Data Processor Agreements (DPA): Template & Negotiation
What is a DPA?
Contract between you (Fiduciary) and a vendor (Processor) specifying:
- What data they process
- How they secure it
- How long they retain it
- Their obligations under DPDP
Critical: No DPA = DPDP violation
Required DPA Clauses
1. Scope of Processing
- Exact data categories
- Volume
- Duration
- Frequency
2. Security Obligations
- Encryption standards (AES-256 minimum)
- Access controls
- Employee training
- Incident response
- Vulnerability assessments
3. Confidentiality
- Employees bound by confidentiality
- No use of data for vendor's purposes
- No sharing with sub-processors without approval
4. Breach Notification
- Notify within 24 hours of breach discovery
- Provide full breach details
5. Data Subject Rights
- Handle data access requests
- Handle deletion requests
- Correction process
6. Audit & Monitoring
- Right to audit processor security
- Right to inspect data
- SOC 2 or ISO 27001 certification
7. Sub-processors
- Disclose all sub-processors
- Sub-processors must have DPAs
- Right to object to new sub-processors
8. Data Return & Deletion
- Return or delete data upon contract termination
- Timeline for deletion (30-90 days)
- Written certification of deletion
Negotiation Tips
- Standardize: Use your template
- Escalate: If vendor won't sign, escalate to their legal team
- Compromise: Allow flexibility on timelines
- Reduce scope: Minimize data vendor accesses if needed
- Alternatives: Find alternative vendor if needed
Red Flags
🚩 Vendor refuses to sign DPA
🚩 Vendor claims "standard contract = DPA"
🚩 Won't disclose sub-processors
🚩 Won't commit to data residency
🚩 Refuses audit rights
🚩 Won't commit to 72-hour breach notification
Disclaimer: General informational article. Consult legal counsel for your DPA. what is dpdp act 2023 dpdp vs gdpr
Start Compliance: Start your free DPDP compliance assessment dpdp penalties explained DPDP Compliance Hub