DPDP NavigatorAct 2023 · Rules 2025
All templates
Contracts & DPAsSection 8

Vendor Security Addendum Template

A security-focused addendum imposing technical and organisational safeguard requirements on vendors handling personal data.

Template
VENDOR SECURITY ADDENDUM

This Vendor Security Addendum ("Addendum") is entered into on [Date] between:

[Organization Name] ("Company") AND [Vendor Name] ("Vendor"),

and supplements the [Master Services Agreement / Data Processing Agreement] dated [Date] between the Parties. This Addendum details the technical and organisational security safeguards the Vendor must implement, giving effect to the Company's obligation under Section 8(5) of the DPDP Act, 2023 to protect personal data against unauthorised processing, breach, loss, and destruction.

1. SCOPE
This Addendum applies to all personal data of the Company's customers, employees, or other Data Principals that the Vendor accesses, stores, transmits, or otherwise processes in connection with the services described in the Principal Agreement.

2. MINIMUM SECURITY CONTROLS
The Vendor shall maintain, at minimum:
   a. Encryption of personal data at rest and in transit using industry-standard algorithms (e.g., AES-256, TLS 1.2 or higher);
   b. Role-based access controls limiting access to personal data strictly to personnel with a need to know;
   c. Multi-factor authentication for all administrative and privileged access to systems holding personal data;
   d. Activity and access logging for systems processing personal data, retained for a minimum of [12 months] or such longer period as prescribed under the DPDP Rules, 2025;
   e. Network segmentation and firewall controls isolating environments holding Company data from other Vendor tenants/clients;
   f. Regular vulnerability scanning and patch management, with critical vulnerabilities remediated within [X days] of discovery;
   g. Secure software development practices, including code review and security testing prior to production deployment.

3. PERSONNEL SECURITY
All Vendor personnel with access to Company personal data shall: undergo background verification consistent with applicable law; sign confidentiality undertakings; and complete security and data-protection training at induction and annually thereafter.

4. PHYSICAL SECURITY
Where personal data is processed or stored in physical facilities, the Vendor shall maintain access-controlled premises, visitor logging, and environmental controls (fire suppression, power redundancy) appropriate to the criticality of the systems housed.

5. SECURITY CERTIFICATIONS
The Vendor shall maintain [ISO/IEC 27001 / SOC 2 Type II / other applicable certification] and shall provide the Company with a current copy of its certification or audit report upon request, at least [annually].

6. INCIDENT NOTIFICATION AND RESPONSE
The Vendor shall notify the Company of any suspected or confirmed Personal Data Breach within [X hours] of discovery, and shall cooperate fully with the Company's investigation, providing all information necessary for the Company to meet its intimation obligations to the Data Protection Board of India and affected Data Principals under Section 8(6). The Vendor shall not make any public statement regarding an incident affecting Company data without the Company's prior written consent.

7. RIGHT TO AUDIT AND PENETRATION TESTING
The Company, or an independent third party appointed by it, may conduct security audits and penetration testing of the Vendor's environment holding Company data, on [X days'] written notice, no more than [once/twice] annually, except following a suspected breach, where notice requirements are waived.

8. SUB-PROCESSOR SECURITY
The Vendor shall ensure any approved sub-processor is bound by security obligations no less protective than those in this Addendum, and shall remain fully liable for sub-processor compliance.

9. REMEDIATION
Where an audit or vulnerability assessment identifies a material security gap, the Vendor shall submit a remediation plan within [X days] and complete remediation within [X days] thereafter, subject to the Company's approval.

10. TERMINATION FOR SECURITY FAILURE
Repeated or uncured material failure to meet the security standards in this Addendum shall constitute a material breach entitling the Company to terminate the Principal Agreement, without prejudice to other remedies.

11. GOVERNING LAW
This Addendum is governed by the laws of India and forms an integral part of the Principal Agreement.

For [Organization Name]                          For [Vendor Name]
Name: ______________________                    Name: ______________________
Title: ______________________                   Title: ______________________

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.