DPDP Processor Contracts: The Clause Rule 6 Requires
The obligation stays with the Data Fiduciary whatever the contract says. What the contract does is give you a way to require, and evidence, that your vendor holds up their end.
The obligation does not transfer
Rule 6(1) is explicit that a Data Fiduciary must protect personal data in its possession or under its control, including in respect of any processing undertaken on its behalf by a Data Processor. Rule 6(1)(f) then requires appropriate contractual provision for safeguards.
So the contract is not a way to move risk. It is a required control, and a means of evidencing that you imposed the safeguards you were obliged to impose.
What the clause should reach
- The Rule 6 measures themselves: encryption or equivalent, access control, logging with one year retention, and continuity measures.
- Prompt notification to you of any incident. Your Rule 7 clock runs from your awareness, and your processor is usually the source of it. Ambiguity here costs you the seventy-two hours.
- Deletion on instruction, so you can meet Rule 8 erasure and rights requests that reach data they hold.
- Assistance with rights requests, since Rule 14 obliges you and the data may sit with them.
- Sub-processor transparency, because their vendors are in your chain.
- Location of processing, relevant to Rule 15 and to Rule 13(4) if you are notified as a Significant Data Fiduciary.
- A right to evidence, so the clause is verifiable rather than declaratory.
Do it in the right order
Renegotiating live contracts is slow. Start with the processors holding the most personal data and the ones whose failure would hurt most: payment providers, KYC vendors, communication platforms, analytics tools, support systems.
For new contracts, get the clause into your standard template now so the backlog stops growing.
The clause that matters most in practice is the notification one. Everything else can be fixed after an incident. Being told late cannot.
Infosek Team
Both directions
If you are also a Data Processor for your own customers, expect to receive these terms as well as issue them. Having a position drafted in advance turns a two week negotiation into a one day one, which is a commercial advantage as much as a compliance one.
Common questions
What must a DPDP processor contract include?
Rule 6(1)(f) requires appropriate provision in the contract between a Data Fiduciary and a Data Processor for taking reasonable security safeguards. In practice that means binding the processor to the Rule 6 measures, plus the operational commitments the Data Fiduciary needs to meet its own obligations on breach intimation, erasure and rights requests.
Who is liable if a Data Processor causes a breach?
Rule 6(1) requires the Data Fiduciary to protect personal data in its possession or control including in respect of processing undertaken on its behalf by a Data Processor. The obligation remains with the Data Fiduciary, which is why the contractual provision is mandatory rather than optional.
Reviewing your vendor agreements?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment