Infosek
INFOSEK

DPDP for SaaS Companies: You Are Probably Both Roles

The dual role is the whole story. Treating yourself as only a processor leaves your own obligations unmet, and treating yourself as only a fiduciary confuses your customers' contracts.

DPDP for SaaS Companies: You Are Probably Both Roles

Both roles, at once

You determine the purpose for your employee records, your CRM contacts and your billing data. For those you are a Data Fiduciary with the full set of obligations.

Your customers determine the purpose for the end-user data they put into your product. For that you are a Data Processor, bound principally through contract.

What your customers will ask for

Enterprise buyers in regulated sectors will need contractual and operational assurances so they can meet their own duties:

The features this implies

Most of the above are product capabilities rather than paperwork. Deleting one end user cleanly, exporting one user's data, and telling a customer precisely which of their records were in an affected system are all engineering work.

The vendor questionnaire is arriving before the regulator does. From 2027 it will ask about DPDP directly, and “we are working on it” loses deals in a way a regulator never would.

Infosek Team

What to do now

Common questions

Is a SaaS company a Data Fiduciary or a Data Processor?

Usually both. It is a Data Fiduciary for data where it determines the purpose, such as its own employee records, marketing lists and billing contacts. It is a Data Processor for the end-user data its customers load into the product, where the customer determines the purpose.

What do SaaS customers need from their vendors under DPDP?

Principally the contractual provision Rule 6(1)(f) requires, binding the Data Processor to take reasonable security safeguards, plus enough operational support that the customer can meet its own obligations on breach intimation, erasure and rights requests.

Answering customer security questionnaires?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment