All templates
Contracts & DPAsSection 8
Data Processing Agreement (DPA) Template
A contract between a Data Fiduciary and its Processor allocating DPDP-compliant processing instructions and security obligations.
Template
DATA PROCESSING AGREEMENT
This Data Processing Agreement ("Agreement") is entered into on [Date] between:
[Organization Name], having its registered office at [Address] ("Data Fiduciary"),
AND
[Processor Name], having its registered office at [Address] ("Processor"),
each a "Party" and collectively the "Parties".
This Agreement supplements the [Master Services Agreement / Order Form] dated [Date] between the Parties ("Principal Agreement") and governs the Processor's processing of personal data on behalf of the Data Fiduciary, consistent with the requirement under Section 8(2) of the DPDP Act, 2023 that any such processing be governed by a valid contract.
1. DEFINITIONS
"Personal Data", "Data Principal", "Processing", and "Personal Data Breach" shall have the meanings assigned under the DPDP Act, 2023 and the DPDP Rules, 2025. "Instructions" means the documented processing instructions issued by the Data Fiduciary as set out in Annexure A.
2. SUBJECT MATTER AND DURATION
The Processor shall process personal data described in Annexure A solely for the duration of the Principal Agreement, or until earlier termination of this Agreement.
3. SCOPE OF PROCESSING
Annexure A sets out: (a) categories of Data Principals; (b) categories of personal data; (c) nature and purpose of processing; (d) duration of processing. The Processor shall not process personal data for any purpose other than as instructed in writing by the Data Fiduciary.
4. PROCESSOR OBLIGATIONS
The Processor shall:
a. Process personal data only on the documented instructions of the Data Fiduciary, including with regard to cross-border transfers;
b. Implement appropriate technical and organisational security safeguards, including encryption, access controls, and activity logging (retained for a minimum period consistent with the DPDP Rules, 2025), to prevent unauthorised access, alteration, disclosure, or loss;
c. Ensure personnel authorised to process personal data are bound by confidentiality obligations;
d. Not engage a sub-processor without the Data Fiduciary's prior written approval, and flow down equivalent obligations to any approved sub-processor via a Sub-Processor Addendum;
e. Assist the Data Fiduciary, insofar as reasonably possible, in responding to Data Principal rights requests (access, correction, erasure) under Sections 11 and 12;
f. Notify the Data Fiduciary of any Personal Data Breach without undue delay, and in any event within [X hours] of becoming aware, providing all information reasonably required for the Data Fiduciary to meet its intimation obligations under Section 8(6);
g. At the Data Fiduciary's election, delete or return all personal data upon termination of this Agreement, except where retention is required by law, and certify such deletion in writing.
5. AUDIT AND INSPECTION
The Data Fiduciary, or an independent auditor appointed by it, may audit the Processor's compliance with this Agreement on [X days'] written notice, no more than [once/twice] per year, except where triggered by a suspected breach.
6. SUB-PROCESSING
Any approved sub-processor must be bound by written terms no less protective than this Agreement. The Processor remains fully liable to the Data Fiduciary for the acts and omissions of its sub-processors.
7. CROSS-BORDER TRANSFER
Where the Processor processes personal data outside India, such transfer shall comply with Section 16 of the DPDP Act and any Government notification restricting transfers to specific countries or territories, as detailed in the Cross-Border Data Transfer Clause attached as Annexure B, if applicable.
8. LIABILITY AND INDEMNITY
The Processor shall indemnify the Data Fiduciary against losses, penalties, and costs arising from the Processor's breach of this Agreement or non-compliance with the DPDP Act, 2023, to the extent set out in the Principal Agreement.
9. TERM AND TERMINATION
This Agreement remains in effect for so long as the Processor processes personal data on the Data Fiduciary's behalf, and survives termination of the Principal Agreement to the extent necessary to give effect to Clause 4(g).
10. GOVERNING LAW
This Agreement shall be governed by the laws of India, with courts at [City] having exclusive jurisdiction.
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the date first written above.
For [Organization Name] For [Processor Name]
Name: ______________________ Name: ______________________
Title: ______________________ Title: ______________________
ANNEXURE A: Description of Processing (Data Principals, Data Categories, Purpose, Duration)
ANNEXURE B: Cross-Border Transfer Details (if applicable)This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.