For SaaS products, IT services and software agencies
DPDP compliance for SaaS and IT services
You are a data processor for your customers’ data and a data fiduciary for your own users and leads. Enterprise buyers will ask for DPDP answers in every security review from now on. ConsentKit helps with both roles, and gives your customers consent tooling they can switch on inside your product.
- Your role
- Processor and fiduciary
- Customer security reviews
- Now include DPDP
- Full compliance
- 13 May 2027
Fieldbook asks for your consent
Choose how we may use your details. You can change this anytime.
Where the DPDP Act touches a SaaS business
The same company holds data in two roles. Pick an area to see which role applies and what it asks of you.
What changes for SaaS on 13 May 2027
Processors have fewer direct duties under the DPDP Act, but your customers will pass theirs on to you by contract.
Know which role you are inSections 2 and 8
For your own users and leads you are a fiduciary. For your customers’ data you are a processor acting on their instructions.
A data map that tags each dataset as fiduciary or processor data.
DPAs with every customerSection 8(2)
Fiduciaries may only use processors under a valid contract. Expect every enterprise customer to ask for DPDP terms.
A DPDP-ready DPA template and a sub-processor list page.
Security safeguards customers will auditSection 8(5) and Rule 6
Encryption, access control, monitoring, backups and logs kept for at least a year.
Access logging and evidence exports for security questionnaires.
Help customers hit the 72-hour clockRule 7
Your customers must report breaches within 72 hours, so they need to hear from you much faster.
An incident workflow that notifies affected customers with the details they need.
Consent tooling inside your productSections 5 and 6
Customers collecting data through your product need notices and consent there too.
Embed ConsentKit through our API so your customers can switch it on.
Cross-border transfers are allowed, with limitsSection 16
Transfers abroad are permitted except to countries the government restricts. Keep track of where data lives.
A hosting and transfer register for customer reviews.
A plan for product and security teams
Security reviews already ask about DPDP. Get your paperwork ready first, then the product.
Data map and roles
Tag every dataset as fiduciary or processor data and list sub-processors.
Contracts and trust page
Publish a DPA, sub-processor list and security overview.
Product changes
Consent on sign-up, in-app deletion, and consent tooling for customers.
Incident readiness
Set customer breach notice timelines and rehearse.
For every kind of software business
Templates for your model.
B2B SaaS
Enterprise customers and security reviews.
B2C apps
You are the fiduciary for your users.
IT services and outsourcing
Processor for many clients.
Web and app agencies
Building consent into client projects.
Hosting and cloud providers
Infrastructure processors.
AI products
Training data and customer data limits.
DPDP compliance for software companies near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions SaaS teams are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Are we a data fiduciary or a processor?
Usually both. You are a fiduciary for your own users, leads and staff, and a processor for data your customers put into your product.
Do processors have direct duties under the Act?
Most duties sit with fiduciaries, but fiduciaries must use processors only under a contract and remain responsible for them, so customers will pass requirements on to you.
Can we store Indian customers’ data abroad?
Yes, except in countries the government restricts by notification. Sector rules, such as RBI’s for payments data, may still require local storage.
Can we use customer data to train our AI models?
Not as a processor acting on customer instructions, unless the customer agrees and has a lawful basis for it.
Can we offer ConsentKit to our own customers?
Yes. Our API lets you embed consent notices and records in your product. Talk to us about partner pricing.
Be ready for your next security review
The readiness check takes about ten minutes and gives you a gap report for SaaS and IT businesses.