Infosek
INFOSEK

DPDP Processor Contracts: The Clause Rule 6 Requires

The obligation stays with the Data Fiduciary whatever the contract says. What the contract does is give you a way to require, and evidence, that your vendor holds up their end.

DPDP Processor Contracts: The Clause Rule 6 Requires

The obligation does not transfer

Rule 6(1) is explicit that a Data Fiduciary must protect personal data in its possession or under its control, including in respect of any processing undertaken on its behalf by a Data Processor. Rule 6(1)(f) then requires appropriate contractual provision for safeguards.

So the contract is not a way to move risk. It is a required control, and a means of evidencing that you imposed the safeguards you were obliged to impose.

What the clause should reach

Do it in the right order

Renegotiating live contracts is slow. Start with the processors holding the most personal data and the ones whose failure would hurt most: payment providers, KYC vendors, communication platforms, analytics tools, support systems.

For new contracts, get the clause into your standard template now so the backlog stops growing.

The clause that matters most in practice is the notification one. Everything else can be fixed after an incident. Being told late cannot.

Infosek Team

Both directions

If you are also a Data Processor for your own customers, expect to receive these terms as well as issue them. Having a position drafted in advance turns a two week negotiation into a one day one, which is a commercial advantage as much as a compliance one.

Common questions

What must a DPDP processor contract include?

Rule 6(1)(f) requires appropriate provision in the contract between a Data Fiduciary and a Data Processor for taking reasonable security safeguards. In practice that means binding the processor to the Rule 6 measures, plus the operational commitments the Data Fiduciary needs to meet its own obligations on breach intimation, erasure and rights requests.

Who is liable if a Data Processor causes a breach?

Rule 6(1) requires the Data Fiduciary to protect personal data in its possession or control including in respect of processing undertaken on its behalf by a Data Processor. The obligation remains with the Data Fiduciary, which is why the contractual provision is mandatory rather than optional.

Reviewing your vendor agreements?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment