Yesterday, I was reviewing a Data Processing Agreement on behalf of one of our clients. This time, we were advising the Data Processor, not the Data Fiduciary. As I read through the agreement, I experienced a sense of déjà vu — the very same gaps that I had noticed while reviewing agreements for other clients over the past year were present here as well.
That’s when I realised that one of the biggest challenges in DPDP implementation isn’t technology alone. It’s poorly drafted Data Processing Agreements.
What these agreements get right, and where they stop
Most agreements do a good job of covering commercial terms, confidentiality, and information security.
However, in our experience, many agreements do not clearly allocate responsibilities under the Digital Personal Data Protection Act, 2023 between the Data Fiduciary and the Data Processor.
Some of the gaps we keep seeing
Lawful processing and onward sharing. Responsibilities here are often not clearly allocated, particularly where the Data Processor is expected to transfer or disclose personal data to other entities as part of the agreed business process.
The data lifecycle across the processor’s ecosystem. There is little clarity on how personal data will be transferred to, received by, processed within, shared by, or returned from the Data Processor’s ecosystem, including the respective responsibilities of each party throughout the data lifecycle.
Reasonable security safeguards. The agreement often fails to clearly define what is expected from the Data Processor, leaving requirements such as encryption, masking or pseudonymisation, tokenisation, access controls, logging, and other appropriate safeguards open to interpretation.
Retention, return and secure deletion. These obligations are frequently incomplete or not aligned with contractual, business, or legal requirements.
Breach, grievance, audit and regulatory cooperation. Responsibilities relating to personal data breaches, grievance handling, audit support, regulatory cooperation, and compliance reporting are often ambiguous or operationally impractical.
Why this is not a drafting quibble
These may appear to be minor drafting gaps today. Tomorrow, they could determine contractual liability, regulatory exposure, and financial loss.
A Data Processing Agreement is not just another vendor agreement. It is the legal document that allocates responsibility, accountability, and risk between the Data Fiduciary and the Data Processor. While the DPDP Act establishes the legal obligations, the agreement should clearly define how those obligations will be operationalised between the parties.
What I would advise
My advice is simple.
If you are a Data Fiduciary, clearly define your legal expectations and statutory responsibilities.
If you are a Data Processor, don’t negotiate only the commercials. Understand every privacy and compliance obligation before signing the agreement.
A well-drafted Data Processing Agreement doesn’t just protect personal data. It protects the relationship between the Data Fiduciary and the Data Processor — and, ultimately, the interests of the Data Principal.
Common questions
Isn't a Data Processing Agreement just another vendor agreement?
No. It is the legal document that allocates responsibility, accountability and risk between the Data Fiduciary and the Data Processor. Most agreements cover commercial terms, confidentiality and information security well; what many do not do is clearly allocate the responsibilities the DPDP Act creates.
Which gaps keep recurring?
Five come up repeatedly: responsibilities for lawful processing and onward sharing, particularly where the processor passes data to other entities; how data moves through the processor's ecosystem and who is responsible at each stage; what reasonable security safeguards actually mean; retention, return and secure deletion; and duties around breaches, grievances, audit support, regulatory cooperation and compliance reporting.
Why address this now?
Because these may appear to be minor drafting gaps today, and tomorrow they could determine contractual liability, regulatory exposure and financial loss.
Sources
Dr Prashant Koranne
Virtual CISO & Data Protection Officer
Dr Koranne advises organisations across BFSI, healthcare and fintech as a virtual CISO and Data Protection Officer, with three decades in cyber security, governance and technology law and more than 300 consulting engagements behind him. He holds an LLB alongside CISA, PCI QSA, CEH and Elite DPO credentials and is a lead auditor for ISO 27001, 27701 and 42001 — which is why he reads a Data Processing Agreement from the control side and the legal side at once.