What the DPDP Act means for the contracts you sign
India's Digital Personal Data Protection Act reaches into ordinary commercial agreements. What changes in your vendor contracts, offer letters and NDAs — and what to fix first.

The Digital Personal Data Protection Act, 2023 is usually discussed as a privacy-policy problem. It is also a contracts problem, and that part gets noticed later — normally when a customer's procurement team sends over a data processing addendum and asks you to sign it.
This is what changes in the paper your business already signs.
A note on what this is. This is a plain-language summary written for people who have to make practical decisions, not legal advice. Your counsel should see anything you actually intend to sign.
The two roles, and why yours is not fixed
The Act splits responsibility between the Data Fiduciary, who decides why and how personal data is processed, and the Data Processor, who processes it on the fiduciary's instructions.
Most businesses are both, on different days. You are a fiduciary for your own employees' data. You are very likely a processor for your customers' data. The obligations differ, and a contract written as though you are only ever one of them will be wrong half the time.
Where it lands in ordinary agreements
Vendor and services agreements
Section 8(2) requires a Data Fiduciary to engage a processor only under a valid contract. That is a direct instruction to your paper: if a vendor touches personal data on your behalf, the agreement has to say so and has to set the terms.
Expect to add, or be asked to accept, clauses covering purpose limitation, security safeguards, breach notification timelines, sub-processor consent, deletion or return on termination, and audit rights.
Offer letters and employment documents
Employee data is personal data. The consent and notice architecture applies, with the Act's carve-outs for employment purposes. The practical consequence is that your offer letter and onboarding pack need a notice that actually describes what you collect and why — not a paragraph copied from a website privacy policy.
NDAs
A confidentiality clause is not a data protection clause, and the two are routinely confused. An NDA restricts disclosure. The DPDP Act governs processing, including uses that involve no disclosure at all. If personal data moves under an NDA, the NDA alone does not discharge the obligation.
Consent, and the retention consequence
Consent under the Act has to be free, specific, informed, unconditional and unambiguous, with a clear affirmative action — and it has to be as easy to withdraw as it was to give.
The part that catches people is what follows withdrawal. When consent is withdrawn or the purpose is served, the fiduciary must cease processing and erase the data, and cause its processors to do the same, unless retention is required by law.
That obligation is only as good as your ability to find the data. If executed agreements sit in three drives, two inboxes and a filing cabinet, "we will erase it" is a statement nobody can honestly make.
Breach notification has no grace period
Every personal data breach must be reported to the Data Protection Board and to each affected Data Principal. The Act does not scale the obligation by severity, which means the internal question is not was this serious enough to report but do we know it happened at all.
Detection depends on records. An access trail on every document is the difference between reporting accurately and guessing.
Four things worth fixing first
- Find out which of your templates involve personal data. Usually more than expected: offer letters, vendor agreements, customer contracts, consultancy agreements, sometimes NDAs.
- Write one processing addendum and reuse it. Negotiating data terms from scratch on every deal is where both the cost and the inconsistency come from.
- Make retention findable. You cannot erase on request what you cannot locate, and a search across storage systems is not a process — it is an incident.
- Keep the trail. Who accessed which agreement and when is both a breach-detection tool and the evidence that your processes ran as documented.
Why this is a records problem
Almost every DPDP obligation on the contract side resolves to the same question: can you show what happened to a document, and can you act on all copies of it at once.
A business whose executed agreements live in one indexed archive, each with a complete access and signature trail, can answer that in minutes. A business whose agreements are scattered across drives and mailboxes can only answer it by asking people to remember — which is not an answer a regulator will accept, and not one your own counsel will be comfortable giving.