B2B SaaS wears two hats: a Fiduciary for your own users and leads, a Processor for the customer data inside your product.
In short
For your own users and marketing you are a Data Fiduciary; for the data customers put in your product you are a Data Processor. Get consent and rights right for the first, and contracts, security and sub-processor control right for the second. Penalties reach ₹250 crore.
What changes for this sub-sector.
Separate the data you decide about (users, leads) from the data you only process for customers.
Sign DPDP-ready processing terms with every customer and every sub-processor.
Website tracking, lead capture and outreach are Fiduciary activities that need consent.
Keep a current sub-processor list, disclose it, and flow duties down by contract.
Handle access, correction and erasure for your own users, and support customers in serving their principals.
Notify affected customers and the Board when a breach touches personal data.
Nail your DPAs and role mapping first, then consent for marketing.
The readiness check maps role, DPA, sub-processor and consent gaps.
Take the readiness check →