What DPDP means for cloud service providers and their customers

What DPDP means for cloud service providers and their customers
Cloud & SaaS

What DPDP means for cloud service providers and their customers

Cloud providers are Data Processors, and their enterprise customers are Data Fiduciaries. The DPDP Act creates obligations for both — and the contracts between them need to change.

Quick Answer: Under the DPDP Act, cloud service providers that process personal data on behalf of enterprise customers are Data Processors. The enterprise customer — who determines the purpose and means of processing — is the Data Fiduciary and is ultimately responsible for compliance. Data Processing Agreements (DPAs) between the two parties must specify what the cloud provider can do with the data, prohibit onward sharing, require breach notification to the customer, and mandate deletion at contract end. Cloud providers should update their standard contracts and DPA templates for DPDP compliance; enterprise customers should review their existing cloud agreements for gaps.

Are cloud service providers Data Fiduciaries or Data Processors under DPDP?

The DPDP Act distinguishes two roles. The Data Fiduciary decides why and how personal data is processed — this is the enterprise company that chooses to store customer data in a cloud environment. The Data Processor carries out that processing on the Fiduciary's instructions — this is the cloud provider. The Fiduciary is primarily responsible for compliance; the Processor has narrower, contractually defined obligations. But if a cloud provider uses customer data for its own purposes beyond the service agreement, it steps out of the Processor role and becomes a Fiduciary for that additional processing.

What must a Data Processing Agreement with a cloud provider include under DPDP?

The contract between an enterprise and its cloud provider must function as a Data Processing Agreement under the DPDP Act. It must: describe the categories of personal data processed; specify the purposes for which the processor may use the data; prohibit the processor from using data for its own business purposes (training its own models, selling to advertisers, etc.); require the processor to implement appropriate security safeguards; mandate notification of data breaches to the enterprise within a short window; and require deletion or return of all personal data at the end of the contract. Review your existing cloud agreements against this checklist.

What security obligations apply when a cloud provider serves a Significant Data Fiduciary?

Cloud providers serving Significant Data Fiduciaries may face additional audit and security requirements. As an SDF, you cannot simply accept a cloud provider's standard security attestation — you need to be able to demonstrate through audit that the provider's safeguards meet the Board's standards. Build audit rights into your DPA, and require cloud providers to maintain relevant certifications (ISO 27001, SOC 2) and to cooperate with independent audits.

How does DPDP apply to multi-cloud environments and sub-processor chains?

Enterprise companies increasingly use multiple cloud providers or rely on cloud providers that in turn use infrastructure from others. Each link in this sub-processor chain is a Data Processing relationship, and the original Fiduciary is responsible for the whole chain. Your DPA with your primary cloud provider should require them to flow down the same data protection obligations to any sub-processors they use. Get a list of sub-processors and review it.

What must cloud providers change in their standard contracts for DPDP compliance?

Cloud providers — whether hyperscale public clouds or boutique managed service providers — need to review their standard customer agreements and update their DPA templates for DPDP. Key gaps in most current agreements: no explicit prohibition on using customer data for the provider's own model training; no defined breach notification timeline to the customer; no mechanism for handling data-subject rights requests that come to the provider; and no deletion-at-termination commitment. Fixing these contractually protects both parties.

Do cloud providers need India-region data centres to comply with DPDP?

For enterprises that may be subject to data localisation requirements — either as SDFs or because they process payment data under RBI rules — the cloud provider must be able to offer India-region storage with data residency guarantees. Verify that your cloud infrastructure can be configured to keep personal data within India, and that the provider's DPA covers the India-region processing specifically.

Frequently asked questions

As a cloud provider, are we responsible if our customer does not get consent from their end users?

No. The Data Fiduciary (your customer) is responsible for obtaining consent from data principals. As a Data Processor, you process data according to the Fiduciary's instructions. You are not responsible for the Fiduciary's consent failures — but you are responsible for your own security safeguards, your sub-processor chain, and breach notification to your customer.

Do we need separate DPAs for each region of our cloud infrastructure?

You need a DPA that covers all the processing you do on behalf of the customer, including all regions where data may be stored or processed. If you operate infrastructure in multiple countries, the DPA should specify which countries are covered and confirm that all locations meet the DPDP Act's transfer requirements (i.e., they are on the government's approved list once published).

How should we handle a data-subject rights request that comes directly to us as the cloud provider?

If a data principal contacts you directly rather than the enterprise customer, redirect them to the Data Fiduciary — the enterprise. You are not in a position to action rights requests independently because you do not know the full context of the data collection. Contractually, your DPA should require the enterprise to handle all data-subject rights requests and to instruct you if they need your assistance (for example, locating or deleting specific records).

Review your cloud DPAs for DPDP compliance

Niti Bharat's Vendor Risk Assessment covers cloud and SaaS provider contracts — identifying DPA gaps, sub-processor risks, and security safeguard requirements under the DPDP Act.

Assess Your Cloud Vendor Risk
Previous Post Next Post

Get Free DPDP Checklist