This document presents a layered summary of the Infosys Vendor Data Processing Agreement (DPA) in accordance with best practices recommended by the UK Information Commissioner’s Office (ICO), the European Data Protection Board (EDPB), and the International Association of Privacy Professionals (IAPP) for layered transparency notices.
How to Navigate This Document:
- Layer 1 – “At a Glance” Overview: A one-page quick-reference dashboard summarizing the key elements of the DPA in table format.
- Layer 2 – Detailed Section-by-Section Summary: A plain-language narrative summary of each section and schedule, providing sufficient detail for operational understanding without reproducing the full legal text.
- Layer 3 – Cross-Reference Guide: A mapping table linking each summary section to its corresponding clause in the full DPA for easy reference.
| Topic | Key Points | Full DPA Reference |
|---|---|---|
| Parties & Scope | Infosys Limited (or subsidiaries/affiliates) as Controller; Vendor/service provider as Processor. Applies to all processing in connection with the Main Agreement. | Sections 1-2; Schedule A |
| Personal Data Processed | 11 categories including: Identity, Contact, Professional/Employment, Financial/Payroll, IT/Technical, Communications, Usage/Behavioral, Location, Recruitment, Benefits/Dependents, Sensitive Personal Data. | Schedule A |
| Purpose of Processing | Processing performed solely for the provision of Services under the Main Agreement and as documented in Controller instructions. | Section 2; Schedule A |
| Processor Obligations | Comply with all Applicable Data Protection Laws; no selling/sharing of data; confidentiality obligations; assist with DSARs, DPIAs, and audits. | Section 3 (3.1-3.9) |
| Security Measures | 12 categories of technical and organizational measures including encryption (AES-256, TLS 1.2+), access controls, incident response, and ISO 27001/SOC 2 Type II certification. | Section 3.3; Schedule B |
| Subprocessors | Prior written consent required; equivalent contractual obligations; maintained register of approved subprocessors. | Section 3.4; Schedule C |
| International Data Transfers | Appropriate safeguards required (SCCs, adequacy decisions, PIPL mechanisms, APP 8, IPP 12); transfer mechanisms documented for 23 jurisdictions. | Section 3.8; Schedules D-E |
| AI Processing | No AI use without explicit prior written consent; transparency, accountability, and data minimization required; prompt notification of AI-related incidents. | Section 4 (4.1-4.6) |
| Data Breach Notification | 48-hour notification to Controller; must include breach details, affected data, consequences, and remedial actions; assist with authority and Data Subject notifications. | Section 5 (5.1-5.3) |
| Data Subject Rights | Processor assists Controller with all types of data subject requests within statutory deadlines. | Section 3.5 |
| Data Retention & Deletion | Return or securely delete all Personal Data upon termination; certification of deletion required. | Section 7 (7.1-7.2) |
| Liability & Indemnification | Each Party liable for its own breach of the DPA; Processor indemnifies Controller for losses arising from Processor's breach. | Section 8 (8.1-8.2) |
| Governing Law | Jurisdiction specified in the Main Agreement; disputes resolved per Main Agreement mechanisms. | Section 9 |
| Jurisdiction-Specific Obligations | Local Processing Agreements for 20+ jurisdictions; specific requirements mapped to each local law (GDPR, CCPA/CPRA, LGPD, PIPL, DPDP Act, etc.). | Section 3.9; Schedule F |
This layer provides a plain-language narrative summary of each section and schedule of the DPA. It is intended for operational understanding and does not reproduce the full legal text.
The DPA defines 11 key terms that form the foundation for interpreting all obligations:
Personal Data: Any information relating to an identified or identifiable natural person processed in connection with the Services.
Processing: Any operation performed on Personal Data, whether automated or manual, including collection, storage, use, disclosure, and deletion.
Controller: Infosys Limited (or its subsidiaries/affiliates) that determines the purposes and means of processing.
Processor: The vendor/service provider that processes Personal Data on behalf of the Controller.
Subprocessor: Any third party engaged by the Processor to assist with processing activities.
Data Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
AI Processing: Any use of artificial intelligence, machine learning, or automated decision-making systems in connection with Personal Data.
Sensitive Personal Data: Special categories of data including health, biometric, racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, and sexual orientation.
Applicable Data Protection Laws: All data protection and privacy laws applicable to the processing, as identified in Schedule A.
Data Subject Rights: The rights of individuals under applicable law, including access, rectification, erasure, restriction, portability, and objection.
Party/Parties: The Controller and the Processor, individually or collectively.
This DPA applies to all processing of Personal Data by the Processor on behalf of the Controller in connection with the Services provided under the Main Agreement. The specific categories of data, data subjects, and processing purposes are detailed in Schedule A. Processing must be carried out solely in accordance with the Controller's documented instructions and for no other purpose.
3.1 General Compliance
The Processor must comply with all Applicable Data Protection Laws. The Processor shall not sell, share, or use Personal Data for cross-context behavioral advertising or any purpose beyond the documented instructions of the Controller. If the Processor believes an instruction infringes applicable law, it must promptly notify the Controller.
3.2 Confidentiality
All personnel authorized to process Personal Data must be bound by appropriate confidentiality obligations, whether contractual or statutory. The Processor must ensure that access to Personal Data is limited to those personnel who require it for the performance of the Services.
3.3 Security Measures
The Processor must implement and maintain appropriate technical and organizational security measures as detailed in Schedule B. These measures must be designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.
3.4 Subprocessing
The Processor shall not engage any subprocessor without the prior written consent of the Controller. Where consent is granted, the Processor must impose equivalent data protection obligations on the subprocessor through a written contract. The Processor remains fully liable for the acts and omissions of its subprocessors. A current register of approved subprocessors is maintained in Schedule C.
3.5 Data Subject Rights
The Processor must assist the Controller in fulfilling its obligations to respond to data subject requests, including requests for access, rectification, erasure, restriction, portability, and objection. Assistance must be provided within timeframes that allow the Controller to meet statutory deadlines.
3.6 Data Protection Impact Assessments (DPIAs)
The Processor must assist the Controller with data protection impact assessments and any prior consultations with supervisory authorities, providing all necessary information regarding the processing activities performed on behalf of the Controller.
3.7 Audits
The Processor must make available to the Controller all information necessary to demonstrate compliance with its obligations. The Processor must allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor must also cooperate with supervisory authorities as required.
3.8 International Data Transfers
Any transfer of Personal Data to a country outside the jurisdiction of origin must be made subject to appropriate safeguards. These include Standard Contractual Clauses (SCCs), adequacy decisions, PIPL-specific mechanisms for China, Australian Privacy Principle 8 (APP 8), New Zealand Information Privacy Principle 12 (IPP 12), and other jurisdiction-specific mechanisms as detailed in Schedule D. Transfer Impact Assessments must be completed per Schedule E.
3.9 Jurisdiction-Specific Obligations
Where processing is subject to jurisdiction-specific requirements, the Processor must comply with the applicable Local Processing Agreement set out in Schedule F. These agreements contain supplementary obligations tailored to the requirements of each local data protection law.
4.1 Prohibition Without Consent
The Processor shall not use any form of artificial intelligence, machine learning, or automated decision-making in connection with the processing of Personal Data without the explicit prior written consent of the Controller. This includes generative AI tools, large language models, and any automated profiling systems.
4.2 Transparency
Where AI processing is authorized, the Processor must provide the Controller with detailed information about the AI systems used, including the type of technology, the purpose of its use, the categories of data processed, the logic involved, and the potential consequences for data subjects.
4.3 Compliance and Accountability
The Processor must ensure that any authorized AI processing complies with all applicable AI-specific regulations, does not result in discrimination or bias, and maintains full accountability and auditability of AI-driven decisions affecting data subjects.
4.4 Data Minimization
AI processing must adhere to strict data minimization principles. The Processor must apply anonymization or pseudonymization wherever possible and ensure that only the minimum amount of Personal Data necessary is used for the authorized AI purpose.
4.5 No Retention for Own Purposes
The Processor must not retain any Personal Data processed through AI systems for its own purposes or for the benefit of third parties. All outputs, models, and derived data remain the property of the Controller unless otherwise agreed in writing.
4.6 AI Incident Notification
The Processor must promptly notify the Controller of any AI-related incidents, including but not limited to algorithmic bias events, unauthorized data use by AI systems, model failures affecting Personal Data integrity, and any regulatory inquiries concerning AI processing.
5.1 Notification Timeline
The Processor must notify the Controller of any Data Breach without undue delay and in any event within 48 hours of becoming aware of the breach. Notification must be made regardless of the perceived severity of the breach.
5.2 Notification Content
The breach notification must include: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its effects; and (d) the name and contact details of the Processor's designated point of contact.
5.3 Assistance with Notifications
The Processor must assist the Controller with any notifications required to supervisory authorities or data subjects under applicable law, providing all information and cooperation necessary for the Controller to meet its notification obligations.
6.1 Legal Basis and Consent
The Controller warrants that it has obtained all necessary rights, consents, and legal bases for the processing of Personal Data as contemplated under the DPA and the Main Agreement.
6.2 Instructions and Information
The Controller shall provide the Processor with all information and instructions necessary for the Processor to fulfill its obligations under the DPA, including clear documentation of processing purposes and scope.
6.3 Controller Compliance
The Controller shall comply with all obligations applicable to it as a data controller under Applicable Data Protection Laws, including maintaining records of processing activities and conducting required impact assessments.
7.1 Data Return
Upon termination or expiration of the Main Agreement, or upon the Controller's request, the Processor shall return all Personal Data to the Controller in a commonly used, machine-readable format, unless applicable law requires continued storage.
7.2 Secure Deletion
Where return is not requested or practicable, the Processor shall securely delete or destroy all Personal Data and all existing copies, using methods that prevent reconstruction or recovery. The Processor must provide written certification of deletion upon request.
8.1 Liability
Each Party shall be liable for damages caused by its breach of the DPA. The Processor shall be liable for damage caused by processing that does not comply with the Controller's lawful instructions or the obligations of the DPA.
8.2 Indemnification
The Processor shall indemnify and hold harmless the Controller against all claims, losses, damages, fines, and expenses arising from or in connection with the Processor's breach of the DPA or any Applicable Data Protection Laws.
The DPA shall be governed by the law specified in the Main Agreement. Any disputes arising under or in connection with the DPA shall be resolved in accordance with the dispute resolution mechanism set forth in the Main Agreement.
The DPA may only be amended by written agreement signed by both Parties. If any provision is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. This DPA supersedes all prior agreements and understandings between the Parties relating to the subject matter hereof.
Schedule A provides the comprehensive operational details of the processing activities covered by the DPA.
Applicable Data Protection Laws (27 Jurisdictions):
The DPA covers processing subject to the following laws: GDPR (EU), UK GDPR, CCPA/CPRA (California), US State Privacy Laws, DPDP Act (India), LGPD (Brazil), PIPL (China), UAE PDPL, DIFC DPL, PDPA (Singapore), Philippine DPA, Privacy Act/APPs (Australia), NZ Privacy Act (New Zealand), Saudi PDPL, Oman PDPL, POPIA (South Africa), APPI (Japan), Malaysia PDPA, Thailand PDPA, PIPA (South Korea), PIPEDA (Canada), Argentina PDPL, Puerto Rico Privacy Laws, Peru PDPL, Chile DPL, Costa Rica DPL, and Mauritius DPA.
Categories of Personal Data (11 Types):
Identity Data; Contact Data; Professional/Employment Data; Financial/Payroll Data; IT/Technical Data; Communications Data; Usage/Behavioral Data; Location Data; Recruitment/Candidate Data; Benefits/Dependents Data; and Sensitive Personal Data.
Categories of Data Subjects (8 Types):
Employees/Workers; Job Applicants; Clients/Customers; Business Contacts; End Users; Website Visitors; Dependents/Beneficiaries; and Trainees/Learners.
Schedule B details 12 categories of security controls that the Processor must implement and maintain:
| # | Category | Key Measures |
|---|---|---|
| 1 | Organizational Security | Information Security Management System (ISMS), security awareness training, personnel background checks |
| 2 | Physical Security | Physical access controls, CCTV surveillance, data center environmental protections |
| 3 | Access Control & Authentication | Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), password policies, least privilege |
| 4 | Network & Infrastructure Security | Firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), patch management, endpoint protection |
| 5 | Encryption & Pseudonymization | AES-256 encryption at rest, TLS 1.2+ in transit, key management procedures |
| 6 | Data Classification & Handling | Data classification framework, sensitivity-based handling procedures, labeling |
| 7 | Application Security | Secure SDLC, vulnerability assessments, regular penetration testing |
| 8 | Incident Detection & Response | Incident response plan, SIEM monitoring, annual tabletop exercises |
| 9 | Business Continuity & Disaster Recovery | BC/DR plans, defined RTO/RPO targets, regular testing |
| 10 | Vendor/Subprocessor Security | Due diligence assessments, contractual security requirements, ongoing monitoring |
| 11 | Data Retention & Secure Disposal | Defined retention limits, cryptographic erasure, certification of destruction |
| 12 | Audit & Assurance | ISO 27001 certification, SOC 2 Type II reports, regular internal audits |
Schedule C contains the register of approved subprocessors. For each subprocessor, the register records: the subprocessor's name, location of processing, purpose of engagement, and date added to the register. The Processor must update this register and obtain Controller consent before engaging any new subprocessor.
Schedule D provides the framework for international data transfers across 23 jurisdictions. For each jurisdiction, it specifies the applicable transfer mechanism (e.g., EU SCCs, UK International Data Transfer Agreement, PIPL-specific mechanisms), the relevant issuing authority, and template clauses to be incorporated into transfer agreements. The schedule ensures that all cross-border transfers are supported by appropriate legal safeguards.
Schedule E provides a structured template for conducting Transfer Impact Assessments (TIAs) prior to international data transfers. The template contains five sections:
Section 1: Exporter/Importer Details
Identification of the data exporter and importer, including contact information and roles.
Section 2: Description of Transfer
Details of the data transferred, categories of data subjects, purpose, and frequency.
Section 3: Transfer Mechanism Verification
Confirmation of the legal mechanism relied upon and its validity.
Section 4: Assessment of Third Country Laws
Analysis of the legal framework in the recipient country, including government access powers and data protection safeguards.
Section 5: Supplementary Measures
Identification of any additional technical, organizational, or contractual measures required to ensure adequate protection.
Schedule F contains jurisdiction-specific supplementary obligations for 20 jurisdictions. Each Local Processing Agreement maps specific requirements of the relevant local data protection law to the Processor's obligations. The covered jurisdictions are:
EU/EEA & UK; United States; India; Brazil; China; UAE & DIFC; Singapore; Philippines; Australia; New Zealand; Saudi Arabia; Oman; South Africa; Japan; Malaysia; Thailand; South Korea; Canada; Argentina; Puerto Rico, Peru, Chile, Costa Rica, and Mauritius.
Each Local Processing Agreement addresses jurisdiction-specific requirements such as mandatory data localization, local representative appointments, specific consent requirements, sector-specific regulations, and local authority notification obligations.
Annexure 1 addresses the specific data protection requirements applicable to staffing agencies engaged as subcontractors. It contains seven parts:
Part I: Definitions and Role Allocation
Defines the specific roles and responsibilities in the staffing context, establishing two processing scenarios: Scenario A (Internal Processing) where the staffing agency processes data for Infosys's internal purposes, and Scenario B (Client Processing) where processing relates to client-facing services.
Part II: General Obligations
Sets out baseline obligations applicable in both scenarios, including: processing only per documented instructions, confidentiality requirements, access controls, security measures, breach notification obligations, data subject rights assistance, DPIA support, prohibition on unauthorized use, onboarding/offboarding procedures, and sub-staffing restrictions.
Part III: Additional Obligations for Scenario A (Internal Processing)
Specifies enhanced requirements when the staffing agency processes Personal Data for Infosys's internal workforce management, HR administration, and operational purposes.
Part IV: Additional Obligations for Scenario B (Client Processing)
Establishes heightened requirements for client-facing processing, including: flow-down of client-specific data protection obligations, client audit rights, strict data segregation between engagements, compliance with client-specific security requirements, and an accelerated 24-hour breach notification timeline for incidents affecting client data.
Part V: Cross-Border Transfers
Applies the DPA's international transfer framework to staffing agency engagements, ensuring that transfers of staffing-related Personal Data comply with the mechanisms set out in Schedule D.
Part VI: Audit, Compliance, and Indemnification
Grants Infosys the right to audit the staffing agency's compliance, establishes reporting requirements, and sets out indemnification obligations for breaches by the staffing agency.
Part VII: Sub-Staffing Agency Register
Requires the staffing agency to maintain a register of any sub-staffing agencies engaged, subject to the same prior consent and equivalent obligation requirements as subprocessors under the main DPA.
The table below maps each summary section in Layer 2 to the corresponding clause or schedule in the full DPA. The full legal text is available upon request or at the designated document repository.
| Layer 2 Summary Section | Full DPA Reference | Notes |
|---|---|---|
| Section 1: Definitions | Section 1, pp. 1-2 | 11 defined terms establishing interpretive framework |
| Section 2: Scope and Purpose | Section 2 | Processing scope linked to Main Agreement |
| Section 3.1: General Compliance | Section 3.1 | Overarching compliance obligation |
| Section 3.2: Confidentiality | Section 3.2 | Personnel confidentiality requirements |
| Section 3.3: Security Measures | Section 3.3; Schedule B | 12 categories of TOMs |
| Section 3.4: Subprocessing | Section 3.4; Schedule C | Consent and subprocessor register |
| Section 3.5: Data Subject Rights | Section 3.5 | Assistance with DSARs |
| Section 3.6: DPIAs | Section 3.6 | Impact assessment support |
| Section 3.7: Audits | Section 3.7 | Audit and inspection rights |
| Section 3.8: International Transfers | Section 3.8; Schedules D-E | Transfer mechanisms for 23 jurisdictions |
| Section 3.9: Jurisdiction-Specific | Section 3.9; Schedule F | Local Processing Agreements |
| Section 4: AI Clauses | Section 4 (4.1-4.6) | AI governance and restrictions |
| Section 5: Data Breaches | Section 5 (5.1-5.3) | 48-hour notification framework |
| Section 6: Controller Obligations | Section 6 (6.1-6.3) | Controller warranties and compliance |
| Section 7: Termination/Data Return | Section 7 (7.1-7.2) | Return or deletion upon termination |
| Section 8: Liability/Indemnification | Section 8 (8.1-8.2) | Liability allocation and indemnity |
| Section 9: Governing Law | Section 9 | Per Main Agreement |
| Section 10: Miscellaneous | Section 10 | Amendments, severability, supersession |
| Schedule A: Processing Details | Schedule A | 27 laws, 11 data categories, 8 subject categories |
| Schedule B: Security Measures | Schedule B | 12 TOM categories with specific controls |
| Schedule C: Subprocessors | Schedule C | Subprocessor register template |
| Schedule D: Transfer Clauses | Schedule D | 23-jurisdiction transfer mechanisms |
| Schedule E: TIA Template | Schedule E | 5-section Transfer Impact Assessment |
| Schedule F: Local Agreements | Schedule F | 20-jurisdiction specific obligations |
| Annexure 1: Staffing Agencies | Annexure 1 (Parts I-VII) | 7-part staffing sub-processing framework |