A client of mine, runs a D2C skincare brand out of Bengaluru, called me last year in a complete panic. Her email marketing vendor, one of those popular SaaS tools everyone uses, had a data breach. Thousands of her customers’ emails and phone numbers were out there, exposed. She pulled up the vendor agreement expecting some protection. There was barely anything. No liability clause, no breach notification timeline, nothing that actually held the vendor responsible.
Guess who had to deal with the angry customers and the compliance headache? Her company. Not the vendor. At the end of the day, those were her customers, not theirs.
I keep seeing this exact situation across Indian businesses — small D2C brands, growing startups, even established manufacturing companies. They sign up with payment gateways like Razorpay or Cashfree, marketing tools, cloud providers like AWS or a local hosting company, CRM platforms — and nobody checks whether the contract actually protects them once the DPDP Act comes into the picture. That’s a gap that can cost a business far more than what they’re paying the vendor.
So What Exactly Is a Data Processing Agreement?
Think of a Data Processing Agreement, or DPA, as the rulebook you hand to any third party that touches your customers’ data on your behalf. In DPDP Act language, you’re the Data Fiduciary; the vendor is the Data Processor. The DPA lays out exactly how they’re supposed to handle whatever data you’re sharing with them.
Here’s the part most business owners in India don’t realise: under the DPDP Act, you don’t get to shift the blame just because you outsourced the work. Your business stays responsible, full stop. What a solid DPA gives you is leverage — a legal basis to actually hold the vendor accountable when something goes wrong.
Why Your Standard Vendor Contract Usually Falls Short
Most vendor agreements in India are built around pricing, SLAs, and payment terms. Data protection, if it shows up at all, is usually one throwaway line about “confidentiality” tucked somewhere near the bottom.
That single line won’t help you much if the vendor loses your data, uses it for a purpose you never approved, or stores it on a server with weak security. You need specific, enforceable terms — not vague reassurances that sound good on paper.
What Should Actually Be in the Agreement
Scope and purpose of processing. Spell out exactly what data the vendor can access and why. A payment gateway needs transaction details — it has no business seeing your customer’s entire order history or browsing behaviour.
Security obligations. List the actual security measures the vendor must maintain — encryption, access controls, regular audits. “We follow industry-standard security” is not an answer, push for specifics.
Breach notification timeline. Set a firm deadline for the vendor to inform you the moment something goes wrong. The DPDP Act has its own reporting requirements to the Data Protection Board of India, and you can’t meet those deadlines if your vendor sits on a breach for two weeks before saying anything.
Sub-processor restrictions. Plenty of vendors quietly bring in other companies to handle parts of the work — a CRM tool outsourcing its SMS gateway, for instance. Your DPA should require sign-off from you before that happens, and hold the sub-processor to the same standard.
Data return or deletion. Decide upfront what happens to your data once the contract ends. Should it be deleted, returned, or both? Get it in writing once it’s actually done.
Audit rights. Give yourself the right to check in on how the vendor is handling your data, or at least ask for proof of compliance. This matters even more for vendors dealing with sensitive information like health or financial data.
Liability and indemnification. Nobody wants to think about this clause until they need it. Make it explicit — who bears the cost if the vendor’s negligence causes a breach or a penalty from the Data Protection Board? Without this, your business could end up paying for someone else’s mistake entirely.
Cross-border transfer terms. A lot of Indian businesses use cloud providers or support teams based outside the country. If that applies to you, this needs to be addressed directly in the agreement, along with the safeguards in place.
Time to Revisit Your Existing Vendor Contracts
Most Indian businesses only find out their vendor contracts are weak after something has already gone wrong, which is exactly the wrong time to find out. It’s worth pulling out your current agreements and checking each one against everything above. You’ll likely find gaps, especially in anything signed before the DPDP Act came into force.
This doesn’t mean tearing up every contract and starting fresh. A DPA can sit alongside your existing agreement as an addendum, filling in whatever data protection terms are missing.
Don’t Let a Vendor’s Mistake Become Your Liability
Your compliance under the DPDP Act is only as strong as the weakest vendor in your chain, not just your own internal practices. One weak contract can undo months of careful compliance work the moment something goes wrong.
Not sure where your vendor contracts stand right now? Get them reviewed before a vendor’s mistake becomes your problem. Book a free consultation and we’ll go through them together.