One of the biggest challenges in DPDP implementation isn't technology alone. It's poorly drafted Data Processing Agreements.
Yesterday, I was reviewing a Data Processing Agreement on behalf of one of our clients.
This time, we were advising the Data Processor, not the Data Fiduciary.
As I read through the agreement, I experienced a sense of déjà vu.
The very same gaps that I had noticed while reviewing agreements for other clients over the past year were present here as well.
That's when I realised that one of the biggest challenges in DPDP implementation isn't technology alone. It's poorly drafted Data Processing Agreements.
Most agreements do a good job of covering commercial terms, confidentiality, and information security.
However, in our experience, many agreements do not clearly allocate responsibilities under the Digital Personal Data Protection Act, 2023 (DPDP Act) between the Data Fiduciary and the Data Processor.
These may appear to be minor drafting gaps today.
Tomorrow, they could determine contractual liability, regulatory exposure, and financial loss.
A Data Processing Agreement is not just another vendor agreement.
It is the legal document that allocates responsibility, accountability, and risk between the Data Fiduciary and the Data Processor. While the DPDP Act establishes the legal obligations, the agreement should clearly define how those obligations will be operationalised between the parties.
If you are a Data Fiduciary, clearly define your legal expectations and statutory responsibilities.
If you are a Data Processor, don't negotiate only the commercials. Understand every privacy and compliance obligation before signing the agreement.
A well-drafted Data Processing Agreement doesn't just protect personal data. It protects the relationship between the Data Fiduciary and the Data Processor — and, ultimately, the interests of the Data Principal.