Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

01 Processors + contracts

Your processor contract is only useful if operations match it

A clause cannot find a forgotten integration, rotate an administrator, retrieve an incident log or delete an exported copy. The service relationship needs an operating record.

The service-control chain

Purpose and instruction must remain connected to configuration, sub-services, evidence and exit.

The service-control chainPurpose and instruction must remain connected to configuration, sub-services, evidence and exit.01Purposeowner · data · instruction02Contractrole · safeguard · assistance03Serviceregion · access · integration04Evidencereview · log · incident05Exitreturn · delete · revoke
  1. 01
    Purposeowner · data · instruction
  2. 02
    Contractrole · safeguard · assistance
  3. 03
    Serviceregion · access · integration
  4. 04
    Evidencereview · log · incident
  5. 05
    Exitreturn · delete · revoke
Editorial operating model. Replace it with your evidenced systems, owners and decisions.

02 Provision-aware reading

Three states that must not be flattened.

01Operative

What is operative now

· in force

Selected definitions, institutional machinery and rule-making provisions are in force. That does not make every substantive operating duty discussed in this article currently operative.

Check the phased ledger
02Scheduled · 18 months

What is notified for later

· notified future commencement

Most day-to-day Data Fiduciary duties discussed here sit in the notified eighteen-month cohort. The displayed date is derived from the status ledger and must be rechecked against later instruments.

Check the phased ledger

Processor governance fails when the signed agreement and the deployed service describe different systems. Teams add marketplace apps, support access, exports, new regions and sub-processors without updating the role assessment or exit plan. A useful review reconciles contract, configuration, owner and evidence.

The Act and final Rules include duties and safeguards relevant to processing undertaken on behalf of a Data Fiduciary, with substantive provisions in a notified future cohort. This article gives an operational review pattern, not a universal role conclusion or model contract.

Start with facts, not the vendor category

A company name or software category does not settle the role. Record who decides the purpose, who determines relevant means, whose instructions govern the processing and whether the provider acts for independent purposes. Use the current agreement, order form, service description and actual configuration. Separate different services where roles or data flows differ.

Write the assessment as a dated conclusion with unresolved questions. Avoid copying a generic “processor” label into every system row. A payment, communications or identity provider may require a more nuanced analysis that qualified reviewers should confirm.

Reconcile the agreement with the live architecture

List products, regions, data categories, integrations, API users, marketplace extensions, support access, sub-processors and export paths. Compare that record with the contract schedule and security description. A service enabled after signature may not appear in the original review. An unrecorded integration can create a new disclosure even when the core vendor remains unchanged.

Ask the system owner to demonstrate the configuration and retrieve a sample event. Mark the UI path for current-console verification because vendor menus and subscription features change. Save redacted evidence, edition and review date rather than asserting a feature that the account may not have.

Turn security language into specific responsibilities

Map contractual safeguards to controls: encryption or equivalent protection, access management, logging and monitoring, continuity, backup, investigation and remediation. For each, name what the organisation configures, what the provider operates and what evidence is available. A certification report may support due diligence but cannot replace the customer’s own configuration and access review.

Record how the provider notifies incidents, preserves evidence and supports investigation. Test the contact route and escalation. If the service cannot provide the event types or retention window the incident plan needs, capture the gap and compensating action rather than assuming the clause creates data.

Design rights and deletion assistance before a request

Identify the search identifiers, export format, correction mechanism, deletion behaviour, backup treatment and downstream services before a live rights request. Run a synthetic test. Record which actions the customer can perform, which require support and which are unavailable or conditional. Avoid sending a real person’s full file to a support inbox merely to prove assistance.

The contract should align with the operating route, but the test result is the stronger readiness signal. If deletion in the primary service leaves data in an integration, export or restore path, the organisation needs a wider workflow and a residual-copy decision.

Give sub-processors and changes an owner

Record the authoritative place where sub-processor or service-change information appears, who reviews it and what events require reassessment. Changes in location, support model, data category or critical dependency can matter even when the provider’s legal name stays the same. Do not imply that every listed infrastructure company has the same role in every deployment.

Procurement, security and the service owner should share one decision record. Accounts payable can reveal forgotten services; single sign-on and API inventories can reveal access; engineering repositories can reveal embedded processors. Reconcile these views on renewal and after material architecture change.

Exit is a control, not a final email

Define export ownership, format validation, replacement dependencies, user revocation, key rotation, integration shutdown, data return, provider deletion and residual backup treatment. Test the exit path for a representative service before renewal pressure or an incident makes it urgent. Assign a person to confirm that downloaded migration files are protected and later disposed of.

Close the record with evidence and exceptions. A vendor saying “deleted” may be one input; the organisation should also confirm revoked identities, stopped flows and removed local copies. Keep the result proportionate and do not collect unnecessary personal data in the exit log.

Put the next review into somebody's working queue.

A role label is a starting point. Assign named internal owners, evidence locations and review dates in an approved system; this site stores none of them.

01

Founder

  • Assign business ownership for every material service.
  • Require tested exit paths for critical systems.
02

Legal / Privacy

  • Record fact-specific roles, instructions and unresolved questions.
  • Reconcile contract terms with current products and sub-services.
03

IT / Security

  • Verify access, logs, backup and incident evidence.
  • Test revocation, key rotation and provider escalation.
04

Product / Engineering

  • Inventory APIs, extensions and embedded services.
  • Design search, correction, deletion and migration paths.
05

Operations

  • Reconcile service records with invoices and actual users.
  • Own renewal, support and secure export disposal events.

The agreement should describe an operable relationship

Read the contract beside the live service, not in isolation. The useful record connects purpose, role, configuration, evidence, change and exit. Where the two disagree, the discrepancy is the work.

Roles and legal sufficiency depend on facts and current instruments. Preserve that boundary and seek qualified review before relying on a conclusion.

Sources and change log

Gazette instruments govern the text and commencement. Government explainers are contextual; this field note remains editorial analysis.

  1. Act No. 22 of 2023Digital Personal Data Protection Act, 2023

    Section 8, including processing on behalf of the Data Fiduciary and general obligations

  2. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rule 6(1)(f): appropriate processor-contract provision for reasonable security safeguards

  3. G.S.R. 846(E)Digital Personal Data Protection Rules, 2025

    Rule 8(3) and illustrations: future-cohort retention and processor implications

  4. G.S.R. 843(E)DPDP Act commencement notification

    Paragraph (c): substantive obligations in the eighteen-month cohort

Change log

Initial private-preview article created against the final Rules, commencement notification and published corrigendum.

Human-review gate: pinpoints, status and fact-specific interpretations must be rechecked before public reliance.

12 Continue with evidence

Turn the reading into a bounded operating record.

Use a template, inspect the mapped controls or answer the readiness assessment with only what your team can retrieve.

Processor register guideSoftware stackOperating templates