Contract template

DPDP data processing agreement template, with GDPR Article 28 mapped.

A processor contract for Indian personal data that meets section 8(2) of the DPDP Act and Rule 6 of the 2025 Rules, with the GDPR Article 28 clauses in brackets for when both laws apply. Copy it, fill the brackets, send it to counsel.

Last updated Published by TryTrustableNot legal advice

01

What must a DPDP data processing agreement contain?

A DPDP data processing agreement must be a valid contract under which the Data Processor processes personal data only on the Data Fiduciary's behalf, with provision for reasonable security safeguards under Rule 6. In practice it should also cover breach notice, erasure on withdrawal, sub-processors, transfers outside India and audit rights.

The statutory floor is short. Section 8(2) of the DPDP Act says a Data Fiduciary may involve a Data Processor “only under a valid contract”, and Rule 6(1)(f) of the DPDP Rules 2025 asks for an appropriate provision in that contract for reasonable security safeguards. Everything else in the template follows from duties the Act puts on the Data Fiduciary, which it can only meet if the processor co-operates: breach intimation under section 8(6), erasure under section 8(7)(b), which requires the Fiduciary to “cause its Data Processor to erase”, and ceasing processing on withdrawal under section 6(6).

The GDPR's Article 28(3) is more prescriptive, listing eight things a processor contract must stipulate. Because many Indian companies are processors or controllers under both laws, the template uses the Article 28 structure and adds the DPDP-specific duties on top.

02

How to use this template

  • Decide whether the GDPR applies. If you have no EU establishment and do not offer goods or services to, or monitor, people in the EU, delete the bracketed GDPR wording.
  • Fill Annex 1 from your record of processing. The purposes must match the ones in your consent notice. Our record of processing activities template has the same columns.
  • Make Annex 2 describe real measures. “Industry-standard security” is not a safeguard anyone can audit. Name the controls, and ask for the evidence with the vendor security questionnaire.
  • Negotiate the bracketed numbers. Breach notice hours, sub-processor notice days and erasure days are commercial choices; the template's defaults leave room inside the statutory clocks.
  • Have counsel review the liability clause. It is deliberately left open.
03

The template

Replace everything in square brackets. Plain text, so it pastes cleanly into your own contract format.

dpdp-data-processing-agreement.txt
DATA PROCESSING AGREEMENT

This Data Processing Agreement ("Agreement") is made on [date] between:

[Customer legal name], [registered address] (the "Data Fiduciary"); and
[Vendor legal name], [registered address] (the "Data Processor").

It forms part of the [Master Services Agreement / Order Form] dated [date] (the
"Principal Agreement"). If the two conflict on the processing of personal data,
this Agreement prevails.

[Drafting note: template only. Have counsel review before signing. Where the
Data Fiduciary is also a GDPR controller, keep the bracketed GDPR wording; where
it is not, delete it.]

1. DEFINITIONS
1.1 "Act" means the Digital Personal Data Protection Act, 2023, and "Rules" means
    the Digital Personal Data Protection Rules, 2025, each as amended.
1.2 "Personal data", "Data Principal", "processing", "personal data breach" and
    "Board" have the meanings given in section 2 of the Act.
1.3 [Where the GDPR applies: "controller", "processor", "data subject" and
    "supervisory authority" have the meanings given in Article 4 of Regulation
    (EU) 2016/679 ("GDPR"). References to the Data Fiduciary include it acting
    as controller, and to the Data Processor include it acting as processor.]
1.4 "Sub-processor" means any person the Data Processor engages to process
    Fiduciary Personal Data.
1.5 "Fiduciary Personal Data" means personal data processed by the Data
    Processor on behalf of the Data Fiduciary under the Principal Agreement, as
    described in Annex 1.

2. SCOPE AND INSTRUCTIONS
2.1 The Data Processor shall process Fiduciary Personal Data only on behalf of
    the Data Fiduciary, only for the purposes in Annex 1, and only on the Data
    Fiduciary's documented instructions, including with regard to transfers
    outside India [and outside the European Economic Area].
2.2 The Data Processor shall inform the Data Fiduciary without delay if, in its
    opinion, an instruction infringes the Act, the Rules [or the GDPR].
2.3 The Data Processor shall not process Fiduciary Personal Data for its own
    purposes, including training or improving machine-learning models, unless
    the Data Fiduciary has instructed it to in writing.
2.4 The parties acknowledge that the Data Fiduciary remains responsible under
    section 8(1) of the Act for processing carried out on its behalf, and that
    nothing in this Agreement transfers that responsibility.

3. CONFIDENTIALITY
3.1 The Data Processor shall ensure that every person it authorises to process
    Fiduciary Personal Data is bound by a written duty of confidentiality and
    has access only to the extent needed for the services.

4. SECURITY SAFEGUARDS
4.1 The Data Processor shall take reasonable security safeguards to prevent a
    personal data breach, including at a minimum the measures in Annex 2, which
    shall include:
    (a) encryption, obfuscation, masking or tokenisation of personal data;
    (b) control of access to the computer resources used to process it;
    (c) logging, monitoring and review of access, sufficient to detect
        unauthorised access;
    (d) back-ups and other measures for continued processing if
        confidentiality, integrity or availability is compromised;
    (e) retention of those logs and the associated personal data for one year,
        for detecting, investigating and remediating unauthorised access,
        unless a longer period is required by law; and
    (f) appropriate technical and organisational measures to ensure those
        safeguards are observed in practice.
4.2 The Data Processor shall not materially reduce the protection given by
    Annex 2 without the Data Fiduciary's prior written agreement.

5. SUB-PROCESSORS
5.1 The Data Processor shall not engage a Sub-processor without the Data
    Fiduciary's prior written authorisation. The Sub-processors listed in
    Annex 3 are authorised on signature.
5.2 The Data Processor shall give at least [30] days' written notice of any
    intended addition or replacement. The Data Fiduciary may object on
    reasonable grounds within that period, and if the objection is not
    resolved it may terminate the affected services without penalty.
5.3 The Data Processor shall impose on each Sub-processor, by written contract,
    obligations no less protective than those in this Agreement, and remains
    fully liable to the Data Fiduciary for each Sub-processor's performance.

6. DATA PRINCIPAL RIGHTS
6.1 Taking into account the nature of the processing, the Data Processor shall
    assist the Data Fiduciary, by appropriate technical and organisational
    measures, to respond to requests to exercise the rights of access,
    correction, completion, updating and erasure, grievance redressal and
    nomination under sections 11 to 14 of the Act [and the rights of data
    subjects under Chapter III of the GDPR].
6.2 The Data Processor shall forward any request it receives directly to the
    Data Fiduciary within [2] business days and shall not respond to it except
    on the Data Fiduciary's instruction.

7. PERSONAL DATA BREACH
7.1 The Data Processor shall notify the Data Fiduciary of any personal data
    breach affecting Fiduciary Personal Data without delay and in any event
    within [24] hours of becoming aware of it.
7.2 The notice shall describe, to the extent then known: the nature, extent,
    timing and location of the breach; the categories and approximate number
    of Data Principals and records affected; the likely consequences; the
    measures taken or proposed to mitigate them; and a contact point. The
    Data Processor shall supplement the notice as more becomes known.
7.3 The Data Processor shall co-operate with the Data Fiduciary so that it can
    intimate the Board and each affected Data Principal under section 8(6) of
    the Act and Rule 7 of the Rules, including the detailed report due to the
    Board within 72 hours [and notify the supervisory authority under Article
    33 of the GDPR].
7.4 The Data Processor shall not notify the Board, any Data Principal or any
    other third party of the breach except as required by law or as the Data
    Fiduciary instructs.

8. WITHDRAWAL OF CONSENT, ERASURE AND RETURN
8.1 When the Data Fiduciary notifies the Data Processor that a Data Principal
    has withdrawn consent, or that a purpose is no longer being served, the
    Data Processor shall cease processing and erase the affected Fiduciary
    Personal Data within [7] days, and confirm erasure in writing.
8.2 On termination or expiry of the services, the Data Processor shall, at the
    Data Fiduciary's choice, return or erase all Fiduciary Personal Data and
    erase existing copies within [30] days, unless retention is required by
    law, in which case it shall tell the Data Fiduciary what is retained, why
    and for how long, and protect it under this Agreement until erased.

9. TRANSFERS OUTSIDE INDIA
9.1 The Data Processor shall not transfer Fiduciary Personal Data outside India,
    or allow it to be accessed from outside India, except to the countries and
    Sub-processors listed in Annex 3 or otherwise approved in writing, and never
    to a country to which transfer is restricted by notification under section
    16 of the Act.
9.2 [Where the GDPR applies: no transfer to a third country shall take place
    except in compliance with Chapter V of the GDPR, including by the standard
    contractual clauses adopted by the European Commission where required.]

10. CHILDREN'S DATA
10.1 Where Fiduciary Personal Data relates to children, the Data Processor shall
     not undertake tracking, behavioural monitoring or targeted advertising
     directed at children, and shall process such data only as the Data
     Fiduciary instructs in line with section 9 of the Act.

11. AUDIT AND INFORMATION
11.1 The Data Processor shall make available to the Data Fiduciary all
     information necessary to demonstrate compliance with this Agreement,
     including current third-party audit reports and certifications, and shall
     allow and contribute to audits and inspections by the Data Fiduciary or an
     auditor it mandates, on [30] days' notice, no more than [once] in any
     12-month period except after a personal data breach or a request from a
     regulator.
11.2 The Data Processor shall assist the Data Fiduciary with any data protection
     impact assessment or periodic audit it is required to carry out, including
     as a Significant Data Fiduciary under section 10 of the Act [or under
     Articles 35 and 36 of the GDPR].

12. LIABILITY
12.1 [Set out the liability position. Counsel should consider whether the
     general liability cap in the Principal Agreement should apply to breaches
     of this Agreement, given the scale of penalties under the Schedule to the
     Act.]

13. TERM, GOVERNING LAW AND JURISDICTION
13.1 This Agreement lasts for as long as the Data Processor processes Fiduciary
     Personal Data. Clauses 8, 11 and 12 survive termination.
13.2 This Agreement is governed by the laws of India, and the courts at [city]
     have exclusive jurisdiction.

Signed for the Data Fiduciary: [name, title, date]
Signed for the Data Processor: [name, title, date]

ANNEX 1 - DESCRIPTION OF THE PROCESSING
Subject matter and nature of the processing: [e.g. hosting and support of CRM]
Purpose(s): [purpose, as stated in the Data Fiduciary's notice]
Categories of Data Principals: [e.g. customers, prospects, employees]
Categories of personal data: [itemised, e.g. name, email, phone, order history]
Children's data involved: [yes / no]
Duration of processing: [term of the Principal Agreement]
Locations of processing and storage: [country, region]

ANNEX 2 - SECURITY SAFEGUARDS
[List the actual measures, not intentions: encryption at rest and in transit
(algorithms), access control model and MFA, logging and log retention period,
back-up frequency and restore testing, vulnerability management, staff
screening and training, incident response contacts.]

ANNEX 3 - AUTHORISED SUB-PROCESSORS
Name | Service provided | Personal data involved | Country of processing
[ ]  | [ ]              | [ ]                    | [ ]
04

How each clause maps to DPDP and GDPR Article 28

The table shows where each clause comes from, so a reviewer can check it against the source rather than against our summary.

ClauseDPDP Act 2023 and Rules 2025GDPRWhat it is for
2. Instructionss.8(2) valid contract; s.8(1) Fiduciary stays responsibleArt. 28(3)(a), Art. 29Keeps the processor inside your stated purposes, which your notice and consents were given against.
3. Confidentialitys.8(5), Rule 6(1)(g) organisational measuresArt. 28(3)(b)Staff with access are bound personally, not only the company.
4. Security safeguardss.8(5); Rule 6(1)(a)–(g), including one-year log retention in 6(1)(e) and the contract provision in 6(1)(f)Art. 28(3)(c), Art. 32Rule 6 lists minimum measures; the clause writes them into the contract so they can be audited.
5. Sub-processorsNot prescribed; follows from s.8(1) and s.8(5)Art. 28(2), 28(4), 28(3)(d)You cannot protect data you do not know has moved to a third party.
6. Rightsss.11–14 (access, correction and erasure, grievance, nomination)Art. 28(3)(e), Chapter IIIRequests have deadlines; the processor holding the data has to help meet them.
7. Breachs.8(6); Rule 7 (Board report within 72 hours)Art. 28(3)(f), Art. 33(2)The processor usually sees the breach first. Your clock depends on its speed.
8. Withdrawal and erasures.6(6) cease processing; s.8(7)(b) cause processor to eraseArt. 28(3)(g)Withdrawal that stops at your edge does not satisfy section 6(6).
9. Transferss.16 (restriction by notification)Art. 28(3)(a), Chapter VAccess from abroad is a transfer too; name the countries.
10. Childrens.9(3) no tracking, behavioural monitoring or targeted advertisingArt. 8 (consent age)The prohibition applies to processing done for you.
11. Audits.10(2) periodic audit and DPIA for Significant Data FiduciariesArt. 28(3)(h), Art. 35–36Gives you the evidence to show the Board or an auditor.

Section references are to the DPDP Act 2023 and the DPDP Rules 2025; Article references to Regulation (EU) 2016/679. Checked September 2026.

05

When does a DPDP processor contract matter most?

A DPDP processor contract matters most when something goes wrong: a breach at the vendor, a withdrawal that needs acting on downstream, or a Board inquiry. The Data Fiduciary answers for all three under section 8(1), so the contract is how it gets the facts and the action it needs in time.

Penalties make the point. Failing to take reasonable security safeguards carries a cap of ₹250 crore, and failing to notify a breach ₹200 crore, under the Schedule to the Act; the DPDP penalties guide sets out every head, and the penalty calculator works through your own exposure. For the wider set of duties, read the DPDP Act and Rules 2025 guide.

A contract promises; it does not show. Knowing which processors hold which data, and whether an erasure that fell due was confirmed, is an operational record. The consent platform keeps a register of processors linked to the purpose that justifies each one, and records withdrawals against them.

More free templates: the full template library, including a 5×5 risk register, a record of processing activities, a vendor security questionnaire and a DPDP consent notice.

Questions

The things people ask us

Does the DPDP Act require a data processing agreement?

Yes. Section 8(2) of the DPDP Act allows a Data Fiduciary to involve a Data Processor to process personal data on its behalf only under a valid contract. Rule 6 of the DPDP Rules 2025 adds that the contract should provide for reasonable security safeguards. The Act does not prescribe the other clauses, so most teams borrow the structure of GDPR Article 28.

Can we just use our GDPR Article 28 DPA for Indian processing?

Mostly, with additions. A GDPR DPA already covers instructions, confidentiality, sub-processors, assistance with rights, breach notice, deletion and audit. For DPDP, add the Rule 6 security minimums including one-year log retention, the section 8(6) and Rule 7 breach timeline, erasure on withdrawal under section 8(7), the section 16 transfer restriction, and the section 9 limits on children's data.

Does signing a DPA move DPDP liability to the processor?

No. Section 8(1) keeps the Data Fiduciary responsible for processing carried out on its behalf, irrespective of any agreement to the contrary. The Board's penalties fall on the Data Fiduciary. The contract gives you operational control and a claim against the processor, which is why the liability clause deserves more attention than it usually gets.

How fast should a processor report a breach to us?

Faster than you have to report onward. Rule 7 requires the Data Fiduciary to give the Board a detailed report within 72 hours of becoming aware, and the GDPR sets 72 hours for notifying the supervisory authority. A processor window of 24 hours, with a duty to supplement, leaves time to investigate. The template leaves the number in brackets for negotiation.

Do we need a separate DPA for every vendor?

You need a valid contract with every Data Processor, but it does not have to be a separate document. Many vendors publish a standard DPA incorporated into their terms. Review it against this template's clauses, especially sub-processor notice, breach timing, erasure on withdrawal and transfers, and negotiate or add an addendum where something is missing.

Is the DPDP Act's processor contract requirement already in force?

The Act and Rules were notified on 14 November 2025, and most substantive duties, including sections 8 and 9 and Rules 6 and 7, apply from 13 May 2027. Contracts signed now will still be running then, so writing the DPDP clauses in at renewal is cheaper than reopening every contract in 2027.

Book a walkthrough

Know which processor holds what.

We map your processors to purposes and consents live on the call, and show where a withdrawal would need to reach.