Infosek
INFOSEK

Does DPDP Apply to B2B Companies With No Consumer Users?

Yes, and the reason is simple enough that it is often missed. The Act protects individuals, not consumers, and every B2B company processes data about individuals from the day it hires its first employee.

Does DPDP Apply to B2B Companies With No Consumer Users?

The short answer

Yes. The DPDP Act protects individuals, not consumers. A Data Principal is the individual to whom the personal data relates, and nothing in section 3 turns on whether your customer is a person or a company.

Even a company that sells exclusively to enterprises holds personal data in at least three places:

Employment data has no carve-out

Some data protection regimes handle employment separately. The DPDP Act does not exempt it. HR files, payroll, performance records, background check results and recruitment pipelines are all processing of digital personal data, with an employer as Data Fiduciary.

This is usually the largest and least governed personal data set in a B2B company, because it sits with HR rather than engineering and rarely appears on a security team's inventory.

The obligation that bites hardest

For most B2B companies it is Rule 8, erasure once the specified purpose is no longer being served. Sales and recruitment data accumulates indefinitely by default. Nobody deletes a lead list, and rejected candidate CVs sit in an applicant tracking system for years with no defined retention.

Rule 6 is the other one. It requires access control on the computer resources holding personal data, and logs giving visibility on who accessed it. In many B2B companies the CRM is broadly readable and the ATS has no access logging at all.

The instinct that DPDP is a consumer-tech problem comes from where the public conversation has been, not from the text. The Act asks whether you process data about identifiable individuals, and every company does.

Infosek Team

You are also probably a Processor

If your product holds data about your customers' end users, you are likely a Data Processor for that, alongside being a Data Fiduciary for your own employee and contact data. Both roles run at once.

The practical consequence is contractual. Rule 6(1)(f) requires appropriate provisions for reasonable security safeguards in the contract between a Data Fiduciary and its Data Processor. Your enterprise customers will need that clause with you, and you will need it with your own sub-processors. Expect this in procurement questionnaires well before May 2027.

Where to start

Common questions

Does the DPDP Act apply to B2B companies?

Yes. The Act applies to the processing of digital personal data, and personal data means data about an identifiable individual. A B2B company processes personal data in its employee records, its buyer and prospect contacts, and its vendor contacts, even if it never has a consumer user.

Is employee data covered by the DPDP Act?

Yes. An employee is a Data Principal like any other individual. Nothing in section 3 carves out processing in an employment context, so HR records, payroll data and recruitment data are within scope.

Mapping what you actually hold?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment