Readiness assessment
SaaS & Technology

The DPDP Act for SaaS & Technology

SaaS companies wear two hats under the Act; getting the roles, contracts and sub-processors right is the whole game.

In short

SaaS companies wear two hats: a Data Fiduciary for your own users, and a Data Processor for customer data. You need clear consent and rights for your users, and airtight contracts, security and sub-processor control for customer data. Penalties reach ₹250 crore.

What the Act asks of you

The obligations that shape compliance in this sector.

Fiduciary vs Processor

Know which role you play for which data; the duties are different for each.

Data processing agreements

Put valid processing contracts in place with customers and every sub-processor.

Security safeguards

Reasonable security is a legal duty; access control, encryption and logging are table stakes.

User rights and consent

For your own users, handle consent, access, correction and erasure directly.

Sub-processor transparency

Disclose and control the vendors that process data on your behalf.

Breach reporting

Notify affected customers and the Board when a breach touches personal data.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Take the readiness check