All insights

Sovereignty & Data Residency

Reading a Vendor DPA With Sovereign Eyes

· 10 minute read

A DPA is not a privacy policy with signatures. Read it as a map of who may touch a citizen record after you click approve, including the subprocessors the cover letter never named.

The additional solicitor in a union ministry received the vendor pack on a Friday. The commercial team wanted a Monday signature so the pilot could start before a secretary-level review. Inside the pack was a twelve-page Data Processing Addendum written for a global SaaS customer. Clause 2 said the vendor would process customer data to provide and improve the services. Clause 8 listed subprocessors as a URL that returned a marketing page. Clause 11 said deletion would occur within a commercially reasonable period.

None of those sentences is rare. All of them fail a sovereign reading. Improve the services is a second purpose. A URL is not a list. Commercially reasonable is not a date. The ministry was about to become a Data Fiduciary that had instructed nothing.

This teardown is how we read an AI DPA with departmental counsel. It is not a substitute for that counsel. It is the mark-up we wish every file already contained before the commercial calendar started to shout.

Write the roles before you read a clause

If the department decides that an agent will read citizen files and draft replies, the department is the Data Fiduciary. The platform vendor is a processor. An SI who can change prompts and tools may be a processor or, if they start setting new purposes, something worse. A model host who retains prompts for abuse review is a sub-processor even if the DPA never uses that word.

Some vendors will try to split the world. They are a processor for the case file and an independent fiduciary for telemetry, security logs or model improvement. That split can be honest for a narrow security event. It is rarely honest for prompt logs. If you accept the split, you have accepted a second purpose. You then need a basis and a notice. Most government files have neither.

The clauses that decide the deal

Mark the DPA against this table. A green cover letter does not paint the cells.
ClauseWeak vendor defaultWhat a sovereign file needs
Purpose and instructionsProvide and improve the servicesNamed workflows only; no improvement; change control for new tools
TrainingMay use data to train models, aggregated or notHard ban on training, fine-tunes, eval-set reuse and distillation
SubprocessorsA URL, plus a right to add names on noticeNamed list with country and function; prior written consent for additions
TransfersVendor may transfer as needed to provide the serviceNo transfer unless listed; Section 16 / Rule 15 decision on file
SecurityIndustry standard measuresNamed controls: encryption, key custody, admin path, logging in India
Deletion and exitCommercially reasonable; certification on requestFixed days; stores named; backups included; certificate without a request tax
AuditSOC 2 on request, no on-siteQuestionnaire plus audit right after incident or annually
Liability and flow-downCap that excludes regulatory fines as indirectFlow-down to subprocessors; no silent carve-out for training claims

Training is the clause that looks small and is not. Improve, develop, quality, safety and abuse all become training if the retained object is a prompt, an embedding or a human-feedback pair. Ban the objects, not the adjectives.

Subprocessors are the clause that looks boring and is not. An India-region application that embeds a foreign guardrail, a foreign speech-to-text engine, or a foreign ticket tool has already transferred. If the list is a URL, print it on the day you sign and put the PDF in the file. Then require notice that is actually prior.

Instructions must be able to change

An agent platform that ships a new tool every sprint will process data the original instruction never named. The DPA should say that new connectors, new model hosts and new memory features are changes of instruction. They need written approval. A release note in a Slack channel is not written approval.

Objections you will hear across the table

This is our global paper, we cannot change it for one ministry. Then you are not selling to a ministry. You are selling a consumer product. Indian public bodies are allowed to walk.

SOC 2 covers this. SOC 2 covers a control environment at a point in time. It does not name your subprocessors, does not ban training on your records, and does not put logs in India. Attach the report. Do not substitute it for the schedule.

DPDP allows transfers. It does. Section 16 and Rule 15 use a restriction model, not a blanket ban. Allowed is not instructed. You still decide whether this transfer exists.

Deletion of backups is impossible. Then write the backup cycle and the date the last copy dies. Impossible without a date is a stall. Impossible with a 90-day tape rotation is a fact the file can live with if counsel agrees.

What to do when they send a URL

If the only DPA is a link, print it the day you receive it and the day you sign. Diff the two. If a training sentence appeared, you caught a silent change. Put both PDFs in the file. A living URL is not an executed contract.

The same trick appears for subprocessors and for security white papers. Print. Date. Diff. If the vendor refuses a PDF because the page is personalised, that is a reason to slow down, not to trust the page more.

A ten-day mark-up, then a 90-day contract path

  1. Day 1–2: print the DPA, the MSA, the subprocessor URL and the security white paper. Highlight improve, reasonable, from time to time, affiliates, and worldwide.
  2. Day 3–5: fill the clause table. Anything amber or red becomes a schedule request, not a comment in the margin that will be lost.
  3. Day 6–8: counsel plus the technical owner walk the architecture against the schedule. Kill features that cannot be instructed.
  4. Day 9–10: send one mark-up. Do not drip comments.
  5. Days 11–45: negotiate the schedule. If the vendor will not move on training or subprocessors, stop the pilot.
  6. Days 46–90: once signed, test the deletion clause and the subprocessor notice with a drill. A clause that has never been exercised is decoration.

What goes in the file

  • The signed DPA plus the sovereignty schedule, not a link.
  • The printed subprocessor list with countries, dated on signature day.
  • The transfer decision under Section 16 / Rule 15, even if the decision is none.
  • The training-ban language in the same words in the MSA and the DPA.
  • The deletion-certificate template and the backup-expiry date.
  • The note of the last deletion drill and the last undeclared-hostname hunt.

Ask Prcept AI for the same schedule. An Indian LLP and a DPIIT recognition do not replace a training ban, a named subprocessor list, or a deletion certificate that mentions backups.

How to defend this in the file

A P6 Compliance/DPO will be asked to explain “Reading a Vendor DPA With Sovereign Eyes” to a secretary who has ten minutes. Do not start with the model. Start with the store, the hop, the clause, or the residual risk. “data processing agreement AI” is a search phrase. The file needs a decision.

A DPA is not a privacy policy with signatures. Read it as a map of who may touch a citizen record after you click approve, including the subprocessors the cover letter never named. DPDP does not define sovereign AI. Transfers can be lawful and still be a bad idea. Sector circulars can be stricter than DPDP. Write which instrument you are using.

If you cannot name the Data Fiduciary, the processor, the location of traces, and the erasure method, you are not ready for production personal data — whatever the architecture PDF says.

  • One sentence on lawful basis or the procurement rule you are invoking.
  • One sentence on where prompts, embeddings and logs live.
  • One sentence on who can compel the operator.
  • One artefact: packet capture, DPA schedule, or deletion certificate template.

Close this loop before the next CAB

Put “Reading a Vendor DPA With Sovereign Eyes” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “data processing agreement AI” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Is a vendor privacy policy a substitute for a DPA?
No. A privacy policy is a public notice the vendor can change. A processor contract is an instruction set you can enforce. If the only document is a URL, you do not have a DPA.
Does DPDP require a written processor arrangement?
The fiduciary remains accountable for processing done on its behalf. A written instruction, security standard, sub-processor control and deletion duty is how that accountability is made real. Do not rely on an email thread.
The DPA says the vendor is an independent Data Fiduciary for telemetry. Is that acceptable?
Only if you have a lawful basis for that second purpose and you told the principal. Recasting telemetry as a separate fiduciary relationship is often a way to keep training or analytics outside your instructions. Treat it as a red flag until counsel agrees.
Can we accept the vendor's standard DPA on GeM?
You can accept it after you mark the gaps. GeM convenience does not repeal Section 16, CERT-In, or a sector localisation circular. Attach a schedule that wins on training, residency of logs, subprocessors and exit.
What if the vendor refuses audit rights?
Then you have no way to test the promises. A reasonable clause is documented questionnaires plus on-site or remote audit on notice, and a right to appoint an independent assessor after an incident. No audit path is not a small omission.

Sources