DPDP Act · SaaS

DPDP compliance for SaaS: what lands on you, and through which door.

The DPDP Act talks to Data Fiduciaries. A SaaS company hears it twice: directly for its own users, and through every Indian customer's contract. Here is what each route asks, by when, and what to build first.

Last updated Published by TryTrustableNot legal advice

Short answer

A B2B SaaS company is usually a Data Processor under India's DPDP Act for its customers' data, and a Data Fiduciary for its own: sign-ups, marketing, website visitors and, for consumer products, its users. The Act puts its duties on the Fiduciary, so a processor's obligations arrive through the contract every customer must sign under section 8(2): security safeguards, breach support, erasure and stopping on withdrawal. The substantive duties apply from 13 May 2027; CERT-In's six-hour reporting already applies to you directly.

01

What applies, and when

The Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025 commence in stages counted from the Rules' publication on 13 November 2025 (PIB). Two dates matter to a SaaS company, and one older regime already applies. The DPDP guide covers every obligation; the regulatory tracker keeps the dates current.

DateWhat appliesSaaS impact
Since 2022CERT-In DirectionsSix-hour incident reporting, 180 days of ICT logs in Indian jurisdiction, clock sync and a point of contact. Applies to you directly as a body corporate
13 Nov 2026Rule 4: Consent Manager registrationConsumer products may receive consent given or withdrawn through a registered Consent Manager. You do not need to become one
13 May 2027Rules 3 and 5 to 16, and the rest of the ActNotice, security safeguards, breach intimation, retention and erasure, children's data, rights, and the Board's power to penalise

Dates from Rule 1 of the DPDP Rules 2025, consistent with the DPDP regulatory tracker. Checked October 2026.

02

Processor or fiduciary: two routes in

As a Data Processor for business customers, the Act does not list your duties; it makes the customer, as Data Fiduciary, responsible for what you do. Section 8(2) requires a valid contract, Rule 6(1)(f) requires that contract to include reasonable security safeguards, section 6(6) requires processing to stop when consent is withdrawn, and section 8(7)(b) requires the Fiduciary to make its processors erase data. All of that reaches you as contract terms. The DPDP data processing agreement template shows what a customer is likely to send.

As a Data Fiduciary for your own website, leads, sign-ups and, in a consumer product, your users, every duty applies to you directly: notice in English or an Eighth Schedule language, consent you can prove, rights, grievance handling within a published period of no more than 90 days, breach intimation, retention, and verifiable parental consent for anyone under 18.

Foreign customers' data processed in India under a contract with a person outside India is mostly outside the Act under section 17(1)(d); the security safeguards still apply. That is why an Indian SaaS company selling mainly abroad often finds the GDPR, through contracts, governs most of its customer data, as the GDPR for SaaS page explains.

03

What Indian customers and the Board will look for

RequirementSourceWhat a customer asks its SaaS vendor for
Security safeguardss.8(5), Rule 6(1)(a) to (d)Encryption or masking, access control, monitoring of access, backups that let processing continue
Logs for detectionRule 6(1)(e), Rule 8(3)Personal data, traffic data and processing logs kept at least one year
Breach supports.8(6), Rule 7Notice fast enough for the customer to tell each person and the Board without delay and file the detailed report within 72 hours
Erasures.8(7)(b)Deletion on the customer's instruction, including backups and sub-processors
Withdrawals.6(6)Stopping processing for a person when the customer passes on a withdrawal
Sub-processorss.8(2)Who else processes the data, under what contract
Cross-border transfers.16, Rule 15Where data goes. No country has been restricted under s.16 so far

Section and rule numbers from the Act and the Rules as notified. Customers may ask for more than this.

The Board's penalties fall on the Fiduciary, up to ₹250 crore per instance for failed security safeguards and ₹200 crore for failed breach notification (the DPDP penalties page has the full Schedule). That exposure is why customers will write indemnities and audit rights into their DPAs.

04

The gaps we see most often in SaaS companies

  • Application and access logs kept for 30 or 90 days, short of the one-year floor customers will pass down
  • Logs held only outside India, when CERT-In expects 180 days in Indian jurisdiction
  • No route for a customer to tell you a person withdrew consent, so processing carries on
  • Deletion that stops at the primary database
  • Breach process tuned to GDPR's 72 hours, with nothing that meets CERT-In's six
  • For B2C products: consent stored as a boolean, notice only in English, and no idea which users are under 18
  • Treating the product's GDPR DPA as DPDP-ready; the Act has no legitimate-interests basis and its own breach rules
05

A realistic timeline

Count back from 13 May 2027. Indian enterprise customers will start sending DPDP schedules to vendors well before that, and the system changes take longest: one-year log retention, erasure that reaches backups and sub-processors, withdrawal handling, and for consumer products, consent records and parental consent. A sensible plan finishes mapping and contracts first, then spends the remaining months on engineering, with a breach drill that runs both the CERT-In six hours and the DPDP 72 hours before the date.

06

What drives the cost

No official cost exists. The drivers are whether you are a Fiduciary for consumer data (much more work than a pure B2B processor), log storage for a year, engineering for erasure and withdrawal, consent tooling, and legal review of customer DPAs. Becoming a Significant Data Fiduciary, by government notification, adds a DPO in India, an independent data auditor and annual DPIAs; few SaaS companies will be notified.

07

DPDP checklist for a SaaS company

#TaskDone when
1Record, per processing activity, whether you are Fiduciary or ProcessorRole and reasoning written down
2Identify data covered by the s.17(1)(d) exemptionForeign customers' data mapped separately
3Prepare a DPDP schedule for customer contractsCovers Rule 6 safeguards, erasure, withdrawal, breach support
4Keep processing logs for at least one yearRetention set and tested
5Keep 180 days of ICT logs in Indian jurisdictionA copy in an Indian region
6Sync clocks and name a CERT-In point of contactNTP source documented; contact filed
7Rehearse breach reporting: CERT-In six hours, customer notice, DPDP 72 hoursDrill report on file
8Build erasure that reaches backups and sub-processorsDeletion evidence per request
9Accept withdrawal signals from customersProcessing stops for that person
10For your own users: notice, provable consent, rights, a grievance period of 90 days or lessPublished and working
11For consumer products: find under-18 users and plan verifiable parental consentApproach chosen under Rule 10

The full 52-item list is the DPDP compliance checklist.

08

How TryTrustable helps, and what it does not do

  • DPDP mapped to shared controls. DPDP requirements sit on the same control set as SOC 2, ISO 27001 and the GDPR in the compliance programme
  • Consent with proof. The consent manager records each decision with the notice version and language shown; the cookie scanner shows what fires before consent
  • Security evidence. SDK and CI checks and GitHub, AWS, Google Cloud, Okta and Google Workspace checks evidence the safeguards you promise customers
  • Hosted in India. Customer data is hosted in Mumbai

TryTrustable is a consent management platform, not a registered Consent Manager under the Act. It does not store your logs or report to CERT-In or the Board for you. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.

09

Sources

Questions

The things people ask us

Is a SaaS company a Data Fiduciary or a Data Processor under the DPDP Act?

Usually both, for different data. For data your business customers put into the product, you process on their behalf under contract, which makes you a Data Processor. For your own sign-ups, marketing and website, and for consumer users of a B2C product, you decide purpose and means, which makes you a Data Fiduciary.

Does the DPDP Act apply directly to Data Processors?

Mostly through contract. The Act places its duties and penalties on the Data Fiduciary, which stays responsible for processing done on its behalf and must engage processors only under a valid contract (section 8(2)). Rule 6 requires that contract to include reasonable security safeguards. Expect Indian customers to flow those duties down to you in a DPA.

When do DPDP obligations apply to SaaS companies?

The substantive duties, including notice, security safeguards, breach intimation, retention and rights, commence on 13 May 2027 under Rule 1 of the DPDP Rules 2025. Consent Manager registration under Rule 4 opens on 13 November 2026. CERT-In's Directions of April 2022, including six-hour incident reporting, already apply.

Does DPDP apply to foreign customers' data we process in India?

Mostly not. Section 17(1)(d) disapplies most of the Act where a company in India processes personal data of people outside India under a contract with a person outside India. Section 8(1) and the security safeguards in section 8(5) still apply, and the foreign customer's own law, such as the GDPR, governs the rest.

How long must a SaaS company keep logs under DPDP?

Rule 6(1)(e) and Rule 8(3) require a Data Fiduciary to keep personal data, traffic data and processing logs for at least one year, from 13 May 2027. Customers will pass that to their processors. CERT-In separately requires 180 days of ICT logs kept within Indian jurisdiction.

Book a walkthrough

Be ready for the DPDP schedule in your next contract.

We show DPDP requirements mapped to the controls you already run, and a consent decision recorded with the notice version and language. Thirty minutes.