DPDP-specific DPA or generate one through a compliant tool before signing.

The 7 must-have clauses

1. Purpose and scope of processing

The DPA must describe exactly what personal data is being processed, for what purpose, and under what legal basis. The processing schedule (typically an annexure) should name each category of data principal (employees, customers, website visitors), each category of personal data, the processing purpose, and the retention period.

Sample clause — Purpose Limitation
"The Data Processor shall process Personal Data solely for the purposes described in Schedule A to this Agreement and for no other purpose without the prior written consent of the Data Fiduciary. The Data Processor shall not use Personal Data for its own commercial purposes, including training of machine learning models, analytics, or product development, unless expressly authorised in writing."

The explicit prohibition on using data for ML training is not boilerplate — it is essential for any SaaS vendor relationship where the vendor's product may use customer data to improve models.

2. Security obligations

Vague obligations ("the processor shall maintain appropriate security measures") are unenforceable. The DPA should specify the security standard required — at minimum, ISO 27001 or SOC 2 Type II for cloud processors, with an obligation to provide current certification on request.

Sample clause — Security Standard
"The Data Processor shall implement and maintain technical and organisational measures at least equivalent to ISO/IEC 27001:2022 standards, including: (a) encryption of Personal Data in transit using TLS 1.2 or higher; (b) encryption of Personal Data at rest using AES-256 or equivalent; (c) multi-factor authentication for all personnel with access to Personal Data; (d) quarterly access reviews with documentation provided to the Data Fiduciary on request. The Data Processor shall provide evidence of current certification within 10 business days of any written request."

3. Sub-processor requirements

Most SaaS vendors use sub-processors: AWS or Azure for hosting, Stripe for payments, Mixpanel for analytics. Each sub-processor that processes your data inherits the same legal risk. The DPA must require the processor to:

  • Provide a current sub-processor list (updated at least quarterly)
  • Give 30 days' advance notice before adding a new sub-processor
  • Execute a DPA with each sub-processor on equivalent terms
  • Remain liable for any sub-processor's breach as if it were the processor's own

4. Breach notification — 6-hour requirement

Sample clause — Breach Notification
"Upon becoming aware of a Personal Data Breach, the Data Processor shall: (a) notify the Data Fiduciary within 6 (six) hours of becoming aware; (b) provide an initial notification containing: the nature of the breach, categories and approximate number of data principals affected, categories of Personal Data involved, likely consequences, and measures taken or proposed to address the breach; (c) provide a full incident report within 72 hours; (d) cooperate with the Data Fiduciary in notifying the Data Protection Board as required under the DPDP Rules 2025."

The 6-hour window is short. If your vendor cannot commit to it contractually, that tells you something about their incident response capability.

5. Data Principal rights assistance

When a data principal submits an access, correction, or erasure request, your processor's systems are almost certainly involved. The DPA must obligate the processor to respond to such requests within a defined SLA — typically 48 hours for initial acknowledgement and 15 days for completion.

6. Data deletion on termination

This clause is missing from more than half the DPAs we review. On contract termination, the processor must delete all personal data within a defined period (typically 30 days) and provide a signed deletion certificate. The DPA should also specify what happens to backups — either deletion on the same schedule or secure quarantine with a defined outer limit.

7. Audit rights

The Data Fiduciary must be able to verify the processor's compliance. The DPA should give you the right to conduct (or commission) an audit of the processor's data handling practices, at least once per contract year, with 15 days' notice. The processor should be obligated to cooperate and provide documentation within a defined period.

DPA execution checklist

Before you sign any DPA, verify:

  • ✅ Processing schedule (Schedule A) is attached and complete
  • ✅ Breach notification timeline is 6 hours (not 72)
  • ✅ Sub-processor list is current and attached
  • ✅ Data deletion obligation is explicit with a defined period
  • ✅ Audit rights clause is present
  • ✅ Security standard is specified (not just "appropriate measures")
  • ✅ Data Principal rights assistance obligation is included
  • ✅ Governing law is Indian law (not UK/EU law)

For a full vendor risk assessment framework, see our post on grading your privacy policy against DPDP — many of the same principles apply to vendor documentation review. You should also review DPDP compliance pricing to understand how DPA execution fits into a complete compliance engagement.

Generate a DPDP-compliant DPA in minutes

Our DPA Generator produces a complete, DPDP Rules 2025-compliant Data Processing Agreement with all seven must-have clauses — ready to send to your vendors today.

Generate Your DPA — ₹1,999 →

Frequently Asked Questions

Do we need a separate DPA with every vendor, or can one master DPA cover all of them?

You need a separate DPA (or a DPA-specific annexure to each vendor's MSA) for each vendor that processes personal data on your behalf. A single master DPA cannot cover multiple vendors because the processing schedule — which specifies what data is processed and for what purpose — is different for each vendor. However, you can use a standard DPA template with vendor-specific schedules to make execution efficient.

What if a major vendor (like AWS or Google) refuses to sign our custom DPA?

Large cloud providers publish standard DPAs that have been reviewed for DPDP compliance by their legal teams. Review the vendor's published DPA against the seven must-have clauses. If the standard DPA covers all seven — including the 6-hour breach notification and audit rights — you can accept it. Document your review in writing. If the standard DPA has gaps, request a custom DPA or negotiate an addendum for the specific clauses that are missing.

Is a DPA required even if the vendor is based in India?

Yes. The DPDP Act applies to any processing of personal data of Indian data principals, regardless of where the processor is located. A domestic vendor processing your customers' or employees' data is a Data Processor under the Act and must execute a DPA. Location does not affect the obligation — only the cross-border transfer clauses become irrelevant for purely domestic processing.

Previous Post Next Post

Get Free DPDP Checklist