DPDP compliance for SaaS: what lands on you, and through which door.
The DPDP Act talks to Data Fiduciaries. A SaaS company hears it twice: directly for its own users, and through every Indian customer's contract. Here is what each route asks, by when, and what to build first.
Last updated Published by TryTrustableNot legal advice
A B2B SaaS company is usually a Data Processor under India's DPDP Act for its customers' data, and a Data Fiduciary for its own: sign-ups, marketing, website visitors and, for consumer products, its users. The Act puts its duties on the Fiduciary, so a processor's obligations arrive through the contract every customer must sign under section 8(2): security safeguards, breach support, erasure and stopping on withdrawal. The substantive duties apply from 13 May 2027; CERT-In's six-hour reporting already applies to you directly.
What applies, and when
The Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025 commence in stages counted from the Rules' publication on 13 November 2025 (PIB). Two dates matter to a SaaS company, and one older regime already applies. The DPDP guide covers every obligation; the regulatory tracker keeps the dates current.
| Date | What applies | SaaS impact |
|---|---|---|
| Since 2022 | CERT-In Directions | Six-hour incident reporting, 180 days of ICT logs in Indian jurisdiction, clock sync and a point of contact. Applies to you directly as a body corporate |
| 13 Nov 2026 | Rule 4: Consent Manager registration | Consumer products may receive consent given or withdrawn through a registered Consent Manager. You do not need to become one |
| 13 May 2027 | Rules 3 and 5 to 16, and the rest of the Act | Notice, security safeguards, breach intimation, retention and erasure, children's data, rights, and the Board's power to penalise |
Dates from Rule 1 of the DPDP Rules 2025, consistent with the DPDP regulatory tracker. Checked October 2026.
Processor or fiduciary: two routes in
As a Data Processor for business customers, the Act does not list your duties; it makes the customer, as Data Fiduciary, responsible for what you do. Section 8(2) requires a valid contract, Rule 6(1)(f) requires that contract to include reasonable security safeguards, section 6(6) requires processing to stop when consent is withdrawn, and section 8(7)(b) requires the Fiduciary to make its processors erase data. All of that reaches you as contract terms. The DPDP data processing agreement template shows what a customer is likely to send.
As a Data Fiduciary for your own website, leads, sign-ups and, in a consumer product, your users, every duty applies to you directly: notice in English or an Eighth Schedule language, consent you can prove, rights, grievance handling within a published period of no more than 90 days, breach intimation, retention, and verifiable parental consent for anyone under 18.
Foreign customers' data processed in India under a contract with a person outside India is mostly outside the Act under section 17(1)(d); the security safeguards still apply. That is why an Indian SaaS company selling mainly abroad often finds the GDPR, through contracts, governs most of its customer data, as the GDPR for SaaS page explains.
What Indian customers and the Board will look for
| Requirement | Source | What a customer asks its SaaS vendor for |
|---|---|---|
| Security safeguards | s.8(5), Rule 6(1)(a) to (d) | Encryption or masking, access control, monitoring of access, backups that let processing continue |
| Logs for detection | Rule 6(1)(e), Rule 8(3) | Personal data, traffic data and processing logs kept at least one year |
| Breach support | s.8(6), Rule 7 | Notice fast enough for the customer to tell each person and the Board without delay and file the detailed report within 72 hours |
| Erasure | s.8(7)(b) | Deletion on the customer's instruction, including backups and sub-processors |
| Withdrawal | s.6(6) | Stopping processing for a person when the customer passes on a withdrawal |
| Sub-processors | s.8(2) | Who else processes the data, under what contract |
| Cross-border transfer | s.16, Rule 15 | Where data goes. No country has been restricted under s.16 so far |
Section and rule numbers from the Act and the Rules as notified. Customers may ask for more than this.
The Board's penalties fall on the Fiduciary, up to ₹250 crore per instance for failed security safeguards and ₹200 crore for failed breach notification (the DPDP penalties page has the full Schedule). That exposure is why customers will write indemnities and audit rights into their DPAs.
The gaps we see most often in SaaS companies
- Application and access logs kept for 30 or 90 days, short of the one-year floor customers will pass down
- Logs held only outside India, when CERT-In expects 180 days in Indian jurisdiction
- No route for a customer to tell you a person withdrew consent, so processing carries on
- Deletion that stops at the primary database
- Breach process tuned to GDPR's 72 hours, with nothing that meets CERT-In's six
- For B2C products: consent stored as a boolean, notice only in English, and no idea which users are under 18
- Treating the product's GDPR DPA as DPDP-ready; the Act has no legitimate-interests basis and its own breach rules
A realistic timeline
Count back from 13 May 2027. Indian enterprise customers will start sending DPDP schedules to vendors well before that, and the system changes take longest: one-year log retention, erasure that reaches backups and sub-processors, withdrawal handling, and for consumer products, consent records and parental consent. A sensible plan finishes mapping and contracts first, then spends the remaining months on engineering, with a breach drill that runs both the CERT-In six hours and the DPDP 72 hours before the date.
What drives the cost
No official cost exists. The drivers are whether you are a Fiduciary for consumer data (much more work than a pure B2B processor), log storage for a year, engineering for erasure and withdrawal, consent tooling, and legal review of customer DPAs. Becoming a Significant Data Fiduciary, by government notification, adds a DPO in India, an independent data auditor and annual DPIAs; few SaaS companies will be notified.
DPDP checklist for a SaaS company
| # | Task | Done when |
|---|---|---|
| 1 | Record, per processing activity, whether you are Fiduciary or Processor | Role and reasoning written down |
| 2 | Identify data covered by the s.17(1)(d) exemption | Foreign customers' data mapped separately |
| 3 | Prepare a DPDP schedule for customer contracts | Covers Rule 6 safeguards, erasure, withdrawal, breach support |
| 4 | Keep processing logs for at least one year | Retention set and tested |
| 5 | Keep 180 days of ICT logs in Indian jurisdiction | A copy in an Indian region |
| 6 | Sync clocks and name a CERT-In point of contact | NTP source documented; contact filed |
| 7 | Rehearse breach reporting: CERT-In six hours, customer notice, DPDP 72 hours | Drill report on file |
| 8 | Build erasure that reaches backups and sub-processors | Deletion evidence per request |
| 9 | Accept withdrawal signals from customers | Processing stops for that person |
| 10 | For your own users: notice, provable consent, rights, a grievance period of 90 days or less | Published and working |
| 11 | For consumer products: find under-18 users and plan verifiable parental consent | Approach chosen under Rule 10 |
The full 52-item list is the DPDP compliance checklist.
How TryTrustable helps, and what it does not do
- DPDP mapped to shared controls. DPDP requirements sit on the same control set as SOC 2, ISO 27001 and the GDPR in the compliance programme
- Consent with proof. The consent manager records each decision with the notice version and language shown; the cookie scanner shows what fires before consent
- Security evidence. SDK and CI checks and GitHub, AWS, Google Cloud, Okta and Google Workspace checks evidence the safeguards you promise customers
- Hosted in India. Customer data is hosted in Mumbai
TryTrustable is a consent management platform, not a registered Consent Manager under the Act. It does not store your logs or report to CERT-In or the Board for you. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.
Sources
- MeitY: Digital Personal Data Protection Act, 2023 (Gazette text)
- MeitY: Digital Personal Data Protection Rules, 2025
- PIB: DPDP Rules notified, 14 November 2025
- CERT-In: Directions under section 70B(6), 28 April 2022
- CERT-In: FAQs on the Directions, May 2022
Checked against these sources in October 2026. Laws, standards and dates change: check the source before you rely on a figure. Not legal, audit or certification advice.
Related audience guides: SOC 2 for AI start-ups · ISO 42001 for AI start-ups · EU AI Act for SaaS · GDPR for SaaS · SOC 2 from India
The things people ask us
Is a SaaS company a Data Fiduciary or a Data Processor under the DPDP Act?
Usually both, for different data. For data your business customers put into the product, you process on their behalf under contract, which makes you a Data Processor. For your own sign-ups, marketing and website, and for consumer users of a B2C product, you decide purpose and means, which makes you a Data Fiduciary.
Does the DPDP Act apply directly to Data Processors?
Mostly through contract. The Act places its duties and penalties on the Data Fiduciary, which stays responsible for processing done on its behalf and must engage processors only under a valid contract (section 8(2)). Rule 6 requires that contract to include reasonable security safeguards. Expect Indian customers to flow those duties down to you in a DPA.
When do DPDP obligations apply to SaaS companies?
The substantive duties, including notice, security safeguards, breach intimation, retention and rights, commence on 13 May 2027 under Rule 1 of the DPDP Rules 2025. Consent Manager registration under Rule 4 opens on 13 November 2026. CERT-In's Directions of April 2022, including six-hour incident reporting, already apply.
Does DPDP apply to foreign customers' data we process in India?
Mostly not. Section 17(1)(d) disapplies most of the Act where a company in India processes personal data of people outside India under a contract with a person outside India. Section 8(1) and the security safeguards in section 8(5) still apply, and the foreign customer's own law, such as the GDPR, governs the rest.
How long must a SaaS company keep logs under DPDP?
Rule 6(1)(e) and Rule 8(3) require a Data Fiduciary to keep personal data, traffic data and processing logs for at least one year, from 13 May 2027. Customers will pass that to their processors. CERT-In separately requires 180 days of ICT logs kept within Indian jurisdiction.
Be ready for the DPDP schedule in your next contract.
We show DPDP requirements mapped to the controls you already run, and a consent decision recorded with the notice version and language. Thirty minutes.