Data privacy (DPDP Act, 2023) · Template

Vendor data processing agreement (DPA) addendum

The DPDP Act does not let you outsource responsibility along with the data. If a vendor processes personal data on your behalf, s. 8(5) requires that engagement to sit under a valid contract — and if they lose it, you are still the fiduciary answering for it. A DPA addendum is how that contract gets added without reopening the commercial terms.

Generate this document See all 21 templates

When you need this

  • Before any vendor touches customer personal data — CRM, payroll, delivery, analytics, support
  • When a payment gateway or marketplace requires it during onboarding
  • As the remediation step after a DPDP readiness assessment flags vendor contracts
  • When an existing supplier agreement predates the DPDP Act and says nothing about processing
  • Where a vendor uses sub-processors of its own, which needs to be surfaced and controlled

What this document must contain

  • Scope: categories, purposes and duration — What data, for what, for how long. A DPA that does not bound the processing authorises all of it.
  • Processing only on documented instruction — The processor acts for your stated purpose, not its own. Without this, vendor use of your customer data for its own analytics is not clearly a breach.
  • Security safeguards — Reasonable security safeguards are an obligation the fiduciary carries. The addendum passes a defined standard down and gives you something to audit against.
  • Sub-processing controls — Prior authorisation, and flow-down of the same obligations. Most breaches happen a layer below the vendor you actually chose.
  • Breach notification, with a stated window — You cannot meet the s. 8(6) intimation duty if you learn about the breach late. Fix a short window and require enough detail to act on.
  • Assistance with data principal rights — Access, correction and erasure requests reach you but the data often sits with the vendor. Their cooperation has to be contractual.
  • Deletion or return on termination — With written confirmation. A vendor that keeps a copy after exit is a liability you no longer have visibility into.

The law that governs it

  • DPDP Act, 2023 — s. 8(5) — A data fiduciary may engage, appoint or otherwise involve a data processor to process personal data on its behalf only under a valid contract. This addendum exists to satisfy that requirement.
  • DPDP Act, 2023 — s. 8(6) — On a personal data breach, the fiduciary must give intimation to the Board and to each affected data principal. Meeting that duty depends on the vendor telling you quickly, which is a contractual matter.
  • DPDP Act, 2023 — the Schedule — Penalties are assessed against the fiduciary. Contracting with a processor does not move the exposure — it only gives you a route to recover against them.

Common mistakes

  • Assuming the vendor's standard terms already cover it, when those terms are usually written to protect the vendor
  • Signing a GDPR DPA unchanged, which cites the wrong statute and misses the s. 8(6) intimation duty
  • No breach notification window, so you find out too late to meet your own obligation
  • Silence on sub-processors, leaving an uncontrolled chain below the vendor you assessed
  • No deletion obligation on exit, so copies persist indefinitely with no visibility

Frequently asked questions

Do I need a DPA with every vendor?

With every vendor that processes personal data on your behalf. Section 8(5) of the DPDP Act, 2023 permits engaging a processor only under a valid contract, and that reaches further than most businesses expect — payroll providers, CRM and support tools, delivery partners, analytics and email platforms all commonly qualify.

Is a GDPR DPA sufficient in India?

Not on its own. A GDPR DPA is built around a different statute and will not reference the DPDP Act's own duties, including the s. 8(6) breach intimation requirement and the rights framework in ss. 11 to 13. An India-specific addendum, or an amendment to the GDPR DPA, is needed.

Who is liable if the vendor causes a breach?

The data fiduciary carries the obligations under the Act, and penalties under the Schedule are assessed accordingly. A DPA does not transfer that exposure; it establishes the vendor's obligations to you and gives you a contractual route to recover, which is a different thing.

What breach notification window should I require?

Short enough that you can still meet your own intimation duty under s. 8(6) after receiving it. Because your obligation runs from the breach rather than from the vendor's disclosure, the contractual window has to leave you time to act, not consume it.

Related documents