Glossary · Data Processor

What Is a Data Processor Under DPDPA?

Your CRM, payroll bureau and cloud host do not take DPDPA liability with them. Section 2(k) names them Data Processors; Section 8(2) requires a valid contract; Section 8(1) keeps you responsible. Paper those vendors before 13 May 2027.

Last reviewed: 25 August 2026

Definition

Under Section 2(k) of the DPDPA, 2023, a Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The dividing line is decision-making: the fiduciary decides why and how data is used; the processor simply acts on the fiduciary's instructions. Your CRM, cloud host, payroll bureau, laboratory information system, SMS or WhatsApp gateway, tally-hosting provider and email platform are typically processors. Section 8(2) lets you engage one only under a valid contract. Critically, Section 8(1) keeps you responsible for compliance — including for processing your processor carries out on your behalf.

Fiduciary vs processor, in practice

Data Fiduciary Data Processor
Decides purpose Yes No
Acts on instructions No Yes
Answers to the data principal Yes No — routes to you
Board looks to You — the fiduciary stays liable Does not take your liability with them

Two things this does not mean. First, engaging a processor does not transfer your liability — you cannot point at your vendor when the Board asks why consent wasn't collected. Second, a processor is not automatically a Significant Data Fiduciary. SDF status under Section 10 applies only where the Central Government notifies an entity, and it brings the Rule 13 annual audit, DPIA and India-resident DPO with it. A large SaaS provider may or may not be notified; that is not something you can assume from its size.

How this matters in practice

Most 15–40 person firms have twelve to twenty processors and a contract with none of them — just a signed-up-online SaaS account and a Terms page. Privigo builds your processor register, flags which vendors touch personal data, and generates DPDPA-aligned contract addenda covering purpose limits, security, breach notification upstream to you, sub-processor disclosure and deletion at contract end.

Frequently asked questions

We use Zoho CRM, a payroll consultant and a WhatsApp Business gateway. Do we need a separate agreement with each?

Yes — Section 8(2) requires a valid contract with every processor, and clicking through standard terms is usually thin. For established SaaS vendors, check whether they publish a data processing addendum you can accept; many now do for India. For your payroll consultant, gateway reseller or local IT partner, you'll likely need to add a written addendum yourself. Cover purpose limits, security, sub-processors, breach notice to you, and deletion on exit.

If our CRM vendor gets breached, are we off the hook?

No. You remain the fiduciary and stay accountable — reporting to the Data Protection Board and informing affected individuals is your obligation, not theirs. Four lanes run together: CERT-In within 6 hours of noticing a reportable cyber incident; Rule 7(1) intimation to affected people without delay; Rule 7(2)(a) initial Board intimation without delay; and Rule 7(2)(b) the detailed Board report within 72 hours. That only works if your contract obliges the vendor to tell you immediately.

Can we be a fiduciary and a processor at the same time?

Regularly. A digital marketing agency is a processor for its clients' customer lists, and a fiduciary for its own employees and leads. A diagnostic lab is a fiduciary for walk-in patients and a processor for samples referred by a hospital. Map it per data set, not per company — the same organisation can hold both roles, with different obligations attaching to each.

Official sources

List every vendor that touches personal data

Book a 30-minute call. We map your CRM, payroll, cloud and messaging stack to Section 8(2) contracts and flag where click-wrap terms leave you exposed.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.