Data Processing Addendum (DPDP)
An addendum allocating data fiduciary and processor roles, for vendor contracts signed before the DPDP Rules were notified.
What to watch when you use this
- Most vendor contracts in force were signed before the DPDP Rules were notified in November 2025 and do not allocate roles at all.
- Obligations phase in, with fuller compliance expected from 13 May 2027.
- Roles are allocated by category of data rather than by a single blanket statement, since one vendor is often both.
- This addendum is a starting point; where you process sensitive data at scale, take advice rather than adopting a form.
Stamping and registration. Stamp duty is a State subject, and an unstamped or insufficiently stamped instrument is generally inadmissible in evidence under Section 35 of the Indian Stamp Act, 1899 until the duty and penalty are paid. Registration requirements are separate and depend on the instrument and the State. Confirm both for your State before executing this document.
DATA PROCESSING ADDENDUM
This Addendum is made on [DATE] between [CUSTOMER NAME], [ADDRESS] ("Customer") and [VENDOR NAME], [ADDRESS] ("Vendor"), and forms part of the agreement between them dated [DATE] ("Principal Agreement").
1. DEFINITIONS
Terms used in this Addendum that are defined in the Digital Personal Data Protection Act, 2023 and the rules made under it ("DPDP") have the meanings given there.
2. ROLES
2.1 In respect of the personal data described in Annexure A, the Customer is the Data Fiduciary and the Vendor is a Data Processor acting on the Customer's behalf.
2.2 In respect of the data described in Annexure B, which the Vendor processes for its own purposes, the Vendor acts as a Data Fiduciary in its own right.
2.3 The parties will review Annexures A and B if the processing changes.
3. PROCESSING ON INSTRUCTIONS
The Vendor will process personal data described in Annexure A only on the Customer's documented instructions and only for the purposes set out there, and will not process it for its own purposes, including the development, improvement or training of any product, service or model, without the Customer's prior written consent.
4. SECURITY
The Vendor will implement and maintain reasonable security safeguards appropriate to the nature of the personal data and the processing, and will restrict access to personnel who need it to perform the Principal Agreement.
5. PERSONAL DATA BREACH
The Vendor will notify the Customer without undue delay, and in any event within [NUMBER] hours, of becoming aware of a personal data breach affecting the personal data described in Annexure A, and will provide the information reasonably required for the Customer to meet its own obligations.
6. SUB-PROCESSING
6.1 The Vendor may engage sub-processors listed in Annexure C.
6.2 The Vendor will give the Customer [NUMBER] days' written notice before adding or replacing a sub-processor, and the Customer may object on reasonable grounds.
6.3 The Vendor will impose on each sub-processor obligations no less protective than those in this Addendum, and remains responsible for their performance.
7. ASSISTANCE
The Vendor will provide reasonable assistance to enable the Customer to respond to requests from Data Principals and to meet its obligations under DPDP, within [NUMBER] days of a written request.
8. CROSS-BORDER PROCESSING
The Vendor will process personal data in the locations listed in Annexure D and will notify the Customer before processing in any other location.
9. DELETION AND RETURN
On termination of the Principal Agreement, the Vendor will, at the Customer's election, return or delete the personal data described in Annexure A within [NUMBER] days, other than copies it is required by law to retain, and will confirm in writing that it has done so.
10. RECORDS AND AUDIT
The Vendor will maintain records of its processing and, on reasonable written notice and no more than [ONCE] per year, provide the Customer with the information reasonably necessary to demonstrate compliance with this Addendum.
11. PRECEDENCE
In the event of conflict between this Addendum and the Principal Agreement in relation to the processing of personal data, this Addendum prevails.
Signed:
_______________________ _______________________
For [CUSTOMER] For [VENDOR]
ANNEXURE A: PERSONAL DATA PROCESSED ON THE CUSTOMER'S BEHALF
[Categories of data, categories of data principals, nature and purpose of processing, duration.]
ANNEXURE B: DATA THE VENDOR PROCESSES FOR ITS OWN PURPOSES
ANNEXURE C: APPROVED SUB-PROCESSORS
ANNEXURE D: PROCESSING LOCATIONS
---
This free template is provided by ClauseAudit as general information, not legal advice, and using it does not create an advocate-client relationship. Replace every [BRACKETED] placeholder. Stamp duty and registration requirements vary by State and are your responsibility. Have the final document reviewed by a qualified advocate before use.Been handed the other side's version instead?
Upload it and get every clause checked against Indian law, with the provision each finding rests on.
Review a saas & vendor contractThis free template is general information about Indian law as at 2026-07-27, not legal advice, and using it does not create an advocate–client relationship. Replace every bracketed placeholder and have the final document reviewed by a qualified advocate before use.