Industry and team

DPDP obligations for Data Processors: a guide for SaaS vendors

Audience: SaaS founders, vendor security and legal teams, outsourcing providers · Last reviewed: October 2026

If you sell software or services that handle your customers' user data, you are probably a Data Processor for that data. The DPDP Act, 2023 puts most obligations on the Data Fiduciary, but those obligations flow down to you through contracts, security questionnaires and deletion requests. This guide explains what customers will ask for and where each ask comes from.

A Data Fiduciary is responsible for complying with the Act for processing done on its behalf by a Data Processor, “irrespective of any agreement to the contrary” (s.8(1)). That is why customers push detailed terms onto vendors.

Are you a processor, a fiduciary, or both?

A Data Fiduciary alone or with others determines the purpose and means of processing (s.2(i)). A Data Processor processes personal data on behalf of a Data Fiduciary (s.2(k)). Most SaaS companies are both:

  • Processor for customer content and end-user records processed to deliver the service.
  • Fiduciary for their own marketing leads, website visitors, billing contacts and employees, where they decide the purpose.

Write this split down per data category. Our fiduciary vs processor guide covers the distinction, and DPDP for SaaS covers the wider product playbook.

The valid contract

A Data Fiduciary may engage a Data Processor for any activity related to offering goods or services to Data Principals “only under a valid contract” (s.8(2)). Rule 6(1)(f) adds that the contract should make appropriate provision for reasonable security safeguards. The Act does not prescribe a standard processor contract, so expect each customer's paper to differ. Prepare your own DPA that maps to the points below.

What customers will need from you

Customer (Fiduciary) obligationSourceWhat you need to support it
Reasonable security safeguards, including for processing by its processorss.8(5), Rule 6(1)Encryption or masking, access control, logging and monitoring, backups (Rule 6(1)(a) to (d))
Retain logs and personal data for one year for detection and investigationRule 6(1)(e)Log retention of at least one year, configurable where other law requires longer
Ensure processors also keep data and logs for at least one year before erasureRule 8(3), Illustration Case 2Retention that survives customer-side deletion for that period, then erasure
Make processors stop processing after consent is withdrawns.6(6)An API or admin action to stop processing a named user's data
Make processors erase data provided to thems.8(7)(b)Deletion across primary stores, replicas and backups, with confirmation
Tell Data Principals which processors received their datas.11(1)(b)A current subprocessor list
Notify the Board and affected people of a breachs.8(6), Rule 7Fast incident notice to the customer with the facts Rule 7(2)(b) asks for
Keep data accurate when used for decisions or shareds.8(3)Correction and update functions

The Act and Rules do not set a deadline for a processor to tell the Fiduciary about a breach. But the Fiduciary owes the Board a detailed report within seventy-two hours of becoming aware (Rule 7(2)(b)), so customers will negotiate a shorter internal window. See the incident response playbook.

Subprocessors and transparency

Because a Data Principal can ask a Fiduciary for the identities of all Data Processors it shared her data with (s.11(1)(b)), customers need an accurate list from you, including your own vendors that touch their data. A public page makes this easy; see how to write a subprocessor list page.

Hosting outside India

Transfers are allowed unless the Central Government restricts a country by notification (s.16(1)), subject to requirements it may specify for making data available to a foreign State or entities it controls (Rule 15). Sector laws with stricter transfer rules still apply (s.16(2)). Customers that are Significant Data Fiduciaries may need certain data kept in India (Rule 13(4)). See cross-border data transfer.

Indian vendors serving foreign clients: s.17(1)(d)

Where personal data of Data Principals outside India is processed under a contract between a person based in India and a person outside India, Chapter II (except s.8(1) and 8(5)), Chapter III and section 16 do not apply (s.17(1)(d)). For Indian outsourcing and SaaS firms serving foreign clients, that removes most of the Act for that data. Security safeguards under s.8(5) remain. Data of people in India is not covered by this exemption.

Processor readiness checklist

  1. Map each data category to your role: processor or fiduciary.
  2. Publish a DPA covering security, stop-processing, erasure, breach notice and subprocessors.
  3. Confirm log retention of at least one year (Rule 6(1)(e), Rule 8(3)).
  4. Test deletion end to end, including backups.
  5. Keep your subprocessor list current.
  6. Prepare answers for security questionnaires.

For customers' side of this process, see the vendor and processor checklist. Most obligations above take effect eighteen months from 13 November 2025 (commencement note under s.1(2); Rule 1(4)).

Frequently asked questions

Does the DPDP Act apply directly to Data Processors?

Most obligations in Chapter II are placed on the Data Fiduciary, which stays responsible for processing done on its behalf by a Data Processor (s.8(1)). Processors mainly take on obligations through the valid contract required by section 8(2).

Is a SaaS company a Data Fiduciary or a Data Processor?

Often both. It is a processor for customer data it processes on the customer's behalf (s.2(k)) and a fiduciary for data whose purpose and means it decides itself, such as its own marketing leads (s.2(i)).

Must a Data Processor keep logs for one year?

Rule 8(3) requires the Data Fiduciary to retain personal data, traffic data and logs of processing done by it or by its processor for at least one year. Illustration Case 2 states the Fiduciary must ensure its cloud processor also retains them for at least one year before erasure.

Does the DPDP Act apply to Indian companies processing foreign customers' data?

Where personal data of people outside India is processed under a contract between a person in India and a person outside India, most of the Act does not apply, but sections 8(1) and 8(5) still do (s.17(1)(d)).

Is there a mandatory DPDP data processing agreement template?

No. Section 8(2) requires a valid contract and Rule 6(1)(f) requires it to provide for reasonable security safeguards, but neither prescribes a standard template.

Practical next step

Build a one-page DPDP support matrix for customers: each Fiduciary obligation, the feature or process that supports it, and the contract clause that covers it. Then run a quick external check of your public trust pages.

Advertisement