#DataProtection

What the DPDP Act means when you hire a software vendor

the two roles, the contract you now need, and the date it starts mattering

If you are buying software that will hold information about your customers, patients or staff, the Digital Personal Data Protection Act 2023 changes what you should be asking for. Not dramatically, and not yet — but the contract you sign this year is the one that has to hold up.

The two roles, and why only one of them carries the fine

The Act splits everyone who touches personal data into two roles. The Data Fiduciary decides why the data is processed and how. The Data Processor does the processing on the Fiduciary’s instructions.

If you run a clinic and we build your appointment system, you are the Fiduciary and we are the Processor. That distinction matters because accountability sits with the Fiduciary even when the processing is outsourced. Handing the work to a vendor does not hand over the obligation.

The penalty ceiling in the Act is up to ₹250 crore for a failure to take reasonable security safeguards. That is the ceiling, not the expectation, but it tells you how seriously the drafters meant it.

The date that matters is 14 May 2027

The DPDP Rules were notified on 13 November 2025 and phase in over eighteen months. The Consent Manager framework starts on 13 November 2026. The obligations most businesses will feel — consent and notice, security safeguards, breach reporting, vendor governance and individual rights — take effect on 14 May 2027.

That is not far away for a system you are commissioning now. Software bought in 2026 will still be running in 2027, and retrofitting consent handling and deletion into a system that was not designed for it costs more than building it in.

The contract is the part people forget

The Rules require a written contract with every processor, carrying appropriate security provisions. That is not only your software vendor. It is every third party that touches the data: hosting, email delivery, payment processing, analytics, CRM, the spreadsheet tool someone exports to.

If you cannot list those today, that list is the first piece of work, ahead of any software.

Five questions worth asking a vendor

  • Where will the data physically be stored, and by whom?
  • Which sub-processors will touch it, and will you tell me when that list changes?
  • How does a person exercise access, correction and erasure — is there a mechanism, or does it mean a support ticket and a manual database edit?
  • What happens to the data when the contract ends?
  • How and how fast will you tell me about a breach?

A vendor who cannot answer the fourth one has not thought about it. A vendor who answers the third with “we would handle that manually” is telling you the obligation will land on your staff.

What we do about it

We are a Processor when we build or run something for a client, and we agree those terms in writing before work starts rather than after. We also ask clients not to send us production personal data for scoping or demonstrations — anonymised or invented data works just as well for working out what to build, and it means there is nothing to lose while the scope is still moving.

None of this is legal advice, and we are not lawyers. It is what we have had to understand to build responsibly, written down in case it saves you the reading.

Common questions

Does the DPDP Act apply if all my customers are in India?

Yes. The Act applies to processing of digital personal data within India, and also to processing outside India where it relates to offering goods or services to people in India. Being India-only does not take you outside it.

If my vendor leaks the data, am I liable?

The Data Fiduciary remains accountable for processing carried out on its behalf. A contract with your processor is how you allocate responsibility between you, but it does not remove your obligation to the people whose data it is.

Do I need a data processing agreement with every tool we use?

With every third party that processes personal data on your instructions, yes. That usually includes hosting, email, payments, CRM and analytics. Tools that never see personal data are a different question.

Next step

Building something for your business?

Tell us who will use it and what they do today. If the answer is not clear yet, that is the conversation worth having first.