DPDP for SaaS Companies: You Are Probably Both Roles
The dual role is the whole story. Treating yourself as only a processor leaves your own obligations unmet, and treating yourself as only a fiduciary confuses your customers' contracts.
Both roles, at once
You determine the purpose for your employee records, your CRM contacts and your billing data. For those you are a Data Fiduciary with the full set of obligations.
Your customers determine the purpose for the end-user data they put into your product. For that you are a Data Processor, bound principally through contract.
What your customers will ask for
Enterprise buyers in regulated sectors will need contractual and operational assurances so they can meet their own duties:
- The Rule 6(1)(f) safeguards clause in your agreement.
- A commitment to notify them promptly of an incident, because their Rule 7 clock runs from their awareness and you are usually the source of it.
- The ability to delete a specific individual's data on request, so they can satisfy erasure and rights obligations.
- Clarity on sub-processors, since your vendors become part of their supply chain.
- Where data is stored, particularly if they may be notified as a Significant Data Fiduciary and become subject to Rule 13(4) localisation for specified data.
The features this implies
Most of the above are product capabilities rather than paperwork. Deleting one end user cleanly, exporting one user's data, and telling a customer precisely which of their records were in an affected system are all engineering work.
The vendor questionnaire is arriving before the regulator does. From 2027 it will ask about DPDP directly, and “we are working on it” loses deals in a way a regulator never would.
Infosek Team
What to do now
- Write down which data sets you are Fiduciary for and which you are Processor for.
- Build per-user deletion and export if you do not have them.
- Add the Rule 6(1)(f) clause to your standard agreement and push it down to your own sub-processors.
- Publish a security page. Its absence is itself a signal to buyers.
Common questions
Is a SaaS company a Data Fiduciary or a Data Processor?
Usually both. It is a Data Fiduciary for data where it determines the purpose, such as its own employee records, marketing lists and billing contacts. It is a Data Processor for the end-user data its customers load into the product, where the customer determines the purpose.
What do SaaS customers need from their vendors under DPDP?
Principally the contractual provision Rule 6(1)(f) requires, binding the Data Processor to take reasonable security safeguards, plus enough operational support that the customer can meet its own obligations on breach intimation, erasure and rights requests.
Answering customer security questionnaires?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment