← SaaS companies
DPDP Act Compliance for SaaS Companies
SaaS platforms processing Indian personal data are usually Data Processors for their customers and Data Fiduciaries for their own users at the same time. The two roles carry different obligations, and contracts rarely make the split explicit.
What DPDP Act requires of saas companies
- Role determination per data flow — Fiduciary for your own users, Processor for customer data, frequently both.
- Consent architecture with granular purposes and withdrawal as easy as granting, where consent is the lawful basis.
- Records of processing and a data inventory that survives contact with an auditor.
- Data-principal rights workflows — access, correction, erasure and grievance redressal within statutory timelines.
- Breach notification readiness, and Significant Data Fiduciary obligations if thresholds are met.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Data inventory and RoPA maintained, not reconstructed
- Consent logs showing purpose, timestamp and withdrawal handling
- Rights-request register with response times against the statutory clock
- Processor agreements flowing obligations down to sub-processors
- Breach detection and notification runbook, exercised
Where saas companies usually come unstuck
- Assuming GDPR compliance satisfies DPDP — the consent and breach regimes differ materially.
- No mechanism to honour erasure across backups and analytics copies.
- Contracts silent on Fiduciary/Processor roles, leaving liability unallocated.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
