Our Expert in India
No results available
Technology contracts in India now operate under a fundamentally different regulatory baseline. The Digital Personal Data Protection Act, 2023 (DPDP Act), operationalised through the DPDP Rules notified in November 2025, imposes binding obligations on data fiduciaries and processors that must be reflected in every SaaS, cloud and managed-services agreement. Simultaneously, the amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, gazetted on 10 February 2026, introduce new duties around synthetic and AI-generated content (SGI) that directly affect platform contracts, reseller arrangements and AI vendor agreements. This guide provides clause-level drafting language, negotiation redlines and a compliance checklist that general counsel, procurement teams and vendor legal departments can apply immediately.
Before diving into individual clauses, here is a concise checklist for any team reviewing or negotiating technology contracts in India under the 2026 regulatory framework:
At a glance: “Every technology contract touching Indian personal data or AI outputs now requires a DPA, an SGI compliance schedule and a cross-border transfer mechanism.”
Three regulatory instruments now define the compliance perimeter for technology contracts in India. Understanding their scope, definitions and timelines is essential before drafting a single clause.
The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India and to processing outside India where it relates to offering goods or services to data principals in India. The Act introduces the concepts of Data Fiduciary (the entity that determines the purpose and means of processing, equivalent to a controller) and Data Processor (the entity processing data on behalf of the fiduciary). Every technology contract must identify which party assumes which role and attach corresponding obligations.
The DPDP Rules, notified in November 2025, operationalise the Act by specifying breach-notification timelines, the powers and procedures of the Data Protection Board of India, data-principal rights-handling mechanisms and record-keeping requirements for processors. Contracts signed or renewed after the Rules came into force must incorporate these operational details, particularly around breach reporting and the data fiduciary’s obligation to notify both the Board and affected data principals.
The amendments gazetted on 10 February 2026 expand the obligations of significant social media intermediaries and other intermediaries to detect, label and address synthetic or AI-generated information (SGI). Platforms must implement technical measures for identification, apply visible labelling, establish escalation paths to grievance officers and cooperate with law-enforcement agencies. These duties flow directly into vendor and platform contracts wherever an intermediary deploys or integrates third-party AI tools.
Not every clause needs updating in every agreement. The scope of revision depends on the contract type, the data processed and whether AI or intermediary functions are in play.
SaaS contracts require the most comprehensive overhaul. They must now include a DPA, breach-notification SLAs aligned to the DPDP Rules, data-portability and export clauses, and, where AI features are embedded, SGI labelling and indemnity provisions. Buyer-side teams should insist on audit rights covering both data-processing infrastructure and AI-model behaviour.
Traditional on-premise licences require fewer DPDP-specific amendments but still need updated warranty language around data security, IP representations for any AI-assisted features and sub-licensing restrictions where personal data access is involved.
Implementation and managed-services contracts often involve temporary access to production data. These require time-limited processing authorisations, strict purpose-limitation clauses and obligations to delete or return data upon project completion, all aligned to DPDP standards.
| Contract type | Buyer priority | Vendor priority |
|---|---|---|
| SaaS / Cloud | DPA + breach SLAs + AI indemnities + audit rights | Liability caps + sub-processor flexibility + IP protection for models |
| Software licence | Data-security warranties + AI-feature representations | Limitation of liability + restriction of reverse engineering |
| Professional services | Purpose limitation + data deletion + access controls | Scope clarity + time-limited processing windows + change-order mechanism |
The DPA is now the single most important schedule in any technology contract involving Indian personal data. It converts the DPDP Act’s statutory duties into enforceable contractual obligations between fiduciary and processor.
A compliant data processing addendum India teams should insist upon must address, at minimum, the following elements:
Model clause, Security measures: “The Data Processor shall implement and maintain technical and organisational security measures no less protective than those described in Annex B. The Data Processor shall, upon the Data Fiduciary’s written request and no more than once per calendar year, provide evidence of compliance through a third-party audit report or permit an on-site inspection upon 30 days’ prior notice.”
Model clause, Breach notification: “The Data Processor shall notify the Data Fiduciary of any Personal Data Breach within 72 hours of becoming aware of such breach. Notification shall include: (a) nature of the breach; (b) categories and approximate number of Data Principals affected; (c) likely consequences; and (d) measures taken or proposed. A comprehensive root-cause report shall follow within 30 calendar days.”
A SaaS contract India teams negotiate today cannot rely on legacy uptime-and-credits language alone. SLAs must now bridge operational performance with regulatory compliance, particularly around incident response and breach notification.
The cloud SLA India market has traditionally centred on availability percentages. Post-DPDP, SLAs need a parallel incident-response waterfall:
Standard SLAs offer service credits for downtime. Industry observers expect the emerging best practice to be a two-tier credit structure: operational credits for availability failures and compliance credits (or termination triggers) for breaches that create regulatory exposure, such as a failure to notify within the contractual window or a sub-processor data-localisation violation. Buyers should negotiate the right to terminate for cause if a compliance breach remains unremedied after a defined cure period.
DPDP rights include data portability for data principals. SaaS agreements should specify the format (machine-readable, interoperable), the timeline for export upon termination (commonly 60–90 days) and the vendor’s obligation to delete all residual copies after export confirmation.
With the IT Rules 2026 amendments imposing SGI labelling and detection duties on intermediaries, every technology contract involving AI-generated content must now allocate risk with precision. The contractual framework for AI liability clauses India practitioners should adopt has three pillars: representations, indemnities and control rights.
Vendors deploying AI should warrant that:
Model clause, AI indemnity: “The Vendor shall defend, indemnify and hold harmless the Customer against all claims, losses and regulatory penalties arising from: (a) infringement of third-party IP by the AI Model or its training data; (b) failure to label synthetic content as required by applicable IT Rules; (c) harm to any third party directly caused by an AI output generated under this Agreement, except to the extent such harm results solely from the Customer’s modification of the output or use contrary to the Vendor’s published usage guidelines.”
Industry observers recommend that AI indemnities be carved out from the general aggregate liability cap and subject to a separate, higher sub-cap, or an uncapped indemnity for IP infringement, mirroring established software-licensing practice.
Buyers should require vendors to maintain immutable logs of AI inputs and outputs for a defined retention period, grant the buyer the right to audit model behaviour (on anonymised or synthetic test data to protect vendor IP), and provide a human-in-the-loop override mechanism for any AI decision that affects data-principal rights. Where the buyer itself operates as an intermediary, these clauses directly support compliance with IT Rules 2026 SGI detection and reporting obligations.
The DPDP Act restricts the transfer of personal data outside India except to jurisdictions or entities not restricted by the Central Government. The DPDP Rules provide the operational framework for assessing permissible transfers. Every cross-border data transfer India clause must now address the available mechanisms, fallback positions and ongoing monitoring obligations.
| Mechanism | When to use | Key contractual requirement |
|---|---|---|
| Government-approved SCCs | Transfers to jurisdictions not on the restricted list; standard vendor-to-vendor flows | Execute SCC annexes; flow down to sub-processors; annual compliance certification |
| Specific government approval | Transfers to restricted jurisdictions or sensitive data categories | Obtain and document approval before transfer; include suspension clause if approval is revoked |
| Local hosting carve-out | Where regulatory risk is too high or government approval is uncertain | Mandate India-region hosting (cloud availability zone); define fallback if region becomes unavailable |
| Contractual safeguards (commercial) | Interim measure pending SCC finalisation or government guidance | Mirror SCC-equivalent protections; include ratchet clause to adopt official SCCs once notified |
Model clause, Cross-border transfer: “The Data Processor shall not transfer Personal Data outside India except: (a) to jurisdictions not restricted by the Central Government under the DPDP Act; and (b) subject to the execution of Standard Contractual Clauses in the form approved by the Central Government (or, pending such approval, in the form set out in Annex C). The Data Processor shall provide the Data Fiduciary with 30 days’ prior written notice of any new cross-border transfer and shall suspend such transfer if the Data Fiduciary objects on reasonable compliance grounds.”
For high-sensitivity deployments, buyers should include a hosting carve-out requiring the vendor to process and store all personal data within India-region data centres. The fallback clause should address disaster-recovery scenarios: if the India region becomes unavailable, the vendor may temporarily replicate data to an approved alternate region, subject to immediate notification and re-localisation within a defined window (commonly 72 hours of restoration).
Platforms operating as intermediaries under Indian law face expanded duties following the IT Rules 2026 amendments. Where a platform contracts with third-party AI vendors, content providers or integrators, those intermediary due diligence clauses must flow down into the vendor agreement.
Contracts should require vendors to:
The platform should secure the right to audit the vendor’s SGI detection mechanisms (at least annually) and to require remediation within a defined cure period. Failure to remediate should constitute a material breach entitling the platform to suspend the vendor’s integration or terminate the agreement.
The following playbook summarises the key negotiation positions. In-house counsel can use this as a pre-negotiation checklist to identify priority asks and acceptable fallbacks.
| Issue | Buyer ask | Vendor concession / fallback |
|---|---|---|
| DPA scope | Broad audit rights, annual on-site inspection | Accept third-party audit report (SOC 2 / ISO 27001) in lieu of on-site; on-site only for cause |
| Breach notification | Notify within 24 hours | 72-hour initial notice (aligned to DPDP practice); 30-day full report |
| Sub-processor control | Prior written consent for each sub-processor | General authorisation with 30-day objection window and list disclosure |
| AI indemnity | Uncapped indemnity for IP infringement and regulatory penalties | Separate sub-cap for AI-related claims; carve-out for customer-modified outputs |
| Cross-border transfers | India-only hosting mandate | India-primary hosting with DR failover to approved region; ratchet to SCCs |
| Liability cap | Regulatory-penalty exposure excluded from cap | Include regulatory penalties within an elevated super-cap (e.g., 3× annual fees) |
| Termination for compliance breach | Immediate termination right | 30-day cure period; termination only if breach is unremedied |
| Entity type | Trigger for reporting | Typical contractual response (clause) |
|---|---|---|
| Data Fiduciary / Controller | Personal data breach affecting data principal rights under DPDP breach thresholds | Mandatory notification to the Data Protection Board and affected data principals within DPDP timeline; obligation to assist with regulator queries (DPA breach clause) |
| Processor / Service Provider | Security incident affecting fiduciary obligations or continuity of service | Must notify fiduciary within 72 hours; provide root-cause analysis within 30 days; comply with forensic audit clause |
| Platform / Intermediary | SGI detection or misinformation event under IT Rules 2026 | Labelling obligations, takedown/escalation clause, cooperation with grievance officer and law enforcement |
The following clauses are designed as drop-in building blocks. Each should be adapted to the specific agreement and reviewed by qualified counsel before execution.
Drafting technology contracts in India is no longer a matter of adapting global templates with local governing-law clauses. The DPDP Act, the DPDP Rules and the IT Rules 2026 amendments have created a jurisdiction-specific compliance layer that must be embedded at the clause level. In-house teams should follow a three-step roadmap to bring their contract portfolio into alignment:
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mitakshara Goyal at Svarniti Law Offices, a member of the Global Law Experts network.
posted 4 minutes ago
posted 27 minutes ago
posted 53 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 7 hours ago
posted 7 hours ago
posted 7 hours ago
posted 8 hours ago
posted 8 hours ago
posted 9 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message