AMLEGALS — Strategic Lawyering
SaaS & Cloud (Data Processors) — DPDPA sector brief

SaaS & Cloud (Data Processors)

DPDPA Impact on SaaS & Cloud Providers

SaaS and cloud providers typically process personal data on behalf of customers as Data Processors — a role defined by the Section 8(2) contract, strong security and breach-support duties.

In short

SaaS and cloud providers typically fall under the DPDP Act, 2023 as Data Processors, processing customer end-user data on instructions under a valid Section 8(2) contract. Their core duties are reasonable security safeguards under Section 8(5) read with Rule 6 and breach-notification support enabling the customer to meet Rule 7 timelines.

  • A SaaS or cloud provider processing customer data on instructions is a Data Processor under Section 8(2).
  • Sub-processors must be bound by flow-down obligations consistent with the customer contract.
  • Cross-border processing remains permitted subject to Section 16 read with Rule 15 and any Central Government restriction.

When the Act applies

The Act applies where a provider processes the digital personal data of Data Principals in India on a customer’s behalf, including where infrastructure or support sits outside India.

Personal data typically in play

  • Customer end-user records held in the platform
  • Authentication and access logs
  • Support tickets containing personal data
  • Backups, replicas and telemetry
  • Sub-processor and hosting-region data

Mapped obligations

Section 8(2)

Processor under valid contract

Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.

Section 8(5) · Rule 6

Reasonable security safeguards

Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.

Section 8(6) · Rule 7

Breach intimation

On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).

Section 16 · Rule 15

Cross-border processing

Processing personal data outside India remains permitted subject to any restriction the Central Government notifies for specified countries, and to Rule 15 requirements on access by foreign States; sectoral localisation directions of RBI, IRDAI and SEBI continue to apply independently.

Section 8(7) · Rule 8

Retention limits & erasure

Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.

Sections 11–14 · Rule 14

Data Principal rights

Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.

Recurring compliance risks

  • Processing customer data beyond the documented instructions/contract
  • Onboarding sub-processors without flow-down obligations
  • No breach-notification support enabling the customer to meet Rule 7
  • Unclear deletion and return of data at contract exit

Actions that follow

  1. 1Offer a Section 8(2)-aligned processing contract with flow-down to sub-processors
  2. 2Provide breach detection and notification support to customers
  3. 3Document hosting regions and cross-border posture under Rule 15
  4. 4Build data-return and verified-deletion at off-boarding

Frequently asked questions

Is a SaaS provider a Data Processor or a Data Fiduciary under the DPDP Act?
When it processes customer end-user personal data only on the customer’s documented instructions, it is a Data Processor engaged under a valid Section 8(2) contract. If it uses that data for its own purposes, it becomes a Data Fiduciary for that processing.
Can a cloud provider host or process Indian personal data outside India?
Cross-border processing remains permitted under Section 16 read with Rule 15, subject to any restriction the Central Government notifies for specified countries and to sectoral localisation directions of RBI, IRDAI or SEBI where they apply.
What breach duties does a processor owe its customer?
A processor must support the customer’s breach obligations under Section 8(6) read with Rule 7 — detecting and reporting incidents promptly so the customer can intimate affected Data Principals without delay and file the detailed report to the Board within 72 hours.