[codicts-css-switcher id=”346″]

Global Law Experts Logo
technology contracts india

How to Draft Technology Contracts in India After the DPDP Act & IT Rules 2026

By Global Law Experts
– posted 60 minutes ago

Technology contracts in India now operate under a fundamentally different regulatory baseline. The Digital Personal Data Protection Act, 2023 (DPDP Act), operationalised through the DPDP Rules notified in November 2025, imposes binding obligations on data fiduciaries and processors that must be reflected in every SaaS, cloud and managed-services agreement. Simultaneously, the amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, gazetted on 10 February 2026, introduce new duties around synthetic and AI-generated content (SGI) that directly affect platform contracts, reseller arrangements and AI vendor agreements. This guide provides clause-level drafting language, negotiation redlines and a compliance checklist that general counsel, procurement teams and vendor legal departments can apply immediately.

Executive Summary & Key Takeaways

Before diving into individual clauses, here is a concise checklist for any team reviewing or negotiating technology contracts in India under the 2026 regulatory framework:

  • Attach a DPDP-aligned Data Processing Addendum (DPA) to every agreement involving personal data, covering lawful basis, purpose limitation, security standards, breach notification and sub-processor controls.
  • Rewrite SLA breach-notification clauses to mirror the timelines established by the DPDP Rules, linking incident response obligations to both the data fiduciary and the Data Protection Board of India.
  • Add AI / SGI-specific clauses, representations on training-data provenance, synthetic-content labelling duties under IT Rules 2026, indemnities for AI-output harms and human-in-the-loop audit rights.
  • Include cross-border transfer mechanisms, contractual safeguards, hosting carve-outs or government-approved standard contractual clauses (SCCs) as mandated by the DPDP Act.
  • Map intermediary due diligence duties into vendor contracts: content labelling, takedown/escalation workflows, grievance-officer cooperation and law-enforcement reporting.
  • Negotiate liability caps and indemnity carve-outs separately for data-protection breaches and AI-output harms, these carry regulatory-penalty exposure and should sit outside general aggregate caps.
  • Implement a continuous-audit playbook, schedule annual contract reviews tied to regulatory amendments and Data Protection Board guidance.

At a glance: “Every technology contract touching Indian personal data or AI outputs now requires a DPA, an SGI compliance schedule and a cross-border transfer mechanism.”

Regulatory Snapshot: DPDP Act, DPDP Rules & IT Rules 2026

Three regulatory instruments now define the compliance perimeter for technology contracts in India. Understanding their scope, definitions and timelines is essential before drafting a single clause.

DPDP Act, Scope & Definitions

The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India and to processing outside India where it relates to offering goods or services to data principals in India. The Act introduces the concepts of Data Fiduciary (the entity that determines the purpose and means of processing, equivalent to a controller) and Data Processor (the entity processing data on behalf of the fiduciary). Every technology contract must identify which party assumes which role and attach corresponding obligations.

DPDP Rules 2025, Operational Obligations

The DPDP Rules, notified in November 2025, operationalise the Act by specifying breach-notification timelines, the powers and procedures of the Data Protection Board of India, data-principal rights-handling mechanisms and record-keeping requirements for processors. Contracts signed or renewed after the Rules came into force must incorporate these operational details, particularly around breach reporting and the data fiduciary’s obligation to notify both the Board and affected data principals.

IT Rules 2026 Amendments, Intermediary & SGI Duties

The amendments gazetted on 10 February 2026 expand the obligations of significant social media intermediaries and other intermediaries to detect, label and address synthetic or AI-generated information (SGI). Platforms must implement technical measures for identification, apply visible labelling, establish escalation paths to grievance officers and cooperate with law-enforcement agencies. These duties flow directly into vendor and platform contracts wherever an intermediary deploys or integrates third-party AI tools.

Practical Drafting Decisions: Contract Types & Where Technology Contracts India Changes Matter

Not every clause needs updating in every agreement. The scope of revision depends on the contract type, the data processed and whether AI or intermediary functions are in play.

SaaS Agreements

SaaS contracts require the most comprehensive overhaul. They must now include a DPA, breach-notification SLAs aligned to the DPDP Rules, data-portability and export clauses, and, where AI features are embedded, SGI labelling and indemnity provisions. Buyer-side teams should insist on audit rights covering both data-processing infrastructure and AI-model behaviour.

Software Licence & Assignment

Traditional on-premise licences require fewer DPDP-specific amendments but still need updated warranty language around data security, IP representations for any AI-assisted features and sub-licensing restrictions where personal data access is involved.

Professional Services & Implementation Contracts

Implementation and managed-services contracts often involve temporary access to production data. These require time-limited processing authorisations, strict purpose-limitation clauses and obligations to delete or return data upon project completion, all aligned to DPDP standards.

Contract type Buyer priority Vendor priority
SaaS / Cloud DPA + breach SLAs + AI indemnities + audit rights Liability caps + sub-processor flexibility + IP protection for models
Software licence Data-security warranties + AI-feature representations Limitation of liability + restriction of reverse engineering
Professional services Purpose limitation + data deletion + access controls Scope clarity + time-limited processing windows + change-order mechanism

Data Processing Addendum, Core DPDP Act Data Processing Clauses and Model Language

The DPA is now the single most important schedule in any technology contract involving Indian personal data. It converts the DPDP Act’s statutory duties into enforceable contractual obligations between fiduciary and processor.

Required DPA Clauses

A compliant data processing addendum India teams should insist upon must address, at minimum, the following elements:

  • Lawful basis and purpose limitation. The processor may process personal data only for the purposes specified by the fiduciary and only on the lawful basis identified in the agreement.
  • Security measures. The processor must implement reasonable security safeguards, technical and organisational, appropriate to the nature and volume of data processed, and must document those measures in an annex.
  • Sub-processor controls. Prior written authorisation from the fiduciary before engaging any sub-processor; flow-down of equivalent data-protection obligations; right to object to new sub-processor appointments.
  • Data-principal rights support. The processor must assist the fiduciary in responding to data-principal requests (access, correction, erasure) within the timelines specified by the DPDP Rules.
  • Breach notification. The processor must notify the fiduciary of any personal data breach without undue delay. Commercial best practice is to set an initial notification window (commonly 72 hours) with a fuller root-cause report following within 30 days.
  • Audit and inspection rights. The fiduciary (or its appointed auditor) must have the right to audit the processor’s compliance with the DPA, subject to reasonable notice and confidentiality protections.
  • Deletion and return. On termination or expiry of the agreement, the processor must delete or return all personal data (at the fiduciary’s election) and certify deletion in writing.
  • Records of processing. The processor must maintain records of processing activities carried out on behalf of the fiduciary, available for inspection by the Data Protection Board of India upon request.

Model Clause Snippets

Model clause, Security measures: “The Data Processor shall implement and maintain technical and organisational security measures no less protective than those described in Annex B. The Data Processor shall, upon the Data Fiduciary’s written request and no more than once per calendar year, provide evidence of compliance through a third-party audit report or permit an on-site inspection upon 30 days’ prior notice.”

Model clause, Breach notification: “The Data Processor shall notify the Data Fiduciary of any Personal Data Breach within 72 hours of becoming aware of such breach. Notification shall include: (a) nature of the breach; (b) categories and approximate number of Data Principals affected; (c) likely consequences; and (d) measures taken or proposed. A comprehensive root-cause report shall follow within 30 calendar days.”

SaaS & Cloud SLAs: Re‑Writing Uptime, Breach Reporting & Remedies for IT Rules 2026 Contract Obligations

A SaaS contract India teams negotiate today cannot rely on legacy uptime-and-credits language alone. SLAs must now bridge operational performance with regulatory compliance, particularly around incident response and breach notification.

Incident Response & Breach Notification Timelines

The cloud SLA India market has traditionally centred on availability percentages. Post-DPDP, SLAs need a parallel incident-response waterfall:

  • Detection → classification (within 4 hours): the vendor categorises the incident as a security event, service disruption, or personal data breach.
  • Initial notification (within 72 hours of confirmed personal data breach): vendor provides the fiduciary with the information required under the DPA breach clause.
  • Root-cause analysis (within 30 days): full report with remediation plan and evidence of corrective measures.
  • Regulatory cooperation: vendor must assist the fiduciary in responding to any inquiry from the Data Protection Board of India or to directions issued under the IT Rules.

Performance Credits & Termination Rights

Standard SLAs offer service credits for downtime. Industry observers expect the emerging best practice to be a two-tier credit structure: operational credits for availability failures and compliance credits (or termination triggers) for breaches that create regulatory exposure, such as a failure to notify within the contractual window or a sub-processor data-localisation violation. Buyers should negotiate the right to terminate for cause if a compliance breach remains unremedied after a defined cure period.

Data Portability & Export Controls

DPDP rights include data portability for data principals. SaaS agreements should specify the format (machine-readable, interoperable), the timeline for export upon termination (commonly 60–90 days) and the vendor’s obligation to delete all residual copies after export confirmation.

AI and Synthetic Content Clauses: AI Liability Clauses India, Drafting for Transparency, Auditing & Indemnities

With the IT Rules 2026 amendments imposing SGI labelling and detection duties on intermediaries, every technology contract involving AI-generated content must now allocate risk with precision. The contractual framework for AI liability clauses India practitioners should adopt has three pillars: representations, indemnities and control rights.

Representations & Warranties for Models and Data

Vendors deploying AI should warrant that:

  • Training data was lawfully obtained and does not infringe third-party intellectual property rights.
  • The model does not process personal data of Indian data principals beyond the scope authorised in the DPA.
  • Outputs are labelled as AI-generated or synthetic where required by the IT Rules 2026 amendments.
  • The model has been tested for bias, hallucination and harmful-output risk, with test results available for audit.

Indemnity & Insurance Clauses

Model clause, AI indemnity: “The Vendor shall defend, indemnify and hold harmless the Customer against all claims, losses and regulatory penalties arising from: (a) infringement of third-party IP by the AI Model or its training data; (b) failure to label synthetic content as required by applicable IT Rules; (c) harm to any third party directly caused by an AI output generated under this Agreement, except to the extent such harm results solely from the Customer’s modification of the output or use contrary to the Vendor’s published usage guidelines.”

Industry observers recommend that AI indemnities be carved out from the general aggregate liability cap and subject to a separate, higher sub-cap, or an uncapped indemnity for IP infringement, mirroring established software-licensing practice.

Audit, Logging & Human-in-the-Loop Control Clauses

Buyers should require vendors to maintain immutable logs of AI inputs and outputs for a defined retention period, grant the buyer the right to audit model behaviour (on anonymised or synthetic test data to protect vendor IP), and provide a human-in-the-loop override mechanism for any AI decision that affects data-principal rights. Where the buyer itself operates as an intermediary, these clauses directly support compliance with IT Rules 2026 SGI detection and reporting obligations.

Cross‑Border Data Transfer India: Routes, Model Clauses & Negotiation Positions

The DPDP Act restricts the transfer of personal data outside India except to jurisdictions or entities not restricted by the Central Government. The DPDP Rules provide the operational framework for assessing permissible transfers. Every cross-border data transfer India clause must now address the available mechanisms, fallback positions and ongoing monitoring obligations.

Transfer Mechanism Comparison

Mechanism When to use Key contractual requirement
Government-approved SCCs Transfers to jurisdictions not on the restricted list; standard vendor-to-vendor flows Execute SCC annexes; flow down to sub-processors; annual compliance certification
Specific government approval Transfers to restricted jurisdictions or sensitive data categories Obtain and document approval before transfer; include suspension clause if approval is revoked
Local hosting carve-out Where regulatory risk is too high or government approval is uncertain Mandate India-region hosting (cloud availability zone); define fallback if region becomes unavailable
Contractual safeguards (commercial) Interim measure pending SCC finalisation or government guidance Mirror SCC-equivalent protections; include ratchet clause to adopt official SCCs once notified

Model Clause for SCCs

Model clause, Cross-border transfer: “The Data Processor shall not transfer Personal Data outside India except: (a) to jurisdictions not restricted by the Central Government under the DPDP Act; and (b) subject to the execution of Standard Contractual Clauses in the form approved by the Central Government (or, pending such approval, in the form set out in Annex C). The Data Processor shall provide the Data Fiduciary with 30 days’ prior written notice of any new cross-border transfer and shall suspend such transfer if the Data Fiduciary objects on reasonable compliance grounds.”

Hosting Carve-Out & Fallback

For high-sensitivity deployments, buyers should include a hosting carve-out requiring the vendor to process and store all personal data within India-region data centres. The fallback clause should address disaster-recovery scenarios: if the India region becomes unavailable, the vendor may temporarily replicate data to an approved alternate region, subject to immediate notification and re-localisation within a defined window (commonly 72 hours of restoration).

Intermediary Due Diligence & Platform Duties Under IT Rules 2026, Clauses & Escalation

Platforms operating as intermediaries under Indian law face expanded duties following the IT Rules 2026 amendments. Where a platform contracts with third-party AI vendors, content providers or integrators, those intermediary due diligence clauses must flow down into the vendor agreement.

Mandatory Notices & Takedown Flows

Contracts should require vendors to:

  • Implement automated detection of synthetic or AI-generated content and apply visible labels before publication.
  • Respond to takedown notices from the platform’s grievance officer within defined SLAs (commonly 24–36 hours for initial assessment).
  • Cooperate with law-enforcement requests routed through the platform and preserve relevant data for the statutory retention period.
  • Provide the platform with periodic compliance reports confirming adherence to SGI labelling and detection obligations.

Vendor Assurances & Audits

The platform should secure the right to audit the vendor’s SGI detection mechanisms (at least annually) and to require remediation within a defined cure period. Failure to remediate should constitute a material breach entitling the platform to suspend the vendor’s integration or terminate the agreement.

Negotiation Checklist & Redlines for Technology Contracts India, Buyer vs Vendor

The following playbook summarises the key negotiation positions. In-house counsel can use this as a pre-negotiation checklist to identify priority asks and acceptable fallbacks.

Issue Buyer ask Vendor concession / fallback
DPA scope Broad audit rights, annual on-site inspection Accept third-party audit report (SOC 2 / ISO 27001) in lieu of on-site; on-site only for cause
Breach notification Notify within 24 hours 72-hour initial notice (aligned to DPDP practice); 30-day full report
Sub-processor control Prior written consent for each sub-processor General authorisation with 30-day objection window and list disclosure
AI indemnity Uncapped indemnity for IP infringement and regulatory penalties Separate sub-cap for AI-related claims; carve-out for customer-modified outputs
Cross-border transfers India-only hosting mandate India-primary hosting with DR failover to approved region; ratchet to SCCs
Liability cap Regulatory-penalty exposure excluded from cap Include regulatory penalties within an elevated super-cap (e.g., 3× annual fees)
Termination for compliance breach Immediate termination right 30-day cure period; termination only if breach is unremedied

Reporting Obligations & Timelines by Entity Type

Entity type Trigger for reporting Typical contractual response (clause)
Data Fiduciary / Controller Personal data breach affecting data principal rights under DPDP breach thresholds Mandatory notification to the Data Protection Board and affected data principals within DPDP timeline; obligation to assist with regulator queries (DPA breach clause)
Processor / Service Provider Security incident affecting fiduciary obligations or continuity of service Must notify fiduciary within 72 hours; provide root-cause analysis within 30 days; comply with forensic audit clause
Platform / Intermediary SGI detection or misinformation event under IT Rules 2026 Labelling obligations, takedown/escalation clause, cooperation with grievance officer and law enforcement

Practical Annex: Model Clause Bank for Technology Contracts India

The following clauses are designed as drop-in building blocks. Each should be adapted to the specific agreement and reviewed by qualified counsel before execution.

  • DPA, Purpose limitation: “The Data Processor shall process Personal Data solely for the purposes described in Schedule [X] and shall not process Personal Data for any other purpose without the Data Fiduciary’s prior written instruction.”
  • DPA, Sub-processor: “The Data Processor shall not engage any Sub-Processor without the Data Fiduciary’s prior written authorisation. The Data Processor shall impose data-protection obligations on each Sub-Processor that are no less protective than those set out in this Addendum.”
  • AI indemnity: “The Vendor shall indemnify the Customer against all third-party claims arising from infringement of intellectual property rights by the AI Model’s training data or outputs and against regulatory penalties imposed under applicable law due to the Vendor’s failure to label synthetic content as required.”
  • SCC / Cross-border transfer: “Transfer of Personal Data outside India shall be subject to the Standard Contractual Clauses set out in Annex [C]. Pending government notification of approved SCCs, the Parties shall apply the interim safeguards in Annex [C-1], which mirror the protections required under the DPDP Act.”
  • SLA, Compliance credit: “In addition to availability credits under Section [Y], if the Service Provider fails to notify the Customer of a Personal Data Breach within 72 hours, the Customer shall be entitled to a compliance credit equal to [5]% of the monthly fee for each 24-hour period of delay, and shall have the right to terminate for cause if the delay exceeds [7] calendar days.”
  • Intermediary, SGI labelling: “The Vendor warrants that all AI-generated or synthetic content delivered through the Platform shall be clearly labelled as such prior to publication, in accordance with the IT (Intermediary Guidelines) Rules as amended. The Vendor shall implement automated detection mechanisms and provide the Platform with quarterly compliance certificates.”

Conclusion & Recommended Next Steps

Drafting technology contracts in India is no longer a matter of adapting global templates with local governing-law clauses. The DPDP Act, the DPDP Rules and the IT Rules 2026 amendments have created a jurisdiction-specific compliance layer that must be embedded at the clause level. In-house teams should follow a three-step roadmap to bring their contract portfolio into alignment:

  1. Risk mapping. Inventory all active technology agreements; identify those involving personal data processing, AI features or cross-border transfers; prioritise high-risk SaaS and cloud contracts for immediate remediation.
  2. Contract remediation. Attach or update DPAs, revise SLAs with breach-notification timelines, insert AI indemnity and SGI labelling clauses, and implement cross-border transfer mechanisms, using the model clauses and negotiation positions outlined in this guide.
  3. Continuous audit & playbooks. Establish an annual contract-review cycle tied to regulatory developments; maintain a living clause bank updated with each new Data Protection Board directive or IT Rules amendment; and build internal playbooks so procurement and vendor teams negotiate from a consistent, compliant baseline.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mitakshara Goyal at Svarniti Law Offices, a member of the Global Law Experts network.

Sources

  1. Ministry of Electronics & IT (MeitY), IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
  2. MeitY, Amendments to IT (Intermediary Guidelines) Rules, 2021
  3. MeitY, Digital Personal Data Protection Rules, 2025
  4. Press Information Bureau (PIB), Notification of DPDP Rules
  5. MeitY, Acts, Policies, Orders & Notices
  6. India Code, Digital Personal Data Protection Act, 2023 (Official Text)

FAQs

What contract clauses does the DPDP Act require data controllers and processors to include?
Include lawful processing basis, purpose limitation, security measures, breach notification obligations, data-principal rights support, auditor access and sub-processor controls, typically via a DPA attached to the main agreement. These clauses operationalise the duties assigned to data fiduciaries and processors under the DPDP Act and Rules.
The DPDP Rules set specific notification timelines for the Data Protection Board and affected data principals. Standard commercial practice is to set an initial vendor-to-fiduciary notification window of 72 hours, with a comprehensive root-cause report following within 30 days.
Add contractual breach-notification clauses aligned to IT Rules timelines, require incident categorisation (security event vs personal data breach vs SGI event), define investigation roles, and provide credits or termination rights for compliance-impacting failures.
Contractually allocate risk through vendor representations about training-data provenance, indemnities for third-party IP infringement or regulated harms, carve-outs for customer-modified outputs, and insurance or liability-cap negotiations. AI indemnities should ideally sit outside the general aggregate cap.
The DPDP Act and Rules recognise contractual safeguards such as government-approved SCCs, specific approvals for restricted jurisdictions and local hosting obligations. Contracts should include fallback clauses and ratchet provisions to adopt official mechanisms once notified.
Yes, but scope should be narrowly defined, covering security controls and anonymised samples rather than raw training data. Vendors can require NDA execution, redaction of proprietary elements and controlled-environment access to protect IP and data-principal PII.
Run a contract inventory, prioritise high-risk SaaS and cloud agreements, update DPAs and SLAs with breach timelines and regulatory-cooperation obligations, negotiate AI indemnities with separate sub-caps, and implement continuous audit playbooks tied to Data Protection Board guidance.
Estate Lawyer USA | Global Law Experts News
By Jonathon Richards

posted 7 hours ago

By Peter Pang

posted 8 hours ago

By Awatif Al Khouri

posted 8 hours ago

By Ujjwal Sharma MCIArb

posted 8 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Draft Technology Contracts in India After the DPDP Act & IT Rules 2026

Send welcome message

Custom Message