Skip to content
DPDP ActData Processing AgreementsProcessorsGovernance

The Biggest Gap in DPDP Implementation Isn't Technology. It's the Data Processing Agreement

Recurring gaps in Data Processing Agreements reviewed across a year of DPDP engagements — and why the agreement, not technology alone, allocates responsibility between fiduciary and processor.

Dr Prashant Koranne Virtual CISO & Data Protection Officer 3 min read

Yesterday, I was reviewing a Data Processing Agreement on behalf of one of our clients. This time, we were advising the Data Processor, not the Data Fiduciary. As I read through the agreement, I experienced a sense of déjà vu — the very same gaps that I had noticed while reviewing agreements for other clients over the past year were present here as well.

That’s when I realised that one of the biggest challenges in DPDP implementation isn’t technology alone. It’s poorly drafted Data Processing Agreements.

What these agreements get right, and where they stop

Most agreements do a good job of covering commercial terms, confidentiality, and information security.

However, in our experience, many agreements do not clearly allocate responsibilities under the Digital Personal Data Protection Act, 2023 between the Data Fiduciary and the Data Processor.

Some of the gaps we keep seeing

Lawful processing and onward sharing. Responsibilities here are often not clearly allocated, particularly where the Data Processor is expected to transfer or disclose personal data to other entities as part of the agreed business process.

The data lifecycle across the processor’s ecosystem. There is little clarity on how personal data will be transferred to, received by, processed within, shared by, or returned from the Data Processor’s ecosystem, including the respective responsibilities of each party throughout the data lifecycle.

Reasonable security safeguards. The agreement often fails to clearly define what is expected from the Data Processor, leaving requirements such as encryption, masking or pseudonymisation, tokenisation, access controls, logging, and other appropriate safeguards open to interpretation.

Retention, return and secure deletion. These obligations are frequently incomplete or not aligned with contractual, business, or legal requirements.

Breach, grievance, audit and regulatory cooperation. Responsibilities relating to personal data breaches, grievance handling, audit support, regulatory cooperation, and compliance reporting are often ambiguous or operationally impractical.

Why this is not a drafting quibble

These may appear to be minor drafting gaps today. Tomorrow, they could determine contractual liability, regulatory exposure, and financial loss.

A Data Processing Agreement is not just another vendor agreement. It is the legal document that allocates responsibility, accountability, and risk between the Data Fiduciary and the Data Processor. While the DPDP Act establishes the legal obligations, the agreement should clearly define how those obligations will be operationalised between the parties.

What I would advise

My advice is simple.

If you are a Data Fiduciary, clearly define your legal expectations and statutory responsibilities.

If you are a Data Processor, don’t negotiate only the commercials. Understand every privacy and compliance obligation before signing the agreement.

A well-drafted Data Processing Agreement doesn’t just protect personal data. It protects the relationship between the Data Fiduciary and the Data Processor — and, ultimately, the interests of the Data Principal.

Common questions

Isn't a Data Processing Agreement just another vendor agreement?

No. It is the legal document that allocates responsibility, accountability and risk between the Data Fiduciary and the Data Processor. Most agreements cover commercial terms, confidentiality and information security well; what many do not do is clearly allocate the responsibilities the DPDP Act creates.

Which gaps keep recurring?

Five come up repeatedly: responsibilities for lawful processing and onward sharing, particularly where the processor passes data to other entities; how data moves through the processor's ecosystem and who is responsible at each stage; what reasonable security safeguards actually mean; retention, return and secure deletion; and duties around breaches, grievances, audit support, regulatory cooperation and compliance reporting.

Why address this now?

Because these may appear to be minor drafting gaps today, and tomorrow they could determine contractual liability, regulatory exposure and financial loss.

Sources

  1. India Code (Ministry of Law and Justice) — Digital Personal Data Protection Act, 2023

Dr Prashant Koranne

Virtual CISO & Data Protection Officer

Dr Koranne advises organisations across BFSI, healthcare and fintech as a virtual CISO and Data Protection Officer, with three decades in cyber security, governance and technology law and more than 300 consulting engagements behind him. He holds an LLB alongside CISA, PCI QSA, CEH and Elite DPO credentials and is a lead auditor for ISO 27001, 27701 and 42001 — which is why he reads a Data Processing Agreement from the control side and the legal side at once.

See your consent flow,
sealed and verifiable.

A 30-minute walkthrough mapped to your data, your notices, and your DPDP readiness deadline.