[codicts-css-switcher id=”346″]

Global Law Experts Logo

Author

  • GOLD

The DPDP Compliance Countdown: Five Contracts Every Business Should Review Now

By Sourav De Biswas
– posted 2 hours ago

The DPDP Compliance Countdown: Five Contracts Every Business Should Review Now

Customer details, employee records and vendor databases are part of everyday business. With India’s new data protection requirements approaching, companies should start checking the agreements that govern how this information is used.

Where does the law stand today?

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the final DPDP Rules, 2025 are taking effect in stages. Certain provisions, including those relating to the Data Protection Board, have already commenced. The consent-manager provisions are scheduled for November 2026. Most business obligations—including notice, consent, security, individual rights and breach reporting—are scheduled to commence in May 2027, under the notified timetable.

As of today, those main DPDP obligations are not yet in force. Businesses must meanwhile continue to comply with the applicable Information Technology Act and Sensitive Personal Data or Information (SPDI) Rules, 2011, alongside existing cybersecurity and sector-specific requirements. The transition does not suspend the law that applies now.

The discussion below explains what companies should prepare for under DPDP. It concerns digital information about identifiable individuals, including information collected on paper and later digitised. Even a business that sells only to other businesses may hold personal data about their staff, as well as its own employees.

A useful starting point is to follow one customer’s or employee’s information through the business. Who collects it? Where is it stored? Which outside agency receives it? The answers often lead to these five groups of documents.

1. Customer terms and privacy notices

A customer should be able to understand why a business needs their information. Under the forthcoming Rules, consent notices must explain the data and purposes clearly and be understandable on their own. A vague reference to “business purposes” will not do.

Start with the forms people actually see: the website sign-up page, purchase screen, loyalty programme and customer-support form. Check whether each field is necessary and whether the explanation matches what the business does with it. A delivery address may be needed to fulfil an order; a date of birth may need a different explanation.

Make optional marketing choices clear. Information supplied for an order should not automatically be treated as permission for unrelated advertising. Where consent is needed, the customer must actively agree, and withdrawing it must be comparably easy. An optional marketing choice is often a practical way to avoid confusion.

Older customer databases also need attention. For consent obtained before the relevant provisions commence, the Act provides for a notice to be given as soon as reasonably practicable. It does not automatically require fresh consent from every existing customer. First check what was agreed, what evidence exists and whether the intended use has changed.

Action now: ask the legal, marketing and product teams to review the same customer journey together. Keep records of the notice shown and the customer’s choice, and test whether an unsubscribe request reaches every relevant system.

2. Vendor and data-processing agreements

Outsourcing work does not transfer all responsibility for personal data. Under DPDP, the business deciding why and how data is used remains responsible for processing done on its behalf. That includes work handled by cloud providers, payroll agencies and customer-support vendors.

The agreement should explain what the vendor may do with the information, who may access it and whether other service providers can be involved. It should also cover security, help with individual requests, incident reporting and what happens to the data when the relationship ends. These are practical contracting recommendations; each agreement should match the service involved.

A promise to comply with applicable law gives little comfort if the vendor cannot explain its access controls, backups or response to an incident. Ask for suitable evidence, such as security reports, and agree how shortcomings will be corrected. Review liability caps as well: a cap linked to a small monthly fee may offer little protection against a serious incident.

Be careful with promises to “delete everything immediately”. Once effective, Rule 8(3) requires at least one year’s retention of personal data, associated traffic data and processing logs for its specified purposes. Other laws may require longer retention. Agree what will be returned, deleted or retained, for how long, and with what access restrictions.

Action now: begin with vendors handling large databases or information such as bank, health or identity records. Negotiate changes at renewals and use a standard privacy schedule for new contracts.

3. Employment and consultant documents

HR files often contain more personal information than customer databases. Salary details, medical records, attendance logs and background checks may be spread across emails, spreadsheets and outside agencies.

The DPDP Act permits specified employment-related uses without consent. This is not a blanket exemption from data protection duties, nor should it automatically be extended to independent consultants. The purpose and relationship need to be assessed.

Explain routine HR practices in an accessible employee notice. Check who receives the information, how long records are kept and whether staff can raise questions or correct errors. Review monitoring practices, including CCTV, biometric attendance and access to work devices, rather than relying on a broad clause in the appointment letter.

For international groups, identify overseas HR systems and access by group companies. Transfers need to be checked against applicable rules; neither group ownership nor an overseas server settles the compliance question.

Action now: ask HR to list every agency and system receiving employee information. Review payroll, insurance, recruitment and background-check arrangements, and remove access that former staff or vendors no longer need.

4. Data-sharing, partnership and platform agreements

A loyalty partnership, referral arrangement or joint promotion can move customer information between several businesses. Problems arise when each assumes the other obtained the necessary permission.

First establish what each party actually does. Is an agency sending communications only on your instructions, or does the partner use customer details for its own campaigns? The contract should reflect that difference and identify who handles notices, permissions, requests and complaints.

An agreement between two businesses does not by itself authorise every use of an individual’s data. Be specific about permitted uses, onward sharing and security, and check that the customer-facing explanation supports the arrangement.

Action now: review collaborations where information crosses company boundaries, including within a corporate group. Try the customer journey yourself and check whether it is clear which business receives the information and why.

5. Acquisition documents and due-diligence data rooms

An acquisition can expose employee records, customer details and complaint files to buyers, lenders and advisers. A confidentiality agreement helps, but does not settle whether personal information may lawfully be shared.

DPDP provides a limited exemption for processing necessary for certain approved schemes, mergers and restructurings. It does not give every private share sale or diligence exercise a general exemption. Even within that exemption, responsibility and reasonable security safeguards remain.

Before opening a data room, ask what the buyer really needs. Salary bands and anonymised headcount may be sufficient initially. Identity documents, medical records or named complainants may call for redaction, restricted access or later disclosure. Limit downloads where appropriate and decide what happens to the information if the deal fails.

Buyers should examine past incidents, customer permissions and vendor arrangements. Where a problem is identified, the acquisition documents should allocate the work and cost of fixing it. A general compliance warranty may be less useful than a specific correction required before closing.

Action now: include a privacy check in data-room preparation and plan who will handle customer and employee information after completion.

Make incident clauses work in real time

Once the DPDP breach rules commence, affected individuals and the Board must be informed without delay. Detailed information must follow to the Board within 72 hours of awareness, unless the Board permits more time on a written request. The 72-hour period is not permission to postpone the first notification.

Existing CERT-In directions separately require covered organisations to report specified cyber incidents within six hours of noticing them or being informed of them. These requirements already apply and must be considered alongside the future DPDP process.

A vendor clause allowing five business days to report an incident can leave the company unable to respond in time. Agree prompt escalation, named contacts and continuing updates. Test the process outside office hours and ensure the vendor does not wait for a completed investigation before alerting you.

What management should start doing

Give one person responsibility for coordinating the work across legal, IT, HR, procurement and marketing. Then set manageable priorities:

  1. In the next 30 days: list the main databases, purposes, recipients and vendors. Include spreadsheets and email attachments, not just formal IT systems.
  2. Over the following 60 days: review the highest-risk agreements and customer forms. Prepare standard clauses, a retention schedule and a process for requests and complaints.
  3. Before May 2027: implement and test the changes. Check an actual withdrawal request, a vendor exit and a simulated breach, and report unresolved issues to management.

Businesses serving children should separately assess parental consent and the restrictions on tracking, behavioural monitoring and targeted advertising under the forthcoming framework, including any applicable exemptions. These issues may require product changes that a contract alone cannot achieve.

The timetable is a suggested work plan, not a statutory sequence. The best place to begin is the arrangement where your business holds the most information but has the least clarity about who can use it. Resolve that gap, assign the next one, and make sure the agreed changes happen in practice.

By Yasuchika Fukuda

posted 36 minutes ago

By Yasuchika Fukuda

posted 36 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The DPDP Compliance Countdown: Five Contracts Every Business Should Review Now

Send welcome message

Custom Message