SaaS vendors, IT services firms, BPOs and cloud providers mostly process personal data on behalf of their clients. Under the Digital Personal Data Protection Act 2023, that usually makes them Data Processors for client data — and Data Fiduciaries for their own employee, lead and customer-contact data.
How DPDP applies to processors
- Obligations flow through contracts: a Data Fiduciary may engage a processor only under a valid contract. Expect clients to push DPDP clauses on security, breach notice, sub-processors, deletion and audit rights into every agreement.
- Security is the product: clients remain liable for reasonable security safeguards, including where a processor fails. That liability will be passed back to vendors through questionnaires, audits and indemnities.
- Breach response: a client must report a breach to the Board within tight timelines, so it needs to hear about incidents from its vendors immediately.
- Deletion on exit: when a contract ends or a client's purpose is served, the personal data must be deleted, including from backups and sub-processors, as agreed.
- Cross-border work: transfers outside India are allowed unless the Government restricts a destination. The Act also has a limited exemption for Indian companies processing non-residents' data under contracts with foreign clients.
Gaps commonly found in SaaS and IT services
- Standard MSAs with confidentiality clauses but no data processing terms
- No up-to-date list of sub-processors and where they host data
- Production client data copied into test, staging or analytics environments
- Support engineers with standing access to client data and no access logging
- Incident response plans that do not include a client-notification step and timeline
- No evidence that client data was deleted at contract end
- The company's own HR and sales data overlooked because "we are only a processor"
Priorities before May 2027
- Prepare a DPDP-ready data processing addendum before clients send theirs.
- Publish and maintain a sub-processor list with hosting locations.
- Move to just-in-time, logged access to client data and keep logs for at least a year.
- Add client breach notification with a defined timeline to the incident response plan.
- Treat your own employee and marketing data as a Data Fiduciary would.
An independent DPDP audit report is also a strong answer to client security questionnaires. See the DPDP audit checklist for what it covers.
