Skip to product menu
close
  • Recent Launches
    Press Space or Enter to display list of options
EXPLORE ALL PRODUCTS

Recent Launches

New

Payroll software with automated tax payments and filing.

Try now
New

Robotic process automation software to automate high-volume, rule-based tasks.

Try for free
New

Low-code IoT platform and solutions for connected businesses.

Try now
New

Business formation service to launch and grow your businesses.

Try now
New

Privacy-friendly application analytics solution.

Try for free
SuitesNew

Unified project management platform for intelligent, data-driven work.

Try now

Sales

 
CRM

Comprehensive CRM platform for customer-facing teams.

CRM
 
Bigin

Simple CRM for small businesses moving from spreadsheets.

Bigin
 
Forms

Build online forms for every business need.

Forms
 
SalesIQ

Live chat app to engage and convert website visitors.

SalesIQ
 
Bookings

Appointment scheduling app for consultations with customers.

Bookings
 
Sign

Digital signature app for businesses.

Sign
 
RouteIQ

Comprehensive sales map visualization and optimal route planning solution.

RouteIQ
 
Thrive

Complete loyalty and affiliate management platform.

Thrive
 
Voice

Cloud Contact Center Software for businesses.

Voice
 
Suites
CRM Plus

Unified platform to deliver top-notch customer experience.

CRM Plus

Marketing

 
Social

All-in-one social media management software.

Social
 
Campaigns

Create, send, and track targeted email campaigns that drive sales.

Campaigns
 
Forms

Build online forms for every business need.

Forms
 
Survey

Design surveys to reach and interact with your audience.

Survey
 
Sites

Online website builder with extensive customisation options.

Sites
 
PageSense

Website conversion optimization and personalisation platform.

PageSense
 
Backstage

End-to-end event management software.

Backstage
 
Webinar

Webinar platform for webcasting online webinars.

Webinar
 
Marketing Automation

All-in-one marketing automation software.

Marketing Automation
 
LandingPage

Smart landing page builder to increase conversion rates

LandingPage
 
Publish

Manage all your local business listings on a single platform.

Publish
 
SalesIQ

Live chat app to engage and convert website visitors.

SalesIQ
 
Sign

Digital signature app for businesses.

Sign
 
Thrive

Complete loyalty and affiliate management platform.

Thrive
 
Voice

Cloud Contact Center Software for businesses.

Voice
 
NEW
LeadChain

Sync, manage, and convert leads across channels seamlessly.

LeadChain
 
NEW
CommunitySpaces

Online community platform for individuals and businesses to grow their network and brand.

CommunitySpaces
 
Suites
Marketing Plus

Unified marketing platform for marketing teams.

Marketing Plus

Commerce

 
Commerce

eCommerce platform to manage and market your online store.

Commerce

Service

 
Desk

Helpdesk software to deliver great customer support.

Desk
 
Assist

Remote support and unattended remote access software.

Assist
 
Lens

Interactive remote assistance software with augmented reality.

Lens
 
FSM

End-to-end field service management platform for service businesses.

FSM
 
SalesIQ

Live chat app to engage and convert website visitors.

SalesIQ
 
Voice

Cloud Contact Center Software for businesses.

Voice
 
NEW
Solo

The all-in-one toolkit for solopreneurs.

Solo
 
Bookings

Appointment scheduling app for consultations with customers.

Bookings
 
Suites
Service Plus

Unified platform for customer service and support teams.

Service Plus

Finance

 
Books

Powerful accounting platform for growing businesses.

Books
 
FREE
Invoice

100% Free invoicing solution.

Invoice
 
Expense

Effortless expense reporting platform.

Expense
 
Inventory

Powerful stock management and inventory control software.

Inventory
 
Billing

End-to-end billing solution for your business.

Billing
 
Checkout

Collect payments online with custom branded pages.

Checkout
 
NEW
Payroll

Payroll software with automated tax payments and filing.

Payroll
 
NEW
Solo

The all-in-one toolkit for solopreneurs.

Solo
 
Practice

Practice management software for accounting firms.

Practice
 
Sign

Digital signature app for businesses.

Sign
 
Commerce

eCommerce platform to manage and market your online store.

Commerce
 
Suites
Finance Plus

All-in-one suite to manage your operations and finances.

Finance Plus

Email and Collaboration

 
Mail

Secure email service for teams of all sizes.

Mail
 
Meeting

Online meeting software for all your video conferencing & webinar needs.

Meeting
 
Writer

Word processor for focused writing and discussions.

Writer
 
Sheet

Spreadsheet software for collaborative teams.

Sheet
 
Show

Create, edit, and share slides with a sleek presentation app.

Show
 
Notebook

Beautiful home for all your notes.

Notebook
 
Cliq

Stay in touch with teams no matter where you are.

Cliq
 
Connect

Employee experience platform to communicate, engage, and build positive employee relations.

Connect
 
Bookings

Appointment scheduling app for consultations with customers.

Bookings
 
TeamInbox

Shared inboxes for teams.

TeamInbox
 
WorkDrive

Online file management for teams.

WorkDrive
 
Sign

Digital signature app for businesses.

Sign
 
Office Suite

Powerful collaborative work platform for teams.

Office Suite
 
Office Integrator

Built in document editors for web apps.

Office Integrator
 
ZeptoMail

Secure and reliable transactional email sending service.

ZeptoMail
 
Calendar

Online business calendar to manage events and schedule appointments.

Calendar
 
Learn

Knowledge and learning management platform.

Learn
 
Voice

Cloud Contact Center Software for businesses.

Voice
 
ToDo

Collaborative task management for individuals and teams.

ToDo
 
Tables

Work management tool to connect people, processes, and information.

Tables
 
FREE
PDF Editor

Collaborative online PDF editing tool.

PDF Editor
 
Suites
Workplace

Application suite built to improve team productivity and collaboration.

Workplace

Human Resources

 
People

Organize, automate, and simplify your HR processes.

People
 
Recruit

Intuitive recruiting platform built to provide hiring solutions.

Recruit
 
Expense

Effortless expense reporting platform.

Expense
 
Workerly

Manage temporary staffing with an employee scheduling solution.

Workerly
 
NEW
Payroll

Payroll software with automated tax payments and filing.

Payroll
 
Shifts

Employee scheduling and time tracking app.

Shifts
 
Sign

Digital signature app for businesses.

Sign
 
Suites
People Plus

Comprehensive HR platform for seamless employee experiences.

People Plus

Security and IT Management

 
Creator

Build custom apps to simplify business processes.

Creator
 
Directory

Workforce identity and access management solution for cloud businesses.

Directory
 
FREE
OneAuth

Secure multi-factor authenticator (MFA) for all your online accounts.

OneAuth
 
Vault

Online password manager for teams.

Vault
 
Catalyst

Pro-code platform to build and deploy your apps.

Catalyst
 
Toolkit

Complete resource for any admin-related lookup queries.

Toolkit
 
Lens

Interactive remote assistance software with augmented reality.

Lens
 
Assist

Remote support and unattended remote access software.

Assist
 
QEngine

Test automation software to build, manage, execute, and report testcases.

QEngine
 
NEW
RPA

Automate manual, tedious, and repetitive tasks easily.

RPA

BI and Analytics

 
Analytics

Modern self-service BI and analytics platform.

Analytics
 
Embedded BI

Embedded analytics and white label BI solutions, tailored for your needs.

Embedded BI
 
DataPrep

AI-powered data preparation service for your data-driven organization.

DataPrep
 
NEW
IoT

Harnessing IoT analytics for real-time operational intelligence.

IoT

Project Management

 
Projects

Manage, track, and collaborate on projects with teams.

Projects
 
Sprints

Planning and tracking tool for scrum teams.

Sprints
 
BugTracker

Automatic bug tracking software for managing bugs.

BugTracker
 
NEW
Solo

The all-in-one toolkit for solopreneurs.

Solo
 
Suites
Projects Plus

Unified project management platform for intelligent, data-driven work.

Projects Plus

Developer Platforms

 
Creator

Build custom apps to simplify business processes.

Creator
 
Flow

Automate business workflows by creating smart integrations.

Flow
 
Catalyst

Pro-code platform to build and deploy your apps.

Catalyst
 
Office Integrator

Built in document editors for web apps.

Office Integrator
 
ZeptoMail

Secure and reliable transactional email sending service.

ZeptoMail
 
QEngine

Test automation software to build, manage, execute, and report testcases.

QEngine
 
Tables

Work management tool to connect people, processes, and information.

Tables
 
NEW
RPA

Automate manual, tedious, and repetitive tasks easily.

RPA
 
NEW
Apptics

Application analytics for all apps.

Apptics
 
Embedded BI

Embedded analytics and white label BI solutions, tailored for your needs.

Embedded BI
 
NEW
IoT

Build, deploy, and scale IoT solutions for connected businesses.

IoT
 
DataPrep

AI-powered data preparation service for your data-driven organization.

DataPrep

IoT

 
NEW
IoT

Low-code IoT platform and solutions for connected businesses.

IoT

Search Result

 
CRM Plus

Unified platform to deliver top-notch customer experience.

Try now
CRM Plus
 
Service Plus

Unified platform for customer service and support teams.

Try now
Service Plus
 
Finance Plus

All-in-one suite to manage your operations and finances.

Try now
Finance Plus
 
People Plus

Comprehensive HR platform for seamless employee experiences.

Try now
People Plus
 
Workplace

Application suite built to improve team productivity and collaboration.

Try now
Workplace
 
Marketing Plus

Unified marketing platform for marketing teams.

Try now
Marketing Plus
 
Projects Plus

Unified project management platform for intelligent, data-driven work.

Try now
Projects Plus
 
All-in-one suite

Zoho One

The Operating System for Business

Run your entire business on Zoho with our unified cloud software, designed to help you break down silos between departments and increase organizational efficiency.

TRY ZOHO ONE
Zoho One
Zoho Marketplace

With over 2000 ready-to-use extensions across 40+ categories, connect your favorite business tools with the Zoho products you already use.

EXPLORE MARKETPLACE
Marketplace
Skip to main content

In this ebook, we cover:

  • A comprehensive overview of the DPDPA.
  • Duties of data fiduciaries.
  • Rights of data principals.
  • Implementation, violations, and penalties.
  • The impact of the DPDPA on contract management.
  • How a CLM solution helps improve compliance.

Elevate your contract compliance with the DPDPA

 
DPDPA

India's new data protection law

A guide for contract managers
 

Introduction

India's Digital Personal Data Protection Act (DPDPA) came into effect on the 11th of August, 2023. This Act sets guidelines for handling digital personal data, balancing individuals' rights to protect their data with organizations' legitimate reasons for processing it.

Introduction

Scope

The Act defines personal data as, "any data about an individual who is identifiable by or in relation to such data."

The Act is applicable for the processing of both digital and digitized personal data within the territory of India as well as outside it. Additionally, any activity related to offering goods and services to data principals within India falls under the purview of this Act.

However, the Act does not apply to the processing of data for domestic or personal purposes by individuals. Furthermore, it does not cover personal data that has been made publicly available.

Key stakeholders

(The definitions included here are as mentioned in the Act.)

Data Principal

A Data Principal is the individual to whom the personal data relates and where such individual is—
  • a child, including the parents or lawful guardian of the child.
  • a person with disability, including their lawful guardian, acting on their behalf.

Board

A regulatory body, or Board, refers to the Data Protection Board of India established by the Central Government under section 18 of this Act.

Consent Manager

A Consent Manager is a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform.

Data Fiduciary

A Data Fiduciary is any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data.

Data Processor

A Data Processor is any person who processes personal data on behalf of a Data Fiduciary.

Significant Data Fiduciary

A Significant Data Fiduciary refers to any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10 of this Act.

Data Protection Officer

A Data Protection Officer is an individual appointed by the Significant Data Fiduciary under clause (a.) of sub-section (2.) of section 10 of this Act.

Rights and duties of a Data Principal

Rights and duties of a Data Principal

Right to access information about personal data

Data Principals can ask for:
  • A summary of the personal data being processed.
  • The identities of other entities with whom the data has been shared.
  • Any other related information about their personal data and its processing.

Exemptions are made when data is shared with other entities for detecting or investigating offenses.

Right to correction and erasure of personal data

Data Principals have the right for corrections, completion, updates, or erasure of their data for which they have previously given consent.

Upon receiving a request, it is the responsibility of the Data Fiduciary to correct the data if it is inaccurate, complete it if it is incomplete, update it if it is outdated, and erase it unless the data is required for a specific purpose or legal compliance.

Right of grievance redressal

Data Principals can raise grievances regarding data management with the respective Data Fiduciary or Consent Manager.

These entities must respond to grievances within a specified period. If the requirements are not met, the Data Principals can approach the central board.

Right to nominate

Data Principals can nominate another individual to exercise their data rights in case they're incapacitated (due to mental unsoundness or bodily infirmity) or deceased.

Duties of Data Principals

Data Principals must:
  • Comply with all other relevant laws.
  • Avoid impersonation.
  • Not suppress vital information when providing data for official documents or proofs.
  • Avoid lodging false grievances or complaints.
  • Provide authentic information when asking for corrections or erasure.

Obligations of the Data Fiduciary

The key obligations of the Data Fiduciary are as follows:
  • Data Fiduciaries must comply with the provisions of this Act under all circumstances and be responsible for the data processing by themselves or by the Data Processor.
  • Data Fiduciaries can use data processors to process personal data on its behalf only under a valid contract.
  • Data Fiduciaries must employ suitable technical and organizational measures to follow the Act's provisions.
  • Data Fiduciaries must safeguard personal data against breaches, including when processed by data processors.
  • If there is a data breach, Data Fiduciaries should notify the board and impacted Data Principals.
  • Data should be erased when the Data Principal withdraws consent or when its purpose is no longer served. If a law requires retention, it can be kept.
  • The purpose of retaining data is considered invalid if the Data Principal does not approach the data fiduciary or exercise any related rights for a set period.
  • Data Fiduciaries must publicly share contact details of their Data Protection Officer or a representative who can address queries about personal data processing.
  • Data Fiduciaries must have a system to address grievances of Data Principals.
  • A Data Principal is deemed not to have approached a Data Fiduciary if they have not initiated contact in any form during a specified period.
Obligations of the Data Fiduciary

Obligations of the Significant Data Fiduciary

The significant data fiduciary must fulfill the following obligations:
  • Appoint a Data Protection Officer who will represent them under this Act, be based in India, be answerable to the organization's primary governing entity such as the Board of Directors, and act as the primary point of contact for grievance redressal.
  • Select an independent auditor for compliance assessment.
  • Carry out regular Data Protection Impact Assessments that highlight the rights of Data Principals, the purposes of data processing, and the associated risks.
  • Undertake periodic audits and align with other prescribed measures consistent with this Act.

Monitoring children's personal data

Before handling the personal data of children or individuals with disabilities under guardianship, Data Fiduciaries are obligated to secure verifiable consent from either the child's parent or the guardian. They must ensure that the data processing won't negatively impact a child's welfare and are strictly barred from tracking, behaviorally monitoring, or directing targeted ads at children.

Transfer of personal data outside India

The Central Government has the authority to set rules that may restrict a Data Fiduciary from transferring personal data for processing to specific foreign countries or regions. However, any current Indian law that provides more stringent protection or tighter restrictions on the export of personal data will continue to be in effect and take precedence.

Rights and duties of a Data Principal

Exemptions

Provisions of this Act don’t apply in cases where:
  • Data processing is necessary for legal rights or claims.
  • Data processing is done by courts, tribunals, or any other body which is entrusted by law in India.
  • Data is processed for preventing, detecting, or investigating any offense.
  • Data of individuals outside India is processed based on a contract with someone outside India.
  • Data processing is necessary for corporate restructurings like mergers or demergers approved by the authority.
  • Processing is to determine the financial standing of a loan defaulter.
(For more details on exemptions, please refer to Chapter IV of this law.)

Penalties

Provisions of this Act don’t apply in cases where:
  • Breach of provisions of the Act or rules: Up to ₹250 crore.
  • Failure of the Data Fiduciary to prevent a personal data breach: Up to ₹200 crore.
  • Failure to notify the Board or the affected individual about a data breach: Up to ₹200 crore.
  • Breach regarding children's data obligations: Up to ₹150 crore.
  • Breach in observance of duties by the Data Principal: Up to ₹10,000.
  • Violation of voluntary undertaking accepted by the Board: Penalty applicable for the original breach under section 28.
  • Breach of any other provision of the Act or its rules: Up to ₹50 crore.

The impact of the DPDPA on contract management

Whenever a new law or regulation emerges in the industry that you operate in, it invariably impacts your business and its contracts. Specifically, two broad alterations emerge:

  • Changes in the language of your contracts to reflect the new provisions in the law/regulation.
  • Introduction of new procedures and controls in your contract management process to ensure compliance.

The DPDPA is no exception to this phenomenon. It necessitates the following transformation in the contract management process of an organization.

Changes in contractual languages

Enhanced rights of Data Principals

The DPDPA provides enhanced rights to the Data Principals, including the right to be informed, the right to correction, erasure, and more. Contracts must now reflect and accommodate these expanded rights, specifying the roles and responsibilities of each party.

Liabilities and indemnities

Given the DPDPA's rigorous penalties for data breaches and non-compliance, contracts must carefully address liabilities and indemnities. Thus, organizations would now be required to refine indemnity clauses to manage potential risks and liabilities.

Data breach notification

Contracts need to clearly lay out the processes, responsibilities, and timelines for data breach notifications. The DPDPA necessitates that affected Data Principals and the Board are duly informed.

Data transfers

In light of the DPDPA's strict guidelines on international data transfers, contracts need to integrate provisions like standard contractual clauses to ensure data that is transferred outside of India remains protected.

Record keeping

The DPDPA mandates that certain entities, like the Data Fiduciaries, maintain a comprehensive log of their data processing activities. This means contracts must now have clauses concerning record maintenance, accessibility, and auditing.

Changes to the contract management processes

Vendor management

The DPDPA emphasizes that organizations should be answerable not just for their own adherence to the law, but also for their vendors' and subcontractors' compliance. This translates to a need for a rigorous procedure to gauge and oversee the DPDPA compliance of third-party entities.

Review and update

Given the stricter data protection mandates of DPDPA, organizations need to periodically revisit and update their existing contracts to ensure they're in line with the latest requirements.

Data processing agreements (DPAs)

If an organization engages a Data Processor (as a third party) to process personal data on its behalf, DPDPA requires that a valid contract (i.e., DPA) is in place between the Data Fiduciary and the Data Processor. Contract managers must be adept at incorporating and understanding these agreements.

Training and awareness

The complex requirements of the DPDPA make it imperative for contract management professionals to have a thorough understanding of its provisions. Regular training, combined with internal audits and activity tracking, is vital to ensure consistent compliance and to address any potential oversights promptly.

Staying DPDPA-compliant with CLM software

Centralized contract repository

A centralized digital repository for storing all contracts is essential in ensuring their easy accessibility, searchability, and manageability. For compliance with the DPDPA, such a system is invaluable. For instance, with a centralized repository coupled with advanced analytics, organizations can swiftly identify and isolate contracts containing specific DPDPA clauses that may require modification to remain compliant.

Template standardization

Contract management solutions often provide standardized templates. Organizations can create DPDPA-compliant templates to ensure every new contract meets the necessary requirements, reducing the risk of non-compliance.

Version control

As contracts undergo revisions, it is essential to maintain a clear record of changes, especially concerning data protection clauses. Contract management software typically offers version control features to track versions.

Obligations management

Obligations related to the DPDPA can be complex and time-sensitive. Contract management software aids in capturing and tracking these obligations. Whether it is periodic audits or specific data handling commitments, automated alerts ensure that organizations never miss a deadline, thereby ensuring compliance and fostering trust with stakeholders.

Access controls

The DPDPA emphasizes the principle of data minimization and restricted access—and business contracts comprise a lot of critical data. Contract management software allows organizations to set granular user permissions, ensuring only authorized individuals can access specific contracts or data.

Audit trails

In compliance with the DPDPA's mandates, it is vital for organizations to ensure transparency and accountability in their data handling processes. Contract management systems can provide comprehensive audit trails detailing who accessed a contract, when, and what changes they made.

Data management

The DPDPA mandates that organizations should not retain personal data beyond its necessary duration. Contract management software aids in this aspect by evaluating metadata within the CLM system and examining contract content. This ensures timely deletion or anonymization of data in compliance with DPDPA guidelines.

Encryption and security

To protect personal data, contract management software that align with DPDPA compliance offer robust encryption protocols, both for data in transit and at rest. This reduces the risk of unauthorized data breaches.

About Zoho Contracts

With over 25 years of history, Zoho is trusted by more than a hundred million users worldwide. Zoho Contracts is our contract management solution. It provides an all-in-one CLM solution, allowing businesses to streamline the contract lifecycle on a singular platform. This eliminates the need for multiple apps, reducing contract cycle times and operational costs. Our platform features advanced analytics for strategic insights, detailed activity monitoring, and targeted obligation management to boost compliance, mitigate risks, and improve productivity. Below are some key features of Zoho Contracts.

Avoid using multiple software

Eliminate the need for a separate word processor, email application, e-signature software, spreadsheet system, document management software, and calendar. Zoho Contracts encompasses all of these software to manage your contracts.

Accelerate your contract authoring

Leverage the power of our native authoring capabilities, which are built on a full-blown word processor that has been refined over 15 years of R&D. Write contracts instantly with the help of our predefined templates, the exhaustive clause library, and intuitive collaboration features. Import your contracts in the draft, signed, or even expired states, and manage them all in Zoho Contracts.

Automate approvals

Create your own approval workflows, both sequential and parallel. Approvers can add contextual comments before approving or rejecting a contract.

Negotiate online with password-protected links

Provide secure access to contracts for counterparty contacts through password-protected links. They can engage in synchronous collaboration, propose modifications, annotate with contextual comments, set comment visibility, track negotiation history, and compare changes.

Secure legally binding signatures digitally

Our eSignature capability, powered by Zoho Sign, allows you to establish a signing order for signatories, including representatives from your organization, counterparty organization, and additional representatives, and secure legally binding signatures.

Effortlessly manage post-execution stages

Our automatically generated amendment letters capture the entire contract history as well as the changes that were made in the current amendment. The letter templates are available for renewals, extensions, and terminations as well.

Never miss out on a renewal opportunity

Choose to auto-renew your contracts. Stay updated on renewal opportunities with in-app and email alerts.

Translate contract data into business insights

Get insights from 30+ standard reports across different aspects of contract management. Get a high-level overview of your contracts at a glance with a personalized dashboard.

Stay on top of all activities

Track activities at the individual contract, user, and stage levels. Audit, access, and download logs ensure improved auditability. The data protection settings allow you to delete and anonymize counterparty data on demand.

Track and manage contractual obligations

Contextually track and manage obligations from within the contract. Allocate tasks to appropriate business stakeholders and schedule reminders. Keep abreast of the ongoing fulfillment of tasks using reports centered on obligations.

Close more deals faster with the Zoho CRM integration

Sales reps can initiate a contract and track its status from Zoho CRM. They can also initiate negotiation, signing, renewal, and amendment requests.

For more information on product features, pricing, and resources, please visit our Zoho Contracts website.

Disclaimer: This e-book does not provide legal advice on the DPDPA. Its objective is to support organizations in developing contract management systems that facilitate compliance. If you have any queries concerning the law, we strongly recommend consulting with your legal counsel and data privacy expert.