DPDP obligations for Data Processors: a guide for SaaS vendors
- A Data Processor processes personal data on behalf of a Data Fiduciary (s.2(k)); the Fiduciary stays responsible for that processing (s.8(1)).
- Most duties reach processors through the contract the Fiduciary must have (s.8(2)), including security terms (Rule 6(1)(f)).
- Customers will expect you to stop processing on withdrawal (s.6(6)), erase on instruction (s.8(7)(b)) and keep logs for at least one year (Rule 8(3)).
- Indian vendors processing data of people outside India under a contract with a foreign person are largely exempt, except s.8(1) and 8(5) (s.17(1)(d)).
If you sell software or services that handle your customers' user data, you are probably a Data Processor for that data. The DPDP Act, 2023 puts most obligations on the Data Fiduciary, but those obligations flow down to you through contracts, security questionnaires and deletion requests. This guide explains what customers will ask for and where each ask comes from.
Are you a processor, a fiduciary, or both?
A Data Fiduciary alone or with others determines the purpose and means of processing (s.2(i)). A Data Processor processes personal data on behalf of a Data Fiduciary (s.2(k)). Most SaaS companies are both:
- Processor for customer content and end-user records processed to deliver the service.
- Fiduciary for their own marketing leads, website visitors, billing contacts and employees, where they decide the purpose.
Write this split down per data category. Our fiduciary vs processor guide covers the distinction, and DPDP for SaaS covers the wider product playbook.
The valid contract
A Data Fiduciary may engage a Data Processor for any activity related to offering goods or services to Data Principals “only under a valid contract” (s.8(2)). Rule 6(1)(f) adds that the contract should make appropriate provision for reasonable security safeguards. The Act does not prescribe a standard processor contract, so expect each customer's paper to differ. Prepare your own DPA that maps to the points below.
What customers will need from you
| Customer (Fiduciary) obligation | Source | What you need to support it |
|---|---|---|
| Reasonable security safeguards, including for processing by its processors | s.8(5), Rule 6(1) | Encryption or masking, access control, logging and monitoring, backups (Rule 6(1)(a) to (d)) |
| Retain logs and personal data for one year for detection and investigation | Rule 6(1)(e) | Log retention of at least one year, configurable where other law requires longer |
| Ensure processors also keep data and logs for at least one year before erasure | Rule 8(3), Illustration Case 2 | Retention that survives customer-side deletion for that period, then erasure |
| Make processors stop processing after consent is withdrawn | s.6(6) | An API or admin action to stop processing a named user's data |
| Make processors erase data provided to them | s.8(7)(b) | Deletion across primary stores, replicas and backups, with confirmation |
| Tell Data Principals which processors received their data | s.11(1)(b) | A current subprocessor list |
| Notify the Board and affected people of a breach | s.8(6), Rule 7 | Fast incident notice to the customer with the facts Rule 7(2)(b) asks for |
| Keep data accurate when used for decisions or shared | s.8(3) | Correction and update functions |
The Act and Rules do not set a deadline for a processor to tell the Fiduciary about a breach. But the Fiduciary owes the Board a detailed report within seventy-two hours of becoming aware (Rule 7(2)(b)), so customers will negotiate a shorter internal window. See the incident response playbook.
Subprocessors and transparency
Because a Data Principal can ask a Fiduciary for the identities of all Data Processors it shared her data with (s.11(1)(b)), customers need an accurate list from you, including your own vendors that touch their data. A public page makes this easy; see how to write a subprocessor list page.
Hosting outside India
Transfers are allowed unless the Central Government restricts a country by notification (s.16(1)), subject to requirements it may specify for making data available to a foreign State or entities it controls (Rule 15). Sector laws with stricter transfer rules still apply (s.16(2)). Customers that are Significant Data Fiduciaries may need certain data kept in India (Rule 13(4)). See cross-border data transfer.
Indian vendors serving foreign clients: s.17(1)(d)
Where personal data of Data Principals outside India is processed under a contract between a person based in India and a person outside India, Chapter II (except s.8(1) and 8(5)), Chapter III and section 16 do not apply (s.17(1)(d)). For Indian outsourcing and SaaS firms serving foreign clients, that removes most of the Act for that data. Security safeguards under s.8(5) remain. Data of people in India is not covered by this exemption.
Processor readiness checklist
- Map each data category to your role: processor or fiduciary.
- Publish a DPA covering security, stop-processing, erasure, breach notice and subprocessors.
- Confirm log retention of at least one year (Rule 6(1)(e), Rule 8(3)).
- Test deletion end to end, including backups.
- Keep your subprocessor list current.
- Prepare answers for security questionnaires.
For customers' side of this process, see the vendor and processor checklist. Most obligations above take effect eighteen months from 13 November 2025 (commencement note under s.1(2); Rule 1(4)).
Frequently asked questions
Does the DPDP Act apply directly to Data Processors?
Most obligations in Chapter II are placed on the Data Fiduciary, which stays responsible for processing done on its behalf by a Data Processor (s.8(1)). Processors mainly take on obligations through the valid contract required by section 8(2).
Is a SaaS company a Data Fiduciary or a Data Processor?
Often both. It is a processor for customer data it processes on the customer's behalf (s.2(k)) and a fiduciary for data whose purpose and means it decides itself, such as its own marketing leads (s.2(i)).
Must a Data Processor keep logs for one year?
Rule 8(3) requires the Data Fiduciary to retain personal data, traffic data and logs of processing done by it or by its processor for at least one year. Illustration Case 2 states the Fiduciary must ensure its cloud processor also retains them for at least one year before erasure.
Does the DPDP Act apply to Indian companies processing foreign customers' data?
Where personal data of people outside India is processed under a contract between a person in India and a person outside India, most of the Act does not apply, but sections 8(1) and 8(5) still do (s.17(1)(d)).
Is there a mandatory DPDP data processing agreement template?
No. Section 8(2) requires a valid contract and Rule 6(1)(f) requires it to provide for reasonable security safeguards, but neither prescribes a standard template.
Practical next step
Build a one-page DPDP support matrix for customers: each Fiduciary obligation, the feature or process that supports it, and the contract clause that covers it. Then run a quick external check of your public trust pages.