Last updated: 20 August 2026
A data processing agreement (DPA) is a contract that governs how one party processes personal data on behalf of another — for example, a cloud or SaaS provider processing data for a business customer. It sits alongside the main commercial contract and allocates the data protection responsibilities.
Under India’s Digital Personal Data Protection Act, 2023, a Data Fiduciary may engage a Data Processor to process personal data only under a valid contract (section 8(2)). The Data Fiduciary remains responsible for compliance with the Act, including for processing carried out on its behalf (section 8(1)) — see Obligations of a Data Fiduciary. A DPA is how that contractual requirement is met in practice.
Where the GDPR applies, Article 28 requires a written contract between the controller and the processor. Among other things, that contract must bind the processor to:
The contract also records the subject matter and duration of the processing, its nature and purpose, and the types of personal data and categories of individuals involved.
A DPA typically reflects these requirements, adjusted to the framework(s) that apply to the parties. A business that both handles Indian personal data and offers services into the EU may need a DPA that addresses both regimes. This page is a general overview and is not legal advice.