How to negotiate a DPDP Data Processing Agreement with a vendor

How to negotiate a DPDP Data Processing Agreement with a vendor
DPA Negotiation

How to negotiate a DPDP Data Processing Agreement with a vendor

A DPA is not a formality — it is your legal protection when a vendor mishandles personal data. Here is how to negotiate one that actually works under DPDP.

Quick Answer: A Data Processing Agreement under the DPDP Act is a binding contract between a Data Fiduciary and a Data Processor specifying the terms on which the Processor handles personal data on behalf of the Fiduciary. The DPA must cover: the scope and purpose of processing; restrictions on use for the Processor's own purposes; security obligations; sub-processor controls; breach notification timelines; data deletion on contract termination; audit rights; and cross-border transfer controls. Many vendors offer standard DPAs that are designed to minimise their liability — here is what to push back on and what terms to insist on.

What are the mandatory components of a DPDP-compliant DPA?

A DPDP DPA must include: a description of the processing (what data, for what purposes, for how long); a prohibition on the Processor using the data for any purpose other than those specified; the security measures the Processor must implement; requirements for sub-processor engagement (prior approval, flow-down obligations); breach notification — the Processor must notify the Fiduciary promptly and in any event within 24–48 hours of discovery; the obligation to delete data on termination; audit rights — the Fiduciary must be able to verify compliance; and acknowledgement that the Processor acts only on the Fiduciary's written instructions.

What clauses do most vendor DPAs get wrong?

The most common deficiencies: vague sub-processor lists ('we may engage sub-processors worldwide' without naming them); 30-day breach notification to you (too long — DPDP requires you to notify the Board promptly, so you need 24–48 hours from the vendor); data deletion timelines that give the vendor months to delete after termination; no audit rights (replaced with 'you may ask us for a summary of our certifications'); and purpose limitation clauses that allow the vendor to use your data for product improvement or AI training without your consent.

How do you push back on a large SaaS vendor's standard DPA?

Large SaaS vendors (Salesforce, HubSpot, AWS) have standard DPAs they issue to all customers, with limited flexibility. Focus your pushback on: sub-processor lists (ensure they provide specific, named sub-processors and notification of changes); breach notification timeline (push for 24 hours notice to you, not 72); AI/ML training opt-out (ensure your data is not used to train models without your consent); and data deletion certification on termination. Many enterprise SaaS vendors will accept a redline on these specific clauses, particularly for larger contract values.

How do you handle DPA negotiations with small Indian vendors?

Small Indian vendors — local software providers, regional IT firms, data entry outsourcing companies — often have no DPA at all. In this case, you draft the DPA and ask them to sign it. Use a simple, clear template covering the mandatory DPDP clauses. Small vendors may push back on audit rights and insurance requirements — but insist on the core obligations: purpose limitation, security measures, breach notification to you within 48 hours, and deletion on termination. A vendor that refuses to sign any form of DPA is not a vendor you should give personal data to.

What security standards should you require from vendors in a DPA?

At a minimum, require: encryption of personal data at rest and in transit; access controls and multi-factor authentication; regular security testing (penetration testing at least annually); ISO 27001 certification or equivalent for high-risk vendors; and the right to receive a copy of the vendor's most recent security audit report. For vendors with access to sensitive personal data (health, financial, biometric), require higher standards: SOC 2 Type II, named-individual access controls, and data segregation (your data should not comingle with other customers' data).

What happens to a DPA when the contract with the vendor ends?

The DPA should specify that on contract termination, the Processor must: (a) stop all processing of your personal data; (b) delete all copies of your personal data from its systems and those of any sub-processors within a defined period (30 days is standard; 60 days may be acceptable for complex systems); (c) certify deletion in writing. The certification of deletion is important — it is your audit evidence that the vendor has complied. If the vendor retains data beyond the specified period for their own legitimate reasons (tax records, legal holds), the DPA should specify what data can be retained, for how long, and with what restrictions.

Frequently asked questions

Does a DPA replace a Non-Disclosure Agreement?

No. A DPA and an NDA serve different purposes. An NDA covers confidential business information (product roadmaps, trade secrets, financial data). A DPA covers the data protection obligations for personal data specifically. You typically need both in a vendor relationship: an NDA for business confidentiality and a DPA for personal data protection. Some companies combine them into a single data protection and confidentiality agreement, but the personal data obligations must be specifically and clearly addressed.

Can we use a GDPR standard contractual clause as a DPA under DPDP?

GDPR SCCs were designed for EU law and include references to EU regulatory authorities, EU transfer mechanisms, and EU data subject rights — which are different from DPDP. They cannot be used as a substitute for a DPDP DPA. However, a GDPR-compliant DPA from a major SaaS vendor provides a reasonable starting point for DPDP compliance in practice — many of the underlying obligations overlap. Review the SaaS vendor's GDPR DPA against the DPDP requirements and supplement where DPDP requirements are additional.

How do we manage DPAs for dozens of vendors?

Build a vendor DPA register: a spreadsheet or contract management tool listing each vendor, whether a DPA is in place, the date of execution, the renewal date, the key breach notification SLA, and the data categories covered. Review the register quarterly — lapsed DPAs and new vendor relationships without DPAs are a systematic risk. Assign each new vendor procurement to a stage-gate where legal review of the DPA is a required step before any personal data is shared with the vendor.

Review your vendor DPAs for DPDP compliance

Niti Bharat's Vendor Risk Assessment reviews your existing DPAs, identifies gaps, and provides a model DPA template and negotiation guide for DPDP compliance.

Start Vendor DPA Review
Previous Post Next Post

Get Free DPDP Checklist