What a good vendor DPA looks like (with template)
An annotated walkthrough of a DPDP-compliant Data Processing Agreement — covering every must-have clause, with sample language for the three sections most organisations get wrong.
Most organisations execute dozens of vendor contracts every year. Very few of those contracts contain a Data Processing Agreement that is actually compliant with the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The gap is not malicious — it is simply that legal teams grab the first DPA template they find online, which is almost always a GDPR template, and assume it will work for Indian law.
It won't. This post walks through the seven clauses every DPDP DPA must contain, shows you sample language for three of the most commonly missing sections, and explains why you should be nervous if your vendor sends you a generic online template.
If you've completed a gap analysis (see our post on what a DPDP gap analysis report looks like), processor agreements are almost always one of the top three findings. If you're wondering how Indian DPA requirements compare to European law, see our post on GDPR vs DPDP.
Why boilerplate DPAs fail
A GDPR-compliant DPA is a good starting point, but it fails DPDP Rules 2025 on at least four specific points:
- Breach notification timeline: GDPR allows 72 hours. DPDP Rules require notification to the Data Protection Board within 6 hours of becoming aware of a breach. A DPA that references "72 hours" is non-compliant from day one.
- Grievance Officer mention: DPDP requires processors to cooperate with the Data Fiduciary's Grievance Officer on complaints. GDPR DPAs have no equivalent concept.
- Data Principal rights: DPDP gives Indian data principals specific rights (access, correction, erasure, nomination) that must be referenced in the DPA, including the processor's obligation to assist the fiduciary in responding to these requests.
- Significant Data Fiduciary obligations: If either party is or may become a Significant Data Fiduciary under Section 10, the DPA must address additional obligations including DPIA cooperation. Most GDPR templates omit this entirely.
The 7 must-have clauses
1. Purpose and scope of processing
The DPA must describe exactly what personal data is being processed, for what purpose, and under what legal basis. The processing schedule (typically an annexure) should name each category of data principal (employees, customers, website visitors), each category of personal data, the processing purpose, and the retention period.
The explicit prohibition on using data for ML training is not boilerplate — it is essential for any SaaS vendor relationship where the vendor's product may use customer data to improve models.
2. Security obligations
Vague obligations ("the processor shall maintain appropriate security measures") are unenforceable. The DPA should specify the security standard required — at minimum, ISO 27001 or SOC 2 Type II for cloud processors, with an obligation to provide current certification on request.
3. Sub-processor requirements
Most SaaS vendors use sub-processors: AWS or Azure for hosting, Stripe for payments, Mixpanel for analytics. Each sub-processor that processes your data inherits the same legal risk. The DPA must require the processor to:
- Provide a current sub-processor list (updated at least quarterly)
- Give 30 days' advance notice before adding a new sub-processor
- Execute a DPA with each sub-processor on equivalent terms
- Remain liable for any sub-processor's breach as if it were the processor's own
4. Breach notification — 6-hour requirement
The 6-hour window is short. If your vendor cannot commit to it contractually, that tells you something about their incident response capability.
5. Data Principal rights assistance
When a data principal submits an access, correction, or erasure request, your processor's systems are almost certainly involved. The DPA must obligate the processor to respond to such requests within a defined SLA — typically 48 hours for initial acknowledgement and 15 days for completion.
6. Data deletion on termination
This clause is missing from more than half the DPAs we review. On contract termination, the processor must delete all personal data within a defined period (typically 30 days) and provide a signed deletion certificate. The DPA should also specify what happens to backups — either deletion on the same schedule or secure quarantine with a defined outer limit.
7. Audit rights
The Data Fiduciary must be able to verify the processor's compliance. The DPA should give you the right to conduct (or commission) an audit of the processor's data handling practices, at least once per contract year, with 15 days' notice. The processor should be obligated to cooperate and provide documentation within a defined period.
DPA execution checklist
Before you sign any DPA, verify:
- ✅ Processing schedule (Schedule A) is attached and complete
- ✅ Breach notification timeline is 6 hours (not 72)
- ✅ Sub-processor list is current and attached
- ✅ Data deletion obligation is explicit with a defined period
- ✅ Audit rights clause is present
- ✅ Security standard is specified (not just "appropriate measures")
- ✅ Data Principal rights assistance obligation is included
- ✅ Governing law is Indian law (not UK/EU law)
For a full vendor risk assessment framework, see our post on grading your privacy policy against DPDP — many of the same principles apply to vendor documentation review. You should also review DPDP compliance pricing to understand how DPA execution fits into a complete compliance engagement.
Generate a DPDP-compliant DPA in minutes
Our DPA Generator produces a complete, DPDP Rules 2025-compliant Data Processing Agreement with all seven must-have clauses — ready to send to your vendors today.
Generate Your DPA — ₹1,999 →Frequently Asked Questions
Do we need a separate DPA with every vendor, or can one master DPA cover all of them?
You need a separate DPA (or a DPA-specific annexure to each vendor's MSA) for each vendor that processes personal data on your behalf. A single master DPA cannot cover multiple vendors because the processing schedule — which specifies what data is processed and for what purpose — is different for each vendor. However, you can use a standard DPA template with vendor-specific schedules to make execution efficient.
What if a major vendor (like AWS or Google) refuses to sign our custom DPA?
Large cloud providers publish standard DPAs that have been reviewed for DPDP compliance by their legal teams. Review the vendor's published DPA against the seven must-have clauses. If the standard DPA covers all seven — including the 6-hour breach notification and audit rights — you can accept it. Document your review in writing. If the standard DPA has gaps, request a custom DPA or negotiate an addendum for the specific clauses that are missing.
Is a DPA required even if the vendor is based in India?
Yes. The DPDP Act applies to any processing of personal data of Indian data principals, regardless of where the processor is located. A domestic vendor processing your customers' or employees' data is a Data Processor under the Act and must execute a DPA. Location does not affect the obligation — only the cross-border transfer clauses become irrelevant for purely domestic processing.