You think you're the processor.Your contract may disagree.
Role under DPDPA follows who decides the purpose and means, not what the sales deck says.
In one line: It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.
The moment you decide why, you are the fiduciary.
The scene
The SaaS platform processed customer data for its clients, cleanly, as a processor. Then product built a benchmarking feature that pooled usage across clients. Nobody noticed that for that feature, the company had started deciding the purpose. It had quietly become a fiduciary.
Where the thinking breaks
Selling resilience
Enterprise buyers in India are rewriting procurement questionnaires around DPDPA. A vendor that can show its breach clock, its sub-processor map and its role analysis wins the security review faster.
The full SaaS & IT services briefing
3 deep divesThe moment you decide why, you are the fiduciary.
Your contract says processor. Your roadmap may disagree.
Your customer trusts you. You trust twenty others.
Every tool your engineers love is a link in someone else's liability.
The DPDPA questionnaire is the new security review.
The vendor with the answers ready is the vendor that gets signed.
Monday morning
- 01List every feature that uses client data for your own purpose.
- 02Map sub-processors, including monitoring and support tools.
- 03Pre-write answers to the DPDPA questions buyers now ask.
Questions, answered plainly
Is a SaaS company a Data Fiduciary or Data Processor under DPDPA?
It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.
Does DPDPA apply to Indian IT companies processing foreign clients' data?
Section 17(1)(d) exempts certain provisions for processing personal data of persons not within India under a contract with a person outside India. Obligations such as security safeguards and the company's own employee data remain relevant.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner