subcontracting clause
Subcontracting Clauses in Indian Contracts: Delegation and Flow-Down
A subcontracting clause decides whether a party can bring in a third party to actually do the work it promised, and what happens to its promises once someone outside the contract is doing that work. Most readers assume the clause exists only to stop the other side quietly farming the job out to a cheaper outsider. That is half the problem. The bigger risk is what does not travel automatically to the subcontractor: your confidentiality terms, your data protection duties, and your liability protections stay with the original party unless the clause makes them "flow down" in writing.
This guide is written by Adira, which builds contract review and CLM software, so we have a stake in you reading subcontracting clauses carefully. That said, the analysis below stands on its own. If you want to mark up one subcontracting clause by hand today, Weave (Adira's free browser tool) lets you do that without an account.
Plain meaning: what a subcontracting clause actually does
Subcontracting means the party who owes an obligation under a contract, call it the prime, brings in a separate legal entity, the subcontractor, to help perform some or all of that obligation. The subcontractor has no contract with the other side, the customer or employer. Its contract is with the prime alone. This is the single fact that most people forget: subcontracting does not put the subcontractor in the customer's shoes, and it does not take the prime out of them.
That makes subcontracting different from assignment, where a party hands off its position in the contract itself. Subcontracting is narrower and, in practice, more common: a services company staffs a project with a freelancer, a manufacturer uses a third-party fabricator, a SaaS vendor hosts on someone else's cloud. In each case the prime stays the only party the customer can hold to the deal.
Who it protects, and the moment it bites
A subcontracting clause protects the party that picked its counterparty for a reason beyond price, its team, its security certifications, its reputation, and does not want that judgment undermined by an unknown third party doing the actual work. It bites the moment the prime wants to bring anyone else into performance, and again the moment something goes wrong and the customer has to work out who is responsible.
It also bites quietly, before anything goes wrong, in due diligence and security reviews. A customer that never asked "who else touches our data" can find out only after a breach that its vendor's vendor, three tiers down, was handling personal data on a laptop with no encryption, and no contract obligating it to do otherwise.
What to look for in the actual text
Five things decide how a subcontracting clause behaves in practice:
- Is subcontracting permitted at all, and on what standard? A flat prohibition, a consent requirement, or silence all mean different things, and silence is not neutral, see below.
- Does the clause say the prime remains fully liable for the subcontractor's acts and omissions as if they were its own? Without this sentence, "was that our fault or the subcontractor's" becomes a live argument instead of a closed question.
- Does it require flow-down of specific obligations? Confidentiality, IP ownership, data protection, security standards, and insurance should be named individually, not left to a vague "the subcontractor shall comply with this Agreement."
- Are the sub-agreement's terms "back-to-back" with the main contract? Back-to-back drafting means the subcontract mirrors the prime contract's scope, standards, and timelines, not just its headline obligations, so nothing the prime promised upstream is quietly weaker downstream.
- Is payment to the subcontractor tied to payment the prime receives from the customer? A "pay when paid" clause in the sub-agreement, rarely visible in the prime contract, shifts payment risk downward and can starve the team actually doing the work.
- Is there an approved-subcontractor list, or a right to object to one? This is the practical control point customers actually use, more than the abstract consent standard.
The Indian position: delegation is allowed, but the promisor stays on the hook
Indian contract law starts from a permissive default on who may physically carry out a promise. Section 40 of the Indian Contract Act, 1872 governs this, under the heading "Person by whom promise is to be performed":
"If it appears from the nature of the case that it was the intention of the parties to any contract that any promise contained in it should be performed by the promisor himself, such promise must be performed by the promisor. In other cases, the promisor or his representative may employ a competent person to perform it."
Read the section on Indian Kanoon. The two illustrations under the section make the line concrete: a promise to pay money can be performed by anyone the promisor arranges, because paying money needs no particular skill. A promise to paint a picture must be performed personally, because the promisee bargained for that specific person's skill. This is vicarious performance, and it is the statutory root of every subcontracting clause in an Indian-governed contract: unless personal skill, trust, or a specific identity was the point of the deal, the promisor may get someone else to do the work.
What Section 40 does not do is release the promisor from the contract. The promisee's agreement is with the promisor, not with whoever the promisor hires to help. If the substitute performs badly, the claim runs against the promisor, under ordinary privity of contract, exactly as if the promisor had done the work itself. A subcontracting clause silent on liability is not silent by accident, it is stating the default that already applies. A clause that tries to say the prime is not responsible for its subcontractor's failures is attempting to contract out of that default.
Data protection adds a second, independent layer, and it is not optional the way a liability disclaimer can at least be attempted. Section 8(1) of the Digital Personal Data Protection Act, 2023 puts this beyond contractual reach:
"A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor."
And Section 8(2) conditions any such delegation on paperwork existing at all:
"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract."
Read both on Indian Kanoon. Together, these subsections mean a business cannot subcontract its way out of DPDP compliance. If your clause lets the prime bring in a sub-processor without a written contract carrying the same data duties downstream, the prime is exposed to regulatory liability the moment personal data crosses that line, and no disclaimer in the main contract will hold up against the statute.
A named case: Zonal General Manager, IRCON International Ltd v Vinay Heavy Equipments
The clearest Indian authority on what a subcontracting relationship does, and does not, transfer is the Supreme Court's decision in Zonal General Manager, IRCON International Ltd v Vinay Heavy Equipments, Civil Appeal No. 4211 of 2015, decided on 6 May 2015. IRCON, the main contractor on a road construction project for SIPCOT, tried to avoid paying its subcontractor by arguing it had not itself been paid by the employer, effectively an unwritten "pay when paid" defence.
The Court rejected that defence and held that, absent an express clause saying otherwise, the two relationships in a subcontracting chain do not merge:
"In the absence of covenant in the main contract to the contrary, the rules in relation to privity of contract will mean that the jural relationship between the employer and the main contractor on the one hand and between the sub-contractor and the main contractor on the other will be quite distinct and separate."
You can read the judgment on Indian Kanoon. The holding cuts both ways. For a subcontractor, it confirms the prime cannot point to an unpaid invoice from the employer as a reason to withhold what it owes downstream, unless the sub-agreement explicitly makes payment conditional on that upstream event. For a customer reviewing its vendor's subcontracting clause, it confirms the flip side: the customer's contract creates no relationship, and no right, against the vendor's subcontractor. If the subcontractor causes harm, the claim runs against the prime, unless the main contract creates a direct right some other way.
Red flags table
| Normal | Red flag | Why it matters |
|---|---|---|
| Subcontracting requires the customer's prior consent, or is limited to a named, approved list | Prime may subcontract freely, to anyone, without notice | Your data and your project can end up with an unknown third party you never vetted |
| Prime remains fully liable for the subcontractor's acts and omissions as if its own | Clause disclaims or limits the prime's liability for the subcontractor's conduct | Attempts to contract around the Section 40 default of continuing liability, and leaves the customer with no one clearly on the hook |
| Confidentiality, IP, and data protection terms are expressly required to flow down to the subcontractor, in writing, at least as strict | Clause only says the subcontractor must "comply with this Agreement," with no named terms | Vague flow-down is hard to enforce and easy for a sub-agreement to quietly water down |
| Prime confirms subcontractor engagements are under a valid written contract carrying equivalent data protection duties | Clause is silent on whether a sub-processor even has a written contract | Section 8(2) DPDP makes a written contract a precondition for engaging a processor at all |
| Subcontractor payment is not conditioned on the prime's own receipt of payment from the customer | Pay-when-paid or pay-if-paid language applies to the subcontractor | As in Ircon, this shifts payment risk down the chain and can starve the team doing the work |
| Customer retains audit or security review rights that expressly extend to material subcontractors, with notice before a new one is added | Audit rights cover only the prime, and there is no notice once initial consent is given | A right you cannot exercise against the party actually handling your data is not a real right |
Bad clause versus better clause
Bad: "The Contractor may engage subcontractors to perform its obligations under this Agreement."
What is wrong: no consent mechanism, no statement that the Contractor remains liable for the subcontractor's work, nothing naming confidentiality or data protection as terms that must flow down, and nothing on payment or termination if a subcontractor is unsuitable.
Better: "The Contractor may engage subcontractors to perform part of its obligations under this Agreement only with the Client's prior written consent, such consent not to be unreasonably withheld, or where the subcontractor is named in Schedule C as pre-approved. The Contractor shall remain fully responsible and liable to the Client for the performance of, and any acts or omissions by, its subcontractors as if such performance, acts, or omissions were the Contractor's own. The Contractor shall ensure that each subcontractor is engaged under a written agreement that imposes confidentiality, intellectual property, data protection, and security obligations on the subcontractor no less protective than those in this Agreement, including obligations equivalent to the Contractor's own obligations as a Data Fiduciary or Data Processor under the Digital Personal Data Protection Act, 2023. Payment to a subcontractor shall not be conditioned on the Contractor's receipt of payment from the Client. The Client may require the Contractor to remove a subcontractor, on reasonable written notice, where the subcontractor is in material breach of the obligations flowed down under this clause."
What changed and why: it sets a real consent standard with a pre-approved list as an alternative, states the continuing-liability default expressly, names the specific terms that must flow down, ties data protection flow-down to the DPDP Act, removes pay-when-paid exposure, and gives the customer a practical removal right.
How this interacts with related clauses
Subcontracting sits next to, and is often confused with, assignment. Assignment transfers the legal right or obligation itself to a new party; subcontracting keeps the original party fully liable while a third party helps perform. A contract can permit one freely while tightly restricting the other, so read both clauses, not just whichever one is headed with the word you searched for.
It also depends on confidentiality and IP assignment language doing real work downstream. A confidentiality clause binding only "the Contractor" does not, by itself, bind a subcontractor who never signed it, which is why the subcontracting clause needs its own flow-down sentence. The same logic applies to IP: if a subcontractor's staff create deliverables, the main contract's IP assignment needs a mirrored obligation in the subcontract, or the customer ends up not owning what it paid for.
Finally, it connects to indemnity and limitation of liability. Since Section 40 leaves the prime liable for a subcontractor's failures by default, the indemnity clause should make clear that a subcontractor's breach is covered the same way a direct breach is, and any liability cap should not be drafted so narrowly that subcontractor-caused losses fall outside it.
US and global contrast
US and UK commercial contracts use "flow-down clause" as a standard, named term of art. US government contracting is the extreme case: federal subcontracts under the Federal Acquisition Regulation must incorporate specific prime-contract clauses by reference, with little room to negotiate. Indian commercial contracts have converged on similar flow-down drafting in practice, but without an equivalent regulatory mandate outside sectors like defence and government procurement, so the discipline depends entirely on what the drafter chooses to write.
The bigger contrast is on payment. "Pay when paid" clauses are common, and often enforceable, in US private construction subcontracts, subject to state-specific limits, several states restrict or void them by statute. Indian courts, as Ircon shows, start from the opposite presumption: without an express clause making payment conditional on the employer paying the main contractor, the obligation to pay the subcontractor is independent and unconditional. A prime relying on an unwritten pay-when-paid understanding in India is relying on something the Supreme Court has already declined to read into a contract.
FAQ
Does a subcontracting clause let the subcontractor sue our customer, or our customer sue the subcontractor, directly? No, not by itself. Under privity of contract, confirmed for subcontracting chains in Zonal General Manager, IRCON International Ltd v Vinay Heavy Equipments, the subcontractor's contract is with the prime, and the customer's contract is with the prime. Neither side gets a direct claim against the other's opposite number unless the main contract expressly creates one.
If our contract is silent on subcontracting, can our vendor bring in a subcontractor without asking us? Probably yes, for work that does not need the vendor's own personal skill, under the Section 40 default. But you would have no visibility into who they chose, and none of your confidentiality or data protection terms would automatically bind that subcontractor. Silence is not the same as a flow-down obligation existing.
Is subcontracting the same as outsourcing to a cloud provider like AWS or Azure? Functionally, yes. If a cloud provider processes your data as part of how the vendor delivers its service, the vendor is subcontracting hosting to that provider. Many vendors do not describe it that way, but the DPDP Act's data-processor obligations do not care what the arrangement is called, only what actually happens to the data.
Can we hold our vendor responsible if their subcontractor causes a data breach? Generally yes, against the vendor, because Section 40 and ordinary privity keep the vendor liable for its subcontractor's performance unless your contract says otherwise. Whether you can also pursue the subcontractor, or a regulator can act against it directly, depends on the DPDP Act's own provisions and whether the vendor's contract with that subcontractor names it as a data processor in its own right.
This guide explains how subcontracting clauses generally work under Indian contract law and the Digital Personal Data Protection Act, and the statutory and case-law basis for the flow-down obligations discussed above. It is not legal advice, and it does not tell you whether your specific clause, or your specific subcontractor arrangement, is enforceable or compliant in your situation. For that, especially before signing a contract that will involve significant subcontracting of data-handling work, talk to a lawyer who can review your actual documents.
Frequently asked questions
- Does a subcontracting clause let the subcontractor sue our customer, or our customer sue the subcontractor, directly?
- No, not by itself. Under privity of contract, confirmed for subcontracting chains in Zonal General Manager, IRCON International Ltd v Vinay Heavy Equipments (Civil Appeal No. 4211 of 2015), the subcontractor's contract is with the prime, and the customer's contract is with the prime. Neither side gets a direct claim against the other's opposite number unless the main contract expressly creates one, for example through a direct warranty or a collateral agreement.
- If our contract is silent on subcontracting, can our vendor bring in a subcontractor without asking us?
- Probably yes, for work that does not need the vendor's own personal skill, under the Section 40 default in the Indian Contract Act, 1872. But you would have no visibility into who they chose, and none of your confidentiality or data protection terms would automatically bind that subcontractor. Silence is not the same as a flow-down obligation existing.
- Is subcontracting the same as outsourcing to a cloud provider like AWS or Azure?
- Functionally, yes. If a cloud provider processes your data as part of how the vendor delivers its service, the vendor is subcontracting hosting or infrastructure to that provider. Many vendors do not describe it that way, but the DPDP Act's data-processor obligations do not care what the arrangement is called, only what actually happens to the personal data.
- Can we hold our vendor responsible if their subcontractor causes a data breach?
- Generally yes, against the vendor, because Section 40 and ordinary privity of contract keep the vendor liable for its subcontractor's performance unless your contract says otherwise. Whether you can also pursue the subcontractor, or a regulator can act against it directly, depends on the DPDP Act's own provisions and on whether the vendor's contract with that subcontractor names it as a data processor in its own right.
Sources
- Section 40, The Indian Contract Act, 1872 (Indian Kanoon)
- Section 8, The Digital Personal Data Protection Act, 2023 (Indian Kanoon)
- Zonal General Manager, IRCON International Ltd v Vinay Heavy Equipments, Civil Appeal No. 4211 of 2015 (Indian Kanoon)
- The Indian Contract Act, 1872 (Full text, India Code)
- The Digital Personal Data Protection Act, 2023 (Full text, India Code)
See how Adira drafts in your voice and reads contracts from your side.
Explore the showroomWorking through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.
Try Weave — free