Corporate agreements

Data Processing Agreement under the DPDP Act, 2023

A Data Processing Agreement (DPA) is a contract between a Data Fiduciary and a Data Processor that governs the processing of personal data. It operationalises the statutory mandate under the Digital Personal Data Protection Act, 2023 (DPDP Act) and defines the scope, purpose, and standards for data handling by the processor.

This document is executed as a private commercial contract and does not require court filing or registration. It is the valid contract required by Section 8(2) of the DPDP Act, without which a Data Fiduciary cannot engage a Data Processor.

Governing law
Digital Personal Data Protection Act, 2023
Sections
s. 2s. 8s. 9s. 10

When this is the right filing

  • When a Data Fiduciary engages a third-party service provider to process personal data on its behalf.
  • To comply with the mandatory contract requirement under Section 8(2) of the DPDP Act before outsourcing any data processing activity.
  • When the Data Fiduciary needs to bind the Data Processor to specific security measures and processing instructions.
  • When the Data Fiduciary is classified as a Significant Data Fiduciary under Section 10 and requires additional contractual safeguards.
  • Do not use this agreement for a standard service contract where the vendor determines the purpose and means of processing; in that scenario, the vendor is itself a Data Fiduciary.

What the court looks for

  • Clear identification of the Data Fiduciary and Data Processor using the precise statutory terminology of the DPDP Act.
  • A defined and limited purpose for processing, along with the nature, type, and volume of personal data as detailed in the schedules.
  • Specific security measures and technical safeguards undertaken by the Data Processor, as listed in Schedule 2.
  • An unequivocal obligation on the Data Processor to process data only on the documented instructions of the Data Fiduciary.
  • Provisions for breach notification and the processor's duty to assist the fiduciary in meeting its obligations to Data Principals and the Data Protection Board of India.

The structure the court expects

The components of the filed format, in the order they appear. LexPilot fills every one of them from your facts and papers.

  1. 1Recitals
  2. 2Schedule 1 — details of processing
  3. 3Schedule 2 — security measures
How it opens
WHEREAS, under the Principal Agreement, the Data Processor processes personal data on behalf of the Data Fiduciary; AND WHEREAS the Parties wish to record their respective obligations in respect of such processing in accordance with the Digital Personal Data Protection Act, 2023 and the rules made thereunder ("DPDP Act").

Bracketed items are filled from your case.

Frequently asked questions

Is this agreement required to be registered or notarised?

No. A Data Processing Agreement is a simple contract governed by the Indian Contract Act, 1872, read with the DPDP Act. It requires nominal state stamp duty but does not require registration or notarisation.

Can I use GDPR terminology like 'controller' and 'processor' in this agreement?

No. The DPDP Act uses distinct terminology. You must use 'Data Fiduciary' instead of 'controller' and 'Data Processor' instead of 'processor'. The individual is a 'Data Principal', not a 'data subject', and the regulator is the 'Data Protection Board of India'.

What happens if the Data Processor causes a personal data breach?

Under Section 8 of the DPDP Act, the Data Fiduciary remains liable to the Data Principal even when processing is outsourced. The Data Processor's liability flows from this contract, which should include an obligation to notify the Data Fiduciary of any breach without undue delay.

Draft this in LexPilot — free

Free trial · Drafting assistance, not legal advice — always verify before filing.