Under India's Digital Personal Data Protection Act, a Data Processor has almost no direct statutory duties — and that is the misleading part. The obligations arrive instead as contract terms, flowed down by every Data Fiduciary that needs its own compliance to hold. For a B2B SaaS company selling into India, DPDP is therefore a procurement problem before it is a legal one.
What Is a Data Processor?
A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The test is whether someone else determined the purpose and means. If a customer told you what to do with the personal data and you executed it, you are a processor for that activity.
The role is activity-specific, not organisation-wide. The same company is routinely a processor for customer-uploaded data and a fiduciary for the account, billing and product-usage data it decides to collect about its own users. Both are true simultaneously, and conflating them produces a compliance programme that fits neither.
Why the Duty Arrives as a Contract, Not a Regulation
Two provisions do the work. Section 8(2) of the Act permits a Data Fiduciary to engage a Data Processor "only under a valid contract." Rule 6(f) of the notified DPDP Rules requires that contract to contain an appropriate provision obliging the processor to take reasonable security safeguards.
The compliance burden stays with the fiduciary. But because the fiduciary cannot discharge its own rule 6 duty without binding you, and cannot meet its rule 7 breach clocks without your cooperation, the duties reach you with contractual force. The Board does not need jurisdiction over you for your customer's lawyers to.
This is why processor-side DPDP readiness is a revenue question. Vendor agreements signed before the Rules were notified will not satisfy section 8(2) and rule 6(f) by accident, which means remediation is a contract-paper exercise across your customer's entire vendor estate — and every one of those customers is about to arrive with an addendum.
Getting DPDP questions in security reviews already?
Share your work email and we'll walk the clauses Indian enterprise buyers are asking for against what your current security programme can already evidence.
What Indian Enterprise Buyers Now Ask For
These are the asks appearing in Indian enterprise procurement aimed at vendors, and they map directly onto the fiduciary's own duties:
- A DPDP-specific addendum to the master agreement
- Security safeguards mirroring rule 6's seven named measures
- Breach notification fast enough for the customer to meet its own rule 7 clocks
- Sub-processor disclosure, with flow-down of the same terms
- Deletion and return commitments that respect rule 8(3)'s one-year minimum log retention
The last one catches teams out. A deletion commitment promising to purge everything within thirty days of termination conflicts with the fiduciary's own duty to retain personal data, traffic data and processing logs for at least a year from processing. A processor that cannot distinguish the two will either break its contract or break its customer's compliance.
The Clauses That Actually Bite
Six clauses actually bite, and each one traces back to a duty the fiduciary cannot discharge without you.
| Clause | What it requires of you | Where it comes from |
|---|---|---|
| Valid contract | A written agreement before any processing begins | Section 8(2) |
| Reasonable security safeguards | The seven measures in rule 6, operated and evidenced | Rule 6(f) |
| Breach notification | Notice fast enough for the fiduciary's "without delay" and 72-hour clocks | Rule 7, flowed down |
| Sub-processor flow-down | The same safeguards bound onto anyone you engage | Rule 6(f), flowed down |
| Assistance with rights requests | Retrieval, correction and erasure within the fiduciary's published period | Rule 14, flowed down |
| Retention floor | Keeping logs and data for the minimum period despite deletion requests | Rule 8(3), flowed down |
Note the asymmetry on breach. Rule 7 gives the fiduciary a "without delay" obligation to affected Data Principals and a seventy-two hour window for its detailed submission to the Board — both running from when the fiduciary becomes aware. If your contract gives you seventy-two hours to notify your customer, you have consumed their entire budget before they start. Expect buyers to ask for considerably less, and build detection that can support it.
Where Processors Get Reclassified as Fiduciaries
The risk is not that you are called a processor and are really one. It is that an activity quietly moves and nobody files a ticket about it.
Choosing your own sub-processors, setting your own retention periods, enriching customer data from third-party sources, or using customer data to train or improve a model for your own benefit all pull an activity toward fiduciary. So does analytics you decided to collect. The moment you determine a purpose, you hold the substantive duties for that activity: notice, consent, rights fulfilment, the lot.
Re-run the determination whenever the product changes. An AI feature that processes customer data for your own improvement purposes is the most common recent trigger, and it rarely arrives labelled as a compliance change.
Getting Processor-Ready Before May 2027
Rules 3 and 5 to 16 commence eighteen months after the Rules were published in the Gazette, in mid-May 2027. Your customers will be remediating their vendor estates well before then, because they cannot leave it to the deadline.
- Inventory which customer relationships involve Indian personal data, and which of those are governed by agreements predating the Rules.
- Draft your own DPDP addendum rather than negotiating twenty of theirs. A vendor arriving with defensible paper sets the terms.
- Map rule 6's seven measures onto what you already operate. An existing ISO 27001 or SOC 2 programme covers most of it as evidence mapping, not new engineering.
- Fix the retention conflict explicitly. Separate your deletion commitment from your log-retention floor in writing, per data category.
- Tighten breach detection and notification so your commitment leaves the fiduciary room inside its own clocks.
- Publish a sub-processor list and keep it current, with the flow-down terms you impose.
The duty-by-duty picture your customers are working from is in our DPDP compliance checklist, and mapping their questionnaire against controls you already run starts with access controls and a log pipeline that satisfies the rule 6 floor.
Data Processor Questions Teams Ask
Very few. The Act places the substantive duties on the Data Fiduciary and reaches the processor through section 8(2), which permits engagement only under a valid contract, and rule 6(f), which requires that contract to oblige the processor to take reasonable security safeguards. The practical consequence is that your obligations have the force of contract rather than regulation — which does not make them lighter, because your customer's own compliance depends on them and their commercial leverage is immediate.
The Schedule's penalties attach to duties the Act places on Data Fiduciaries, Significant Data Fiduciaries and Data Principals. A pure processor's exposure is primarily contractual — indemnities, termination, damages — rather than a penalty from the Board. The important caveat is that determining a purpose for any processing activity makes you a Data Fiduciary for that activity, and the Schedule then applies to you directly for it.
No. Nothing in the Act or the Rules requires a processor to incorporate in India. Rule 15 permits transfer of personal data outside India, subject to requirements the Central Government may specify about making that data available to a foreign State or an entity under its control. The one localisation duty sits in rule 13(4) and applies only to notified Significant Data Fiduciaries for data classes the government specifies. Sector rules are separate, and RBI's payment-data circular is stricter than DPDP.
The Rules do not set a processor-to-fiduciary deadline — your contract does. What constrains the negotiation is rule 7: the fiduciary must inform affected Data Principals and send the Board a first intimation without delay, and make a detailed submission within seventy-two hours of becoming aware. A seventy-two hour notification window from you consumes their entire budget, so expect buyers to ask for hours rather than days and build detection that can support the commitment you sign.
Separate the two obligations per data category. Rule 8(3) requires the Data Fiduciary to retain personal data, associated traffic data and processing logs for a minimum of one year from the date of processing. That is a duty on your customer, flowed to you as a constraint on what your deletion commitment can promise. The workable answer is a contract that distinguishes deletion of the primary record from retention of processing logs, with the retention floor stated explicitly rather than discovered during an incident.
Answer DPDP questionnaires without a bespoke project each time
Book a demo and we'll show how Konfirmity maps the rule 6 safeguards to evidence your systems produce on their own, so processor due diligence stops being a quarter-long exercise.
Book a demo
Why Processor Status Is a Sales Problem
Being a Data Processor under DPDP does not mean being lightly regulated. It means being regulated through someone else's contract, by a counterparty whose own compliance depends on yours and who can withhold a renewal to get it.
The vendors that treat this as a sales-readiness exercise — defensible paper, mapped controls, a breach commitment they can actually meet — will clear Indian enterprise procurement while competitors are still discovering the questions. Start with the role determination activity by activity, because the places you are quietly a Data Fiduciary carry duties no contract will flow to you.
