Skip to main content Skip to footer

Data Processing Agreement Summary

This document presents a layered summary of the Infosys Vendor Data Processing Agreement (DPA) in accordance with best practices recommended by the UK Information Commissioner’s Office (ICO), the European Data Protection Board (EDPB), and the International Association of Privacy Professionals (IAPP) for layered transparency notices.

How to Navigate This Document:

  • Layer 1 – “At a Glance” Overview: A one-page quick-reference dashboard summarizing the key elements of the DPA in table format.
  • Layer 2 – Detailed Section-by-Section Summary: A plain-language narrative summary of each section and schedule, providing sufficient detail for operational understanding without reproducing the full legal text.
  • Layer 3 – Cross-Reference Guide: A mapping table linking each summary section to its corresponding clause in the full DPA for easy reference.

Topic Key Points Full DPA Reference
Parties & Scope Infosys Limited (or subsidiaries/affiliates) as Controller; Vendor/service provider as Processor. Applies to all processing in connection with the Main Agreement. Sections 1-2; Schedule A
Personal Data Processed 11 categories including: Identity, Contact, Professional/Employment, Financial/Payroll, IT/Technical, Communications, Usage/Behavioral, Location, Recruitment, Benefits/Dependents, Sensitive Personal Data. Schedule A
Purpose of Processing Processing performed solely for the provision of Services under the Main Agreement and as documented in Controller instructions. Section 2; Schedule A
Processor Obligations Comply with all Applicable Data Protection Laws; no selling/sharing of data; confidentiality obligations; assist with DSARs, DPIAs, and audits. Section 3 (3.1-3.9)
Security Measures 12 categories of technical and organizational measures including encryption (AES-256, TLS 1.2+), access controls, incident response, and ISO 27001/SOC 2 Type II certification. Section 3.3; Schedule B
Subprocessors Prior written consent required; equivalent contractual obligations; maintained register of approved subprocessors. Section 3.4; Schedule C
International Data Transfers Appropriate safeguards required (SCCs, adequacy decisions, PIPL mechanisms, APP 8, IPP 12); transfer mechanisms documented for 23 jurisdictions. Section 3.8; Schedules D-E
AI Processing No AI use without explicit prior written consent; transparency, accountability, and data minimization required; prompt notification of AI-related incidents. Section 4 (4.1-4.6)
Data Breach Notification 48-hour notification to Controller; must include breach details, affected data, consequences, and remedial actions; assist with authority and Data Subject notifications. Section 5 (5.1-5.3)
Data Subject Rights Processor assists Controller with all types of data subject requests within statutory deadlines. Section 3.5
Data Retention & Deletion Return or securely delete all Personal Data upon termination; certification of deletion required. Section 7 (7.1-7.2)
Liability & Indemnification Each Party liable for its own breach of the DPA; Processor indemnifies Controller for losses arising from Processor's breach. Section 8 (8.1-8.2)
Governing Law Jurisdiction specified in the Main Agreement; disputes resolved per Main Agreement mechanisms. Section 9
Jurisdiction-Specific Obligations Local Processing Agreements for 20+ jurisdictions; specific requirements mapped to each local law (GDPR, CCPA/CPRA, LGPD, PIPL, DPDP Act, etc.). Section 3.9; Schedule F

This layer provides a plain-language narrative summary of each section and schedule of the DPA. It is intended for operational understanding and does not reproduce the full legal text.

The DPA defines 11 key terms that form the foundation for interpreting all obligations:

Personal Data: Any information relating to an identified or identifiable natural person processed in connection with the Services.

Processing: Any operation performed on Personal Data, whether automated or manual, including collection, storage, use, disclosure, and deletion.

Controller: Infosys Limited (or its subsidiaries/affiliates) that determines the purposes and means of processing.

Processor: The vendor/service provider that processes Personal Data on behalf of the Controller.

Subprocessor: Any third party engaged by the Processor to assist with processing activities.

Data Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

AI Processing: Any use of artificial intelligence, machine learning, or automated decision-making systems in connection with Personal Data.

Sensitive Personal Data: Special categories of data including health, biometric, racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, and sexual orientation.

Applicable Data Protection Laws: All data protection and privacy laws applicable to the processing, as identified in Schedule A.

Data Subject Rights: The rights of individuals under applicable law, including access, rectification, erasure, restriction, portability, and objection.

Party/Parties: The Controller and the Processor, individually or collectively.

This DPA applies to all processing of Personal Data by the Processor on behalf of the Controller in connection with the Services provided under the Main Agreement. The specific categories of data, data subjects, and processing purposes are detailed in Schedule A. Processing must be carried out solely in accordance with the Controller's documented instructions and for no other purpose.

3.1 General Compliance

The Processor must comply with all Applicable Data Protection Laws. The Processor shall not sell, share, or use Personal Data for cross-context behavioral advertising or any purpose beyond the documented instructions of the Controller. If the Processor believes an instruction infringes applicable law, it must promptly notify the Controller.

3.2 Confidentiality

All personnel authorized to process Personal Data must be bound by appropriate confidentiality obligations, whether contractual or statutory. The Processor must ensure that access to Personal Data is limited to those personnel who require it for the performance of the Services.

3.3 Security Measures

The Processor must implement and maintain appropriate technical and organizational security measures as detailed in Schedule B. These measures must be designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.

3.4 Subprocessing

The Processor shall not engage any subprocessor without the prior written consent of the Controller. Where consent is granted, the Processor must impose equivalent data protection obligations on the subprocessor through a written contract. The Processor remains fully liable for the acts and omissions of its subprocessors. A current register of approved subprocessors is maintained in Schedule C.

3.5 Data Subject Rights

The Processor must assist the Controller in fulfilling its obligations to respond to data subject requests, including requests for access, rectification, erasure, restriction, portability, and objection. Assistance must be provided within timeframes that allow the Controller to meet statutory deadlines.

3.6 Data Protection Impact Assessments (DPIAs)

The Processor must assist the Controller with data protection impact assessments and any prior consultations with supervisory authorities, providing all necessary information regarding the processing activities performed on behalf of the Controller.

3.7 Audits

The Processor must make available to the Controller all information necessary to demonstrate compliance with its obligations. The Processor must allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Processor must also cooperate with supervisory authorities as required.

3.8 International Data Transfers

Any transfer of Personal Data to a country outside the jurisdiction of origin must be made subject to appropriate safeguards. These include Standard Contractual Clauses (SCCs), adequacy decisions, PIPL-specific mechanisms for China, Australian Privacy Principle 8 (APP 8), New Zealand Information Privacy Principle 12 (IPP 12), and other jurisdiction-specific mechanisms as detailed in Schedule D. Transfer Impact Assessments must be completed per Schedule E.

3.9 Jurisdiction-Specific Obligations

Where processing is subject to jurisdiction-specific requirements, the Processor must comply with the applicable Local Processing Agreement set out in Schedule F. These agreements contain supplementary obligations tailored to the requirements of each local data protection law.

4.1 Prohibition Without Consent

The Processor shall not use any form of artificial intelligence, machine learning, or automated decision-making in connection with the processing of Personal Data without the explicit prior written consent of the Controller. This includes generative AI tools, large language models, and any automated profiling systems.

4.2 Transparency

Where AI processing is authorized, the Processor must provide the Controller with detailed information about the AI systems used, including the type of technology, the purpose of its use, the categories of data processed, the logic involved, and the potential consequences for data subjects.

4.3 Compliance and Accountability

The Processor must ensure that any authorized AI processing complies with all applicable AI-specific regulations, does not result in discrimination or bias, and maintains full accountability and auditability of AI-driven decisions affecting data subjects.

4.4 Data Minimization

AI processing must adhere to strict data minimization principles. The Processor must apply anonymization or pseudonymization wherever possible and ensure that only the minimum amount of Personal Data necessary is used for the authorized AI purpose.

4.5 No Retention for Own Purposes

The Processor must not retain any Personal Data processed through AI systems for its own purposes or for the benefit of third parties. All outputs, models, and derived data remain the property of the Controller unless otherwise agreed in writing.

4.6 AI Incident Notification

The Processor must promptly notify the Controller of any AI-related incidents, including but not limited to algorithmic bias events, unauthorized data use by AI systems, model failures affecting Personal Data integrity, and any regulatory inquiries concerning AI processing.

5.1 Notification Timeline

The Processor must notify the Controller of any Data Breach without undue delay and in any event within 48 hours of becoming aware of the breach. Notification must be made regardless of the perceived severity of the breach.

5.2 Notification Content

The breach notification must include: (a) the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its effects; and (d) the name and contact details of the Processor's designated point of contact.

5.3 Assistance with Notifications

The Processor must assist the Controller with any notifications required to supervisory authorities or data subjects under applicable law, providing all information and cooperation necessary for the Controller to meet its notification obligations.

6.1 Legal Basis and Consent

The Controller warrants that it has obtained all necessary rights, consents, and legal bases for the processing of Personal Data as contemplated under the DPA and the Main Agreement.

6.2 Instructions and Information

The Controller shall provide the Processor with all information and instructions necessary for the Processor to fulfill its obligations under the DPA, including clear documentation of processing purposes and scope.

6.3 Controller Compliance

The Controller shall comply with all obligations applicable to it as a data controller under Applicable Data Protection Laws, including maintaining records of processing activities and conducting required impact assessments.

7.1 Data Return

Upon termination or expiration of the Main Agreement, or upon the Controller's request, the Processor shall return all Personal Data to the Controller in a commonly used, machine-readable format, unless applicable law requires continued storage.

7.2 Secure Deletion

Where return is not requested or practicable, the Processor shall securely delete or destroy all Personal Data and all existing copies, using methods that prevent reconstruction or recovery. The Processor must provide written certification of deletion upon request.

8.1 Liability

Each Party shall be liable for damages caused by its breach of the DPA. The Processor shall be liable for damage caused by processing that does not comply with the Controller's lawful instructions or the obligations of the DPA.

8.2 Indemnification

The Processor shall indemnify and hold harmless the Controller against all claims, losses, damages, fines, and expenses arising from or in connection with the Processor's breach of the DPA or any Applicable Data Protection Laws.

The DPA shall be governed by the law specified in the Main Agreement. Any disputes arising under or in connection with the DPA shall be resolved in accordance with the dispute resolution mechanism set forth in the Main Agreement.

The DPA may only be amended by written agreement signed by both Parties. If any provision is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. This DPA supersedes all prior agreements and understandings between the Parties relating to the subject matter hereof.

Schedule A provides the comprehensive operational details of the processing activities covered by the DPA.

Applicable Data Protection Laws (27 Jurisdictions):

The DPA covers processing subject to the following laws: GDPR (EU), UK GDPR, CCPA/CPRA (California), US State Privacy Laws, DPDP Act (India), LGPD (Brazil), PIPL (China), UAE PDPL, DIFC DPL, PDPA (Singapore), Philippine DPA, Privacy Act/APPs (Australia), NZ Privacy Act (New Zealand), Saudi PDPL, Oman PDPL, POPIA (South Africa), APPI (Japan), Malaysia PDPA, Thailand PDPA, PIPA (South Korea), PIPEDA (Canada), Argentina PDPL, Puerto Rico Privacy Laws, Peru PDPL, Chile DPL, Costa Rica DPL, and Mauritius DPA.

Categories of Personal Data (11 Types):

Identity Data; Contact Data; Professional/Employment Data; Financial/Payroll Data; IT/Technical Data; Communications Data; Usage/Behavioral Data; Location Data; Recruitment/Candidate Data; Benefits/Dependents Data; and Sensitive Personal Data.

Categories of Data Subjects (8 Types):

Employees/Workers; Job Applicants; Clients/Customers; Business Contacts; End Users; Website Visitors; Dependents/Beneficiaries; and Trainees/Learners.

Schedule B details 12 categories of security controls that the Processor must implement and maintain:

# Category Key Measures
1 Organizational Security Information Security Management System (ISMS), security awareness training, personnel background checks
2 Physical Security Physical access controls, CCTV surveillance, data center environmental protections
3 Access Control & Authentication Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), password policies, least privilege
4 Network & Infrastructure Security Firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), patch management, endpoint protection
5 Encryption & Pseudonymization AES-256 encryption at rest, TLS 1.2+ in transit, key management procedures
6 Data Classification & Handling Data classification framework, sensitivity-based handling procedures, labeling
7 Application Security Secure SDLC, vulnerability assessments, regular penetration testing
8 Incident Detection & Response Incident response plan, SIEM monitoring, annual tabletop exercises
9 Business Continuity & Disaster Recovery BC/DR plans, defined RTO/RPO targets, regular testing
10 Vendor/Subprocessor Security Due diligence assessments, contractual security requirements, ongoing monitoring
11 Data Retention & Secure Disposal Defined retention limits, cryptographic erasure, certification of destruction
12 Audit & Assurance ISO 27001 certification, SOC 2 Type II reports, regular internal audits

Schedule C contains the register of approved subprocessors. For each subprocessor, the register records: the subprocessor's name, location of processing, purpose of engagement, and date added to the register. The Processor must update this register and obtain Controller consent before engaging any new subprocessor.

Schedule D provides the framework for international data transfers across 23 jurisdictions. For each jurisdiction, it specifies the applicable transfer mechanism (e.g., EU SCCs, UK International Data Transfer Agreement, PIPL-specific mechanisms), the relevant issuing authority, and template clauses to be incorporated into transfer agreements. The schedule ensures that all cross-border transfers are supported by appropriate legal safeguards.

Schedule E provides a structured template for conducting Transfer Impact Assessments (TIAs) prior to international data transfers. The template contains five sections:

Section 1: Exporter/Importer Details

Identification of the data exporter and importer, including contact information and roles.

Section 2: Description of Transfer

Details of the data transferred, categories of data subjects, purpose, and frequency.

Section 3: Transfer Mechanism Verification

Confirmation of the legal mechanism relied upon and its validity.

Section 4: Assessment of Third Country Laws

Analysis of the legal framework in the recipient country, including government access powers and data protection safeguards.

Section 5: Supplementary Measures

Identification of any additional technical, organizational, or contractual measures required to ensure adequate protection.

Schedule F contains jurisdiction-specific supplementary obligations for 20 jurisdictions. Each Local Processing Agreement maps specific requirements of the relevant local data protection law to the Processor's obligations. The covered jurisdictions are:

EU/EEA & UK; United States; India; Brazil; China; UAE & DIFC; Singapore; Philippines; Australia; New Zealand; Saudi Arabia; Oman; South Africa; Japan; Malaysia; Thailand; South Korea; Canada; Argentina; Puerto Rico, Peru, Chile, Costa Rica, and Mauritius.

Each Local Processing Agreement addresses jurisdiction-specific requirements such as mandatory data localization, local representative appointments, specific consent requirements, sector-specific regulations, and local authority notification obligations.

Annexure 1 addresses the specific data protection requirements applicable to staffing agencies engaged as subcontractors. It contains seven parts:

Part I: Definitions and Role Allocation

Defines the specific roles and responsibilities in the staffing context, establishing two processing scenarios: Scenario A (Internal Processing) where the staffing agency processes data for Infosys's internal purposes, and Scenario B (Client Processing) where processing relates to client-facing services.

Part II: General Obligations

Sets out baseline obligations applicable in both scenarios, including: processing only per documented instructions, confidentiality requirements, access controls, security measures, breach notification obligations, data subject rights assistance, DPIA support, prohibition on unauthorized use, onboarding/offboarding procedures, and sub-staffing restrictions.

Part III: Additional Obligations for Scenario A (Internal Processing)

Specifies enhanced requirements when the staffing agency processes Personal Data for Infosys's internal workforce management, HR administration, and operational purposes.

Part IV: Additional Obligations for Scenario B (Client Processing)

Establishes heightened requirements for client-facing processing, including: flow-down of client-specific data protection obligations, client audit rights, strict data segregation between engagements, compliance with client-specific security requirements, and an accelerated 24-hour breach notification timeline for incidents affecting client data.

Part V: Cross-Border Transfers

Applies the DPA's international transfer framework to staffing agency engagements, ensuring that transfers of staffing-related Personal Data comply with the mechanisms set out in Schedule D.

Part VI: Audit, Compliance, and Indemnification

Grants Infosys the right to audit the staffing agency's compliance, establishes reporting requirements, and sets out indemnification obligations for breaches by the staffing agency.

Part VII: Sub-Staffing Agency Register

Requires the staffing agency to maintain a register of any sub-staffing agencies engaged, subject to the same prior consent and equivalent obligation requirements as subprocessors under the main DPA.

The table below maps each summary section in Layer 2 to the corresponding clause or schedule in the full DPA. The full legal text is available upon request or at the designated document repository.

Layer 2 Summary Section Full DPA Reference Notes
Section 1: Definitions Section 1, pp. 1-2 11 defined terms establishing interpretive framework
Section 2: Scope and Purpose Section 2 Processing scope linked to Main Agreement
Section 3.1: General Compliance Section 3.1 Overarching compliance obligation
Section 3.2: Confidentiality Section 3.2 Personnel confidentiality requirements
Section 3.3: Security Measures Section 3.3; Schedule B 12 categories of TOMs
Section 3.4: Subprocessing Section 3.4; Schedule C Consent and subprocessor register
Section 3.5: Data Subject Rights Section 3.5 Assistance with DSARs
Section 3.6: DPIAs Section 3.6 Impact assessment support
Section 3.7: Audits Section 3.7 Audit and inspection rights
Section 3.8: International Transfers Section 3.8; Schedules D-E Transfer mechanisms for 23 jurisdictions
Section 3.9: Jurisdiction-Specific Section 3.9; Schedule F Local Processing Agreements
Section 4: AI Clauses Section 4 (4.1-4.6) AI governance and restrictions
Section 5: Data Breaches Section 5 (5.1-5.3) 48-hour notification framework
Section 6: Controller Obligations Section 6 (6.1-6.3) Controller warranties and compliance
Section 7: Termination/Data Return Section 7 (7.1-7.2) Return or deletion upon termination
Section 8: Liability/Indemnification Section 8 (8.1-8.2) Liability allocation and indemnity
Section 9: Governing Law Section 9 Per Main Agreement
Section 10: Miscellaneous Section 10 Amendments, severability, supersession
Schedule A: Processing Details Schedule A 27 laws, 11 data categories, 8 subject categories
Schedule B: Security Measures Schedule B 12 TOM categories with specific controls
Schedule C: Subprocessors Schedule C Subprocessor register template
Schedule D: Transfer Clauses Schedule D 23-jurisdiction transfer mechanisms
Schedule E: TIA Template Schedule E 5-section Transfer Impact Assessment
Schedule F: Local Agreements Schedule F 20-jurisdiction specific obligations
Annexure 1: Staffing Agencies Annexure 1 (Parts I-VII) 7-part staffing sub-processing framework