Readiness assessment
SaaS & Technology · B2B SaaS

The DPDP Act for B2B SaaS

B2B SaaS wears two hats: a Fiduciary for your own users and leads, a Processor for the customer data inside your product.

In short

For your own users and marketing you are a Data Fiduciary; for the data customers put in your product you are a Data Processor. Get consent and rights right for the first, and contracts, security and sub-processor control right for the second. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Know your two roles

Separate the data you decide about (users, leads) from the data you only process for customers.

Data processing agreements

Sign DPDP-ready processing terms with every customer and every sub-processor.

Marketing and lead data

Website tracking, lead capture and outreach are Fiduciary activities that need consent.

Sub-processor control

Keep a current sub-processor list, disclose it, and flow duties down by contract.

User and principal rights

Handle access, correction and erasure for your own users, and support customers in serving their principals.

Breach notification

Notify affected customers and the Board when a breach touches personal data.

Check your SaaS data flows.

The readiness check maps role, DPA, sub-processor and consent gaps.

Take the readiness check