insightfour
Vendor Agreements and Data Processing Obligations Explained

Personal data rarely remains within one organisation. Businesses routinely share customer, employee, applicant and user information with cloud providers, SaaS platforms, payroll companies, marketing agencies, logistics providers, analytics platforms and technology vendors. This makes vendor data processing obligations an important part of privacy governance in India. A vendor contract is no longer merely a commercial document. Where a third party processes personal data on behalf of a business, the agreement can become an important mechanism for controlling privacy, security and operational risk.

India's privacy framework is moving towards a more structured approach through the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. However, the framework has phased commencement. As of September 2026, several core operational provisions, including Section 8 and the detailed security requirements in Rule 6, are scheduled for the later commencement phase. Businesses should therefore prepare contracts now rather than wait until the statutory obligations become operational.

Why vendor agreements matter for data protection

A business can outsource a processing activity, but outsourcing does not automatically remove its responsibility for the underlying data. Under the DPDP framework, a Data Processor is a person who processes personal data on behalf of a Data Fiduciary. The distinction depends on the actual processing relationship, rather than the commercial label given to the vendor.

For example, a company may appoint a cloud provider to host its customer database. It may use a payroll platform to manage employee records or a customer support provider to handle complaints. In each situation, the third party may be processing personal data on behalf of the organisation.

The contractual relationship therefore needs to reflect the actual data flow. A simple confidentiality clause may protect confidential business information, but it does not necessarily address the operational requirements associated with personal data processing.

The DPDP Act specifically provides for contractual engagement of Data Processors. Section 8(2), which is scheduled for the eighteen month commencement phase, states that a Data Fiduciary may engage a Data Processor for relevant activities only under a valid contract.

Data Fiduciary and Data Processor: who is responsible?

The first step in reviewing a vendor agreement is identifying the role of each party.

A Data Fiduciary determines the purpose and means of processing personal data. A Data Processor processes personal data on behalf of the Data Fiduciary. A vendor may therefore be a Data Processor for one activity but operate as an independent Data Fiduciary for another.

This distinction is particularly important for modern SaaS arrangements. A software provider might process customer information strictly according to a company's instructions for one service. The same provider might use certain information independently for its own purposes in another context. The contract should not simply assume one role covers every processing activity.

Businesses should document the purpose of processing, categories of personal data, categories of Data Principals, systems involved, locations of processing and permitted uses before finalising the agreement.

What should a data processing clause cover?

A well drafted vendor agreement should establish clear boundaries around how personal data may be processed.

The vendor should receive clear instructions about the permitted purpose. Personal data provided for customer support should not automatically become available for unrelated product development, advertising or other commercial purposes.

The agreement should also identify the categories of information involved. Customer contact information creates different risks from identity documents, financial information, health information or children's information. A risk based approach helps determine the level of contractual protection required.

The agreement should also address access. Vendor personnel should only access personal data where necessary for their assigned responsibilities. Access should be controlled, reviewed and removed when no longer required.

These contractual controls support the wider accountability model contemplated by India's data protection framework.

Security safeguards should be contractual obligations

Security is one of the most important areas in a vendor relationship.

The notified DPDP Rules, 2025 provide for reasonable security safeguards covering personal data processed by a Data Fiduciary itself or on its behalf through a Data Processor. Rule 6 includes measures such as encryption, masking or obfuscation, access controls, logging and monitoring, backups, retention of relevant logs and contractual safeguards with Data Processors.

Businesses should therefore avoid vague wording such as “the vendor will maintain adequate security”. The contract should explain the expected standard in terms suitable for the service and risk involved.

For a cloud provider, this may involve encryption, identity management, access logging and resilience controls. For a customer support provider, it may also require restrictions on downloading records, controlled employee access and secure disposal.

A vendor agreement should ideally connect contractual commitments with evidence. Depending on risk, this may include security certifications, audit reports, penetration testing summaries, policies or other appropriate assurance material.

Breach notification must work in practice

A privacy contract is tested most severely during a security incident.

If a vendor discovers unauthorised access to personal data, the business needs information quickly. A clause requiring notification “promptly” may be too vague for an effective incident response programme.

The contract should establish an internal escalation process. It should specify how the vendor will notify the business, what initial information must be provided, how updates will be communicated and who will coordinate investigation and remediation.

The agreement should also require reasonable cooperation with forensic investigations and regulatory responses where appropriate.

This matters because the organisation engaging the processor may have its own statutory notification responsibilities once the relevant DPDP provisions commence. The vendor therefore needs to notify the organisation quickly enough for the organisation to assess and discharge its own legal duties.

Businesses should also align vendor incident clauses with their internal incident response plan. Contractual rights are of limited value if nobody knows who must activate them.

Sub processors require careful control

Many vendors do not operate alone. A SaaS provider may use cloud infrastructure, analytics platforms, customer support systems or other technology providers.

This creates a chain of processing.

A business should know whether its vendor uses sub processors, who those entities are, what data they receive and where processing takes place. The agreement should establish an appropriate mechanism for approving or objecting to material changes in the sub processor chain.

Equivalent privacy and security obligations should also flow down where appropriate.

This is especially important for technology vendors whose underlying infrastructure can change during the contract term. A company may sign an agreement believing its data will be handled by one provider, only to discover later that another entity is performing a material part of the processing.

Data retention, deletion and return

Vendor agreements should also address the end of the data lifecycle.

When a service ends, the business should know what happens to the personal data. The vendor should not retain information indefinitely merely because the service agreement has expired.

The contract should establish whether information must be returned, deleted or securely disposed of. It should also address backups, legal retention requirements and the evidence available to demonstrate deletion where appropriate.

This requirement becomes particularly important during vendor transitions. A company moving from one CRM, payroll platform or cloud provider should not have personal data scattered across its previous supplier's active systems and backups without a defined retention position.

Cross border processing should be visible

A vendor may process Indian personal data outside India even when the business itself operates from India.

Cloud architecture, support teams, infrastructure providers and sub processors can create international data flows without the procurement team fully appreciating them.

The DPDP Act does not create a blanket prohibition on every cross border transfer. Section 16 provides a framework under which the Central Government may restrict transfers of personal data outside India to specified countries or territories. Other sector specific requirements may also apply depending on the organisation and information involved.

Vendor agreements should therefore require sufficient transparency about processing locations and material changes to those arrangements.

A business operating in a regulated sector should also assess applicable requirements from sectoral regulators before approving an international processing arrangement.

Vendor due diligence should begin before signing

A contract cannot compensate for inadequate vendor selection.

Before onboarding a supplier, the organisation should understand what personal data the supplier will access and why. It should assess the nature of the service, the volume of information, security controls, subcontracting model, processing locations and incident history where relevant.

High risk vendors should receive deeper scrutiny than vendors with no access to personal data.

Procurement, information security, privacy and legal teams should work together. A vendor questionnaire can identify technical and organisational controls, while legal review can convert material risks into enforceable contractual terms.

This is where data processing compliance becomes part of procurement governance rather than an issue addressed only after a contract has already been negotiated.

Vendor monitoring does not end after contract signing

One common mistake is treating the signed agreement as the end of compliance work.

Vendor risk can change. Services evolve, new sub processors are appointed, processing locations change and new features may introduce artificial intelligence or additional analytics.

Businesses should therefore periodically reassess material vendors.

Contract reviews should be triggered by significant changes such as a new processing purpose, acquisition of the vendor, major system migration, new sub processor, material security incident or expansion into new jurisdictions.

Evidence of reviews should also be retained. A documented vendor governance process helps demonstrate that privacy commitments are actively managed rather than merely written into contracts.

What happens when a vendor refuses strong privacy clauses?

Large technology suppliers often operate on standard terms. Businesses may have limited negotiating leverage.

This does not mean every clause should simply be accepted.

The organisation should first identify which provisions are legally essential, which are risk controls and which are preferred commercial protections. A risk based approach can then determine whether alternative safeguards are acceptable.

For high risk processing, inability to obtain adequate contractual protections may itself be a reason to reconsider the vendor.

For lower risk services, other controls may reduce exposure. The decision should be documented rather than left to informal procurement discussions.

The role of indemnities and liability provisions

Privacy obligations should also be considered alongside liability provisions.

A vendor may agree to comply with data protection requirements while its general liability clause places a relatively low cap on claims. This can create a mismatch between the seriousness of the processing risk and the available contractual remedy.

Businesses should examine liability caps, indemnities, exclusions, insurance requirements and treatment of regulatory costs.

No single liability structure works for every transaction. A payroll vendor, health technology provider and ordinary office supplies vendor present very different levels of privacy risk.

The commercial allocation should therefore reflect the nature of the processing.

Indian businesses should prepare before full commencement

The Government notified the DPDP Rules, 2025 in November 2025. MeitY's official materials confirm a phased eighteen month implementation approach. The commencement notification places the core operational provisions of the Act, including Sections 3 to 17 and Section 8, in the later phase.

This gives businesses an important preparation window.

Organisations should identify vendors handling personal data, classify their roles, map data flows and review existing contracts. Procurement templates should be updated before new vendors are onboarded. Existing high risk arrangements should be prioritised for remediation.

Businesses should also remember that India's privacy landscape currently includes other applicable legal requirements. The Information Technology Act, 2000 and the Information Technology SPDI Rules, 2011 remain relevant during the transition, particularly for organisations handling sensitive personal data or information within their scope.

Building a stronger vendor governance model

The most effective approach is to treat vendor privacy as a lifecycle process.

At the procurement stage, identify whether personal data will be processed. During due diligence, assess the vendor's security and privacy controls. During contract negotiation, document processing instructions, security obligations, incident response, sub processor controls, retention, deletion and relevant transfer provisions.

During the relationship, monitor material changes and reassess risk. During termination, confirm return or deletion of personal data and revoke access.

This approach creates a defensible record showing how the organisation manages third party data risk.

For businesses dealing with extensive personal data, specialist corporate contract compliance review can also help align commercial agreements with the organisation's wider privacy framework.

Frequently Asked Questions

Is a data processing agreement mandatory in India?

Under Section 8(2) of the DPDP Act, a Data Fiduciary may engage a Data Processor for covered activities only under a valid contract. However, Section 8 is part of the eighteen month commencement phase following the November 2025 notification. Businesses should therefore prepare processor agreements in advance rather than assuming the provision is already fully operational.

What is the difference between a vendor and a Data Processor?

A vendor is a commercial concept. A Data Processor is a legal role based on how the party processes personal data. A vendor becomes a Data Processor where it processes personal data on behalf of a Data Fiduciary. The actual activities should be examined rather than relying solely on the contract title.

What should a vendor data processing agreement contain?

It should address the processing purpose, instructions, permitted data, confidentiality, security safeguards, access controls, breach notification, sub processors, retention, deletion, return of information, relevant audit or assurance rights and applicable transfer requirements.

Can a standard vendor agreement cover data protection requirements?

Sometimes, but a generic vendor agreement may not provide sufficient detail. Businesses should review the agreement against the actual data processing activities and applicable law. A confidentiality clause alone is rarely an adequate privacy governance mechanism.

Who is responsible if a vendor causes a data breach?

Responsibility depends on the facts and applicable legal framework. A contractual arrangement does not automatically eliminate the Data Fiduciary's statutory responsibilities. The organisation should therefore maintain oversight of its processors and ensure vendors have effective security and incident reporting obligations.

Should companies review old vendor agreements?

Yes. Existing contracts should be prioritised based on risk. Agreements involving customer databases, employee information, financial information, health information, children's data or large volumes of personal data deserve particular attention.

Do vendor contracts need to address sub processors?

Where a vendor uses other parties to process personal data, the organisation should understand and appropriately govern the sub processor arrangement. Contractual flow down of relevant privacy and security requirements is an important control.

Does Indian data protection law prohibit vendors from processing data outside India?

Not as a blanket rule. The DPDP Act provides for restrictions on transfers to certain countries or territories through Government notification. Sector specific requirements may also apply. Businesses should therefore understand the vendor's processing locations before approving the arrangement.

Why are vendor agreements important for DPDP compliance?

They provide a practical mechanism for translating an organisation's privacy and security requirements into enforceable obligations for third parties. They also help establish accountability across the data processing chain.

When should a business review its vendor privacy contracts?

A review should occur during onboarding and periodically afterwards. It should also be triggered by major changes in processing, new sub processors, international expansion, significant security incidents, new technology features or changes in applicable law.

Conclusion

Vendor management is now an important part of privacy governance for Indian businesses. Personal data may pass through several technology and service providers before a business delivers its product or service. Each additional processing relationship can create operational, contractual and regulatory risk.

A strong vendor agreement should therefore do more than protect confidential information. It should establish clear processing boundaries, security expectations, incident procedures, sub processor controls, retention rules and appropriate accountability.

With India's DPDP framework moving through its phased implementation, businesses have an opportunity to review vendor arrangements before the core obligations become operational. A structured approach to vendor due diligence, contracting and ongoing monitoring can reduce avoidable risk and create stronger evidence of responsible data governance.

This update was released on 21 Sep 2026.

The views expressed in this update are personal and should not be construed as any legal advice. Please contact us directly on +91 22 40565252 or contact@mhcolaw.com for any assistance.

Legal Update Team
MANSUKHLAL HIRALAL & COMPANY
Advocates, Solicitors and Notaries
T: +91 22 40565252
Mumbai Office: Surya Mahal, 2nd Floor, 5, Burjorji Bharucha Marg, Fort, Mumbai-400 023, India
Delhi Office: Block C-9, Lower Ground Floor, Jangpura Extension, New Delhi - 110 014, India
www.mhcolaw.com

"Noted lawyer in the Real Estate practitioner from India" - Chambers & Partners

Please consider the environment before printing this email

The information contained in this communication is intended solely for the use of the individual or entity to whom it is addressed and others authorized to receive it. This communication may contain confidential or legally privileged information. If you are not the intended recipient, any disclosure, copying, distribution or action taken relying on the contents is prohibited and may be unlawful. If you have received this communication in error, or if you or your employer does not consent to email messages of this kind, please notify the sender immediately by responding to this email and then delete it from your system. No liability is accepted for any harm that may be caused to your systems or data by this message.
Need Help? Chat with us