Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
SaaS & Technology

DPDP Act Compliance for SaaS & Technology Companies

SaaS companies wear two hats under the Act; getting the roles, contracts and sub-processors right is the whole game.

In short

SaaS companies wear two hats: a Data Fiduciary for your own users, and a Data Processor for customer data. You need clear consent and rights for your users, and airtight contracts, security and sub-processor control for customer data. Penalties reach ₹250 crore.

What DPDP Act compliance asks of you

The obligations that shape compliance in this sector.

Fiduciary vs Processor

Know which role you play for which data; the duties are different for each.

Data processing agreements

Put valid processing contracts in place with customers and every sub-processor.

Security safeguards

Reasonable security is a legal duty; access control, encryption and logging are table stakes.

User rights and consent

For your own users, handle consent, access, correction and erasure directly.

Sub-processor transparency

Disclose and control the vendors that process data on your behalf.

Breach reporting

Notify affected customers and the Board when a breach touches personal data.

See where you stand.

Run the free readiness check for a sector-specific gap report.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

Take the readiness check →