DPDP Compliance Is Due 13 May 2027. Is Your Vendor Contract Ready?
Most vendor contracts are not ready. The DPDP Rules, 2025 were notified on 13 November 2025 and the substantive obligations apply from 13 May 2027, so a contract signed today should already allocate data fiduciary and processor roles.
India now has a data protection statute with a compliance deadline attached. Most vendor contracts in force today were signed before the Rules existed, which means the obligations arriving in 2027 are not reflected in the documents that govern how your data is actually handled.
Key takeaways
- The Digital Personal Data Protection Act, 2023 is the operative statute; the DPDP Rules, 2025 were notified on 13 November 2025.
- Obligations phase in, with full compliance expected from 13 May 2027.
- The Act distinguishes a data fiduciary, who decides purposes and means, from a data processor acting on their behalf.
- A fiduciary is expected to bind its processors by contract, which is where existing vendor agreements fall short.
- Contracts signed before November 2025 will almost never address these roles.
Why this is a contract problem, not only a policy problem
Organisations responding to DPDP tend to start with a privacy notice and a consent flow, which are visible and customer-facing. The harder work sits behind them, in the contracts with every vendor that touches personal data on your behalf: your CRM, your payroll provider, your support desk, your analytics tools, your cloud infrastructure.
The Act contemplates that a data fiduciary remains answerable for personal data it is responsible for, including where processing is carried out by someone else under contract. That makes the contract the instrument through which the obligation is passed down, and a contract that never mentions data protection roles is not doing that job.
What the timeline actually is
The Act was passed in 2023 and the Rules were notified on 13 November 2025. Rather than everything commencing at once, obligations phase in over a period, with the fuller set of compliance requirements expected from 13 May 2027.
The practical reading for a business is that the deadline is far enough away to plan for and close enough to matter for contracts being signed now. A three-year SaaS agreement signed today runs straight through the compliance date, which is exactly why the data protection terms in it are worth getting right at signature rather than amending later.
What a vendor contract should address
- Which party is the data fiduciary and which is the processor for each category of data.
- The purposes for which the vendor may process, and a prohibition on processing for its own purposes.
- Security obligations and a breach notification process with a defined timeline.
- Sub-processing: whether the vendor may engage others, and on what terms.
- Deletion or return of personal data on termination, and within what period.
- Cross-border transfer, since much SaaS infrastructure sits outside India.
- Assistance with data principal requests, so you can meet your own obligations.
The realistic remediation path
Auditing every vendor contract at once is not how this gets done in practice. The workable sequence is to inventory which vendors actually receive personal data, rank them by volume and sensitivity, and address the top of that list first. A payroll provider and a marketing analytics tool are not the same risk.
For contracts up for renewal, the renewal is the moment of leverage. For long-dated contracts, most enterprise vendors are issuing data processing addenda proactively because their other customers are asking, so requesting one is usually a short conversation rather than a negotiation.
A caution on precision
This is a regime that is still bedding in. The Rules were notified recently, the phasing is spread over time, and guidance continues to develop. An article can tell you the shape of the obligations and which contract terms to look at. It cannot tell you that a particular arrangement is compliant.
Where personal data is central to your business, or where you handle sensitive categories at scale, this is worth proper advice rather than a checklist, and the time to get it is while the deadline is still ahead of you.
Have a contract in front of you?
Upload it and get every clause checked against Indian law, with the provision each finding rests on.
Review your saas & vendor contractCommon questions
Does DPDP apply to a small Indian company?
The Act applies to the processing of digital personal data with the exemptions and thresholds it sets out, and certain obligations attach to entities designated as significant data fiduciaries rather than to everyone. Whether and how it applies to your organisation depends on what you process and at what scale, which is worth confirming rather than assuming size exempts you.
Our vendor is outside India. Does that change things?
Cross-border processing is addressed by the Act and is one of the terms a contract should deal with explicitly. It does not make the arrangement impossible, but it is a term to look at deliberately rather than leave silent, particularly where infrastructure sits offshore.
Do we need to redo every contract before May 2027?
A prioritised approach is more realistic than a wholesale one. Inventory which vendors receive personal data, rank by volume and sensitivity, and work down the list, using renewals as the natural point of leverage.
Related guides
This article is general information about Indian law as of 2026-07-26, not legal advice, and reading it does not create an advocate–client relationship. Statutes and rules change, particularly under the Labour Codes where State rules are still being notified. Consult a qualified advocate about your own situation.