Every vendor, cloud provider, payment gateway, or third-party tool that processes your customers' personal data is your legal responsibility under the DPDP Act 2023. Without a valid Data Processing Agreement, you are fully liable for their non-compliance. We draft and review watertight DPAs that protect your business — completely.
Under the DPDP Act 2023, you — as the Data Fiduciary — remain fully responsible for how your processors and vendors handle personal data. A data breach at your CRM provider, payment gateway, or cloud host is legally your breach. A DPA is the contractual mechanism that shifts appropriate liability, mandates vendor obligations, and protects your business if things go wrong.
Without a DPA with each processor, you bear full regulatory liability for every data incident across this entire chain.
Operating without a DPA means no contractual limits on what your vendor can do with your customers' data. They can retain it indefinitely, use it for their own purposes, and share it freely — and you are legally responsible for all of it.
Vendor standard terms are written to protect the vendor — not you. They typically disclaim liability for data breaches, allow broad data use, and contain no DPDP-specific obligations. Clicking "I agree" to their terms does not create a valid DPA.
Contracts signed before the DPDP Act 2023 don't include mandatory clauses on data localisation, breach notification timelines, sub-processor restrictions, or audit rights. These contracts need immediate amendment.
Your vendor often uses their own sub-processors — AWS, Google, Twilio, etc. Without sub-processor flow-down clauses in your DPA, your data protection obligations stop at your vendor's door while liability flows all the way back to you.
From initial drafting to reviewing and updating existing vendor contracts — we cover every data-sharing relationship your business has.
Full DPA draft covering processing instructions, data categories, purpose limitations, security obligations, breach notification duties, sub-processor controls, audit rights, data deletion on termination, and liability caps — tailored to your specific vendor relationship.
Review of DPAs provided by your vendors — identifying missing DPDP clauses, unfavourable liability terms, inadequate security standards, and unacceptable sub-processor provisions. Delivered with a redline version and negotiation guidance.
Systematic review of all your third-party vendor relationships — identifying which vendors process personal data, which have valid DPAs, which need new agreements, and which pose the highest compliance risk. Delivered as a prioritised vendor risk register.
DPDP-compliance addenda for existing vendor contracts — adding mandatory data protection clauses without requiring full contract renegotiation. Faster and more cost-effective for established vendor relationships.
Agreements for transferring personal data to processors outside India — covering DPDP Act restrictions on cross-border transfers, approved country frameworks, standard contractual clauses, and data localisation requirements for regulated sectors.
Where two businesses jointly determine the purpose and means of processing (co-branded products, data sharing partnerships, joint marketing), we draft Joint Controller Agreements clearly allocating DPDP responsibilities, liabilities, and Data Principal rights handling between both parties.
Every DPA we draft contains all mandatory elements required by the DPDP Act 2023 — and the commercial protections your business needs beyond bare compliance.
Explicit written instructions specifying exactly what the processor may do with the data — categories processed, permitted purposes, geographic restrictions, and prohibitions on any use beyond the contracted scope.
Minimum security standards the processor must maintain — encryption at rest and in transit, access controls, penetration testing frequency, security certifications (ISO 27001, SOC 2), and incident response standards.
Contractual obligation to notify you of any data breach within a specific timeframe (typically 24–48 hours) — giving you sufficient time to fulfil your own DPDP Act notification obligations to the Data Protection Board.
Prior written consent requirement before the processor engages sub-processors, with obligation to flow down identical data protection terms — ensuring your DPDP obligations cascade through the entire processing chain.
Your contractual right to audit the processor's data protection practices — either directly or via an independent third party — to verify compliance with the DPA terms and DPDP Act obligations at any time.
Obligation to return or securely delete all personal data on contract termination — within a specified timeframe, with a written certification of deletion and destruction of all backup copies.
Clear liability allocation for data breaches caused by the processor — indemnification clauses, liability caps, and insurance requirements that protect your business from bearing the full cost of a vendor's non-compliance.
Processor's obligation to assist you in responding to Data Principal rights requests (access, correction, erasure) within required timelines — so vendor-held data is covered when a user exercises their DPDP Act rights.
If a third party touches your customer data in any way, you need a DPA with them. Here are the most common vendor types we work with.
AWS, Google Cloud, Azure, DigitalOcean — hosting your databases and applications
Razorpay, PayU, Stripe, CCAvenue — processing customer payment and financial data
Salesforce, HubSpot, Mailchimp, Zoho — storing and processing customer contact data
Google Analytics, Mixpanel, Hotjar — tracking user behaviour and personal identifiers
Twilio, MSG91, Interakt — sending messages using customer phone numbers
Darwinbox, Keka, GreytHR — processing sensitive employee personal and financial data
DigiLocker, CKYC, Aadhaar-based services — processing sensitive identity documents
Shiprocket, Delhivery, Ecom Express — accessing customer addresses and contact details
We start with a structured intake form capturing the vendor's name, service type, data categories shared, processing locations, existing contractual arrangements, and your specific risk concerns. This enables us to tailor the DPA precisely to the relationship — not use a generic template.
Our advocates assess the data protection risk profile of the vendor relationship — the sensitivity of data shared, cross-border transfer risks, sub-processor exposure, vendor's security posture, and sector-specific requirements. This determines the robustness of protections needed in the DPA.
For new DPAs — we draft from scratch, tailored to the specific vendor. For vendor-provided DPAs — we produce a detailed redline with all required additions, deletions, and modifications, plus a plain-English summary of what each change achieves and why it is necessary for DPDP compliance.
We support you through vendor negotiation — advising on which clauses are non-negotiable for DPDP compliance, which have flexibility, and providing draft responses to vendor pushback. For enterprise vendors with standard DPAs, we identify the minimum acceptable modifications to meet your legal obligations.
Final executed DPA delivered with a plain-English summary of your key rights and the vendor's key obligations. We update your vendor compliance register with the DPA status, next review date, and any outstanding obligations — keeping your entire vendor landscape documented and audit-ready.
Every DPA is drafted and reviewed by enrolled advocates with specific expertise in technology contracts, IT law, and DPDP compliance — not by junior staff or contract templates.
First draft or redline delivered within 48 hours of receiving complete intake information — fast enough for procurement timelines without sacrificing legal quality.
Deep understanding of DPDP Act requirements, Indian IT Act obligations, and sector-specific regulations (RBI, SEBI, IRDAI, NHA) that may impose additional vendor contract requirements in your industry.
Many businesses need DPAs with 5, 10, or 20+ vendors. We offer bulk DPA packages at significantly reduced per-DPA pricing — making systematic vendor compliance affordable.
We maintain a vendor compliance register tracking DPA status, expiry, renewal dates, and outstanding obligations across all your vendor relationships — one less thing to manage internally.
As the DPDP Rules evolve, we review and update your DPAs annually to ensure they remain compliant — protecting you as the legal landscape develops over the coming years.
Every vendor processing your customer data without a valid DPA is an uncontrolled liability. Let us draft or review your DPAs and give you complete control over your vendor data chain — starting today.