A data processor is any person who processes personal data on behalf of a data fiduciary. That is the definition in Section 2(k) of the DPDP Act. The data fiduciary decides why and how the data is processed; the processor carries out that processing on its instructions. Cloud hosting providers, payroll bureaus, call centres, IT support vendors and marketing platforms are typical examples. The Act places almost every obligation on the data fiduciary, so a processor’s duties arrive mainly through its contract rather than directly from the statute.
The distinction matters because it decides who answers to the Data Protection Board. A data fiduciary remains responsible for compliance even when a vendor does the work, and the individual whose data is processed, the data principal, deals with the fiduciary, not the vendor.
Data processor or data fiduciary?
The test is who decides the purpose and means of processing. The same company can be both, for different activities:
- a payroll bureau is a processor for the salary data it handles for clients, and a data fiduciary for the data of its own employees;
- a cloud provider is a processor for the data its customers store, and a data fiduciary for its own billing and account records;
- a marketing agency is a processor while it sends campaigns on a client’s instructions, and becomes a data fiduciary if it uses the same data for its own purposes.
Labels in a contract do not settle the question. If a vendor starts deciding what data to collect or how to use it for its own ends, it is acting as a data fiduciary for that processing and carries the full set of duties.
What the Act requires when you use a processor
| Requirement | Source | What it means in practice |
|---|---|---|
| A valid contract | Section 8(2) | A data fiduciary may engage a processor only under a valid contract |
| Responsibility stays with the fiduciary | Section 8(1) | The fiduciary is responsible for compliance for processing done on its behalf, whatever the contract says |
| Security safeguards | Section 8(5) and Rule 6 | Reasonable safeguards must cover processing by the processor, and the contract must contain appropriate provisions for them |
| Logs kept for a year | Rule 6 | Logs and related personal data must be retained for one year to detect and investigate unauthorised access, unless another law requires otherwise |
| Stopping and erasing | Sections 6(6) and 8(7) | When consent is withdrawn or the purpose ends, the fiduciary must cause its processors to stop processing and erase the data it shared |
| Transparency to individuals | Section 11 | On request, the fiduciary must disclose the identities of the processors with whom personal data has been shared |
The Act has no separate list of processor obligations of the kind found in Article 28 of the GDPR, and the penalties in its Schedule are framed around the data fiduciary. A failure to take reasonable security safeguards, the heaviest of them, carries up to INR 250 crore, and the fiduciary bears it even where the breach happened at a vendor. That is why the contract carries so much weight.
What a processor contract should cover
The Act asks only for a valid contract, but a contract that does not pass these duties down leaves the fiduciary exposed. A sound agreement covers:
- processing only on the fiduciary’s documented instructions and only for the stated purpose;
- the security safeguards the processor must maintain, including encryption, access control, logging and the one year log retention in Rule 6;
- prompt notice to the fiduciary of any personal data breach, so the fiduciary can inform the Board and affected individuals under Section 8(6);
- deletion or return of data when consent is withdrawn, the purpose ends or the contract ends;
- approval before the processor engages sub processors, with the same terms flowing down;
- help with requests from data principals, audit and inspection rights, and where the data will be stored.
Our page on data processing agreement negotiation explains how we help clients agree these terms with vendors.
Two situations worth knowing
Indian vendors serving foreign clients. Under Section 17(1)(d), where a person in India processes personal data of individuals outside India under a contract with a person outside India, most of the Act does not apply. Sections 8(1) and 8(5) still do, so the duty of responsibility and the duty to keep reasonable security safeguards remain. This is the position of many Indian IT and outsourcing firms.
Processors outside India. The Act allows transfers of personal data abroad, including to processors, unless the Government restricts transfers to a notified country under Section 16. Rule 15 also lets the Government set requirements for making personal data available to foreign states or their agencies. A sector regulator’s stricter rule on data localisation continues to apply.
What this means for your organisation
If you are a data fiduciary, list every vendor that touches personal data, decide which of them are processors, put a valid contract in place with each and check that it covers security, breach notice, deletion and sub processors. If you are a processor, expect these clauses in client contracts and make sure your controls can meet them, because your clients’ exposure under the Act becomes yours through the contract. Breach readiness is the area where the two meet; our breach management guide covers it.
These obligations take effect on 13 May 2027, eighteen months after the DPDP Rules were notified. For help with vendor mapping and contracts, see our DPDP consulting page.
Frequently asked questions
Broadly, yes: both process personal data on behalf of another party that decides the purpose. The difference is that the DPDP Act places almost all obligations on the data fiduciary, while the GDPR also imposes direct duties on processors.
The penalties in the Schedule are framed around the data fiduciary, which stays responsible for processing done on its behalf. A processor’s exposure comes mainly through its contract with the fiduciary, and a processor that uses data for its own purposes is treated as a data fiduciary for that processing.
Yes. Section 8(2) allows a data fiduciary to engage a processor only under a valid contract. In practice it should be in writing, because Rule 6 expects it to contain appropriate provisions on security safeguards.
Yes. A payroll bureau, for example, is a processor for its clients’ salary data and a data fiduciary for its own employees’ data. The role is decided activity by activity.
Largely not, where the processing is done under a contract with a person outside India. Section 17(1)(d) exempts most of the Act, but Sections 8(1) and 8(5) on responsibility and security safeguards still apply.
Yes, unless the Government restricts transfers to that country under Section 16 or a sector regulator requires the data to stay in India. The data fiduciary remains responsible for the processing.
Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that provides DPDP consulting. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.