Skip to content

Data Processing Addendum

Last updated: 29 June 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Comply Technologies (“Processor”) and the customer (“Controller” / “Data Fiduciary”) and reflects the parties’ obligations under India’s DPDP Act, 2023 and, where applicable, the GDPR.

1. Roles

The Controller determines the purposes and means of processing personal data; Comply processes personal data only on the Controller’s documented instructions.

2. Scope of processing

Comply processes personal data only to provide the services, for the duration of the agreement, covering the categories of data and data principals defined in the order form.

3. Sub-processors

Comply may engage vetted sub-processors under written contract with equivalent obligations, and will maintain a current list available on request.

4. Security

Comply implements appropriate technical and organisational measures — encryption, access control, continuous monitoring and breach-clock procedures — to protect personal data.

5. Data-principal requests & assistance

Comply assists the Controller in responding to data-principal requests (access, correction, erasure) and in meeting its DPDP/GDPR obligations, including breach notification within required timelines.

6. International transfers & deletion

Where data is transferred across borders, appropriate safeguards apply. On termination, Comply deletes or returns personal data as instructed.

7. Requesting a signed DPA

To execute a counter-signed DPA, contact privacy@comply.in.


This page is provided for general information and does not constitute legal advice. For a contract-ready agreement, please contact us.