Konfirmity

Data Processor: Why DPDP reaches you through a contract (2026)

Author

Konfirmity

2026-10-05

Under India's Digital Personal Data Protection Act, a Data Processor has almost no direct statutory duties — and that is the misleading part. The obligations arrive instead as contract terms, flowed down by every Data Fiduciary that needs its own compliance to hold. For a B2B SaaS company selling into India, DPDP is therefore a procurement problem before it is a legal one.

What Is a Data Processor?

A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The test is whether someone else determined the purpose and means. If a customer told you what to do with the personal data and you executed it, you are a processor for that activity.

The role is activity-specific, not organisation-wide. The same company is routinely a processor for customer-uploaded data and a fiduciary for the account, billing and product-usage data it decides to collect about its own users. Both are true simultaneously, and conflating them produces a compliance programme that fits neither.

Why the Duty Arrives as a Contract, Not a Regulation

Two provisions do the work. Section 8(2) of the Act permits a Data Fiduciary to engage a Data Processor "only under a valid contract." Rule 6(f) of the notified DPDP Rules requires that contract to contain an appropriate provision obliging the processor to take reasonable security safeguards.

The compliance burden stays with the fiduciary. But because the fiduciary cannot discharge its own rule 6 duty without binding you, and cannot meet its rule 7 breach clocks without your cooperation, the duties reach you with contractual force. The Board does not need jurisdiction over you for your customer's lawyers to.

This is why processor-side DPDP readiness is a revenue question. Vendor agreements signed before the Rules were notified will not satisfy section 8(2) and rule 6(f) by accident, which means remediation is a contract-paper exercise across your customer's entire vendor estate — and every one of those customers is about to arrive with an addendum.

Getting DPDP questions in security reviews already?

Share your work email and we'll walk the clauses Indian enterprise buyers are asking for against what your current security programme can already evidence.

We check that your email domain is real and can receive mail before sending. If we can't verify it, we won't be able to follow up — so please use a work address rather than a forwarding or temporary one.

We'd like to know who we're talking to. By submitting this form you agree that we may contact you about Konfirmity — no more than six emails a year, and we won't ask again each time. You can unsubscribe from any of them, and we'll stop. See our Privacy Policy.

What Indian Enterprise Buyers Now Ask For

These are the asks appearing in Indian enterprise procurement aimed at vendors, and they map directly onto the fiduciary's own duties:

  • A DPDP-specific addendum to the master agreement
  • Security safeguards mirroring rule 6's seven named measures
  • Breach notification fast enough for the customer to meet its own rule 7 clocks
  • Sub-processor disclosure, with flow-down of the same terms
  • Deletion and return commitments that respect rule 8(3)'s one-year minimum log retention

The last one catches teams out. A deletion commitment promising to purge everything within thirty days of termination conflicts with the fiduciary's own duty to retain personal data, traffic data and processing logs for at least a year from processing. A processor that cannot distinguish the two will either break its contract or break its customer's compliance.

The Clauses That Actually Bite

Six clauses actually bite, and each one traces back to a duty the fiduciary cannot discharge without you.

ClauseWhat it requires of youWhere it comes from
Valid contractA written agreement before any processing beginsSection 8(2)
Reasonable security safeguardsThe seven measures in rule 6, operated and evidencedRule 6(f)
Breach notificationNotice fast enough for the fiduciary's "without delay" and 72-hour clocksRule 7, flowed down
Sub-processor flow-downThe same safeguards bound onto anyone you engageRule 6(f), flowed down
Assistance with rights requestsRetrieval, correction and erasure within the fiduciary's published periodRule 14, flowed down
Retention floorKeeping logs and data for the minimum period despite deletion requestsRule 8(3), flowed down

Note the asymmetry on breach. Rule 7 gives the fiduciary a "without delay" obligation to affected Data Principals and a seventy-two hour window for its detailed submission to the Board — both running from when the fiduciary becomes aware. If your contract gives you seventy-two hours to notify your customer, you have consumed their entire budget before they start. Expect buyers to ask for considerably less, and build detection that can support it.

Where Processors Get Reclassified as Fiduciaries

The risk is not that you are called a processor and are really one. It is that an activity quietly moves and nobody files a ticket about it.

Choosing your own sub-processors, setting your own retention periods, enriching customer data from third-party sources, or using customer data to train or improve a model for your own benefit all pull an activity toward fiduciary. So does analytics you decided to collect. The moment you determine a purpose, you hold the substantive duties for that activity: notice, consent, rights fulfilment, the lot.

Re-run the determination whenever the product changes. An AI feature that processes customer data for your own improvement purposes is the most common recent trigger, and it rarely arrives labelled as a compliance change.

Getting Processor-Ready Before May 2027

Rules 3 and 5 to 16 commence eighteen months after the Rules were published in the Gazette, in mid-May 2027. Your customers will be remediating their vendor estates well before then, because they cannot leave it to the deadline.

  1. Inventory which customer relationships involve Indian personal data, and which of those are governed by agreements predating the Rules.
  2. Draft your own DPDP addendum rather than negotiating twenty of theirs. A vendor arriving with defensible paper sets the terms.
  3. Map rule 6's seven measures onto what you already operate. An existing ISO 27001 or SOC 2 programme covers most of it as evidence mapping, not new engineering.
  4. Fix the retention conflict explicitly. Separate your deletion commitment from your log-retention floor in writing, per data category.
  5. Tighten breach detection and notification so your commitment leaves the fiduciary room inside its own clocks.
  6. Publish a sub-processor list and keep it current, with the flow-down terms you impose.

The duty-by-duty picture your customers are working from is in our DPDP compliance checklist, and mapping their questionnaire against controls you already run starts with access controls and a log pipeline that satisfies the rule 6 floor.

Data Processor Questions Teams Ask

Very few. The Act places the substantive duties on the Data Fiduciary and reaches the processor through section 8(2), which permits engagement only under a valid contract, and rule 6(f), which requires that contract to oblige the processor to take reasonable security safeguards. The practical consequence is that your obligations have the force of contract rather than regulation — which does not make them lighter, because your customer's own compliance depends on them and their commercial leverage is immediate.

The Schedule's penalties attach to duties the Act places on Data Fiduciaries, Significant Data Fiduciaries and Data Principals. A pure processor's exposure is primarily contractual — indemnities, termination, damages — rather than a penalty from the Board. The important caveat is that determining a purpose for any processing activity makes you a Data Fiduciary for that activity, and the Schedule then applies to you directly for it.

No. Nothing in the Act or the Rules requires a processor to incorporate in India. Rule 15 permits transfer of personal data outside India, subject to requirements the Central Government may specify about making that data available to a foreign State or an entity under its control. The one localisation duty sits in rule 13(4) and applies only to notified Significant Data Fiduciaries for data classes the government specifies. Sector rules are separate, and RBI's payment-data circular is stricter than DPDP.

The Rules do not set a processor-to-fiduciary deadline — your contract does. What constrains the negotiation is rule 7: the fiduciary must inform affected Data Principals and send the Board a first intimation without delay, and make a detailed submission within seventy-two hours of becoming aware. A seventy-two hour notification window from you consumes their entire budget, so expect buyers to ask for hours rather than days and build detection that can support the commitment you sign.

Separate the two obligations per data category. Rule 8(3) requires the Data Fiduciary to retain personal data, associated traffic data and processing logs for a minimum of one year from the date of processing. That is a duty on your customer, flowed to you as a constraint on what your deletion commitment can promise. The workable answer is a contract that distinguishes deletion of the primary record from retention of processing logs, with the retention floor stated explicitly rather than discovered during an incident.

Answer DPDP questionnaires without a bespoke project each time

Book a demo and we'll show how Konfirmity maps the rule 6 safeguards to evidence your systems produce on their own, so processor due diligence stops being a quarter-long exercise.

Book a demo

Why Processor Status Is a Sales Problem

Being a Data Processor under DPDP does not mean being lightly regulated. It means being regulated through someone else's contract, by a counterparty whose own compliance depends on yours and who can withhold a renewal to get it.

The vendors that treat this as a sales-readiness exercise — defensible paper, mapped controls, a breach commitment they can actually meet — will clear Indian enterprise procurement while competitors are still discovering the questions. Start with the role determination activity by activity, because the places you are quietly a Data Fiduciary carry duties no contract will flow to you.

//related blogs

Konfirmity

CSP in Cloud Computing: Meaning, purpose, and real-world imp...

Konfirmity

2025-12-12

CSP in Cloud Computing: Meaning, purpose, and real-world importance (2026)

arrow

What is a CSP? We explain what a Cloud Service Provider is, its purpose, and why choosing the right one is so important in (2026).

Konfirmity

What is DIB: A practical overview for companies (2026)

Konfirmity

2025-12-04

What is DIB: A practical overview for companies (2026)

arrow

What exactly is the Defense Industrial Base (DIB)? Get a practical (2026) overview of who is in the DIB and what it means for your company.

Konfirmity

What is DoDIN: What it means and how it impacts businesses (...

Konfirmity

2026-01-19

What is DoDIN: What it means and how it impacts businesses (2026)

arrow

What is the DoDIN? We explain what the "Department of Defense Information Network" is and how it impacts (2026) businesses that connect to it.

Konfirmity

Certified CMMC Professional (CCP): Understanding its role in...

Konfirmity

2026-01-19

Certified CMMC Professional (CCP): Understanding its role in compliance and security (2026)

arrow

What is a Certified CMMC Professional (CCP)? Find out what this certification means and its (2026) role in the CMMC compliance ecosystem.

Konfirmity

What is a Data Breach: The basics every business should know...

Konfirmity

2026-01-19

What is a Data Breach: The basics every business should know (2026)

arrow

What really counts as a data breach? We cover the (2026) basics, the different types, and what every business needs to know.

Konfirmity

What is ISO 9001 Compliance: Understanding its role in compl...

Konfirmity

2026-01-19

What is ISO 9001 Compliance: Understanding its role in compliance and security (2026)

arrow

What does ISO 9001 compliance mean? We explain this quality standard and its (2026) role in building a foundation for compliance and security.

How Real Security Becomes Compliance

Built by the CTO who scaled NIUM to $2 billion. 10 years building security and compliance for regulated fintechs. 4.5 years running Konfirmity profitably.

Book a call