You think you're the processor.Your contract may disagree.

Role under DPDPA follows who decides the purpose and means, not what the sales deck says.

In one line: It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.

The estate · SaaS & IT servicesHover to inspect

The moment you decide why, you are the fiduciary.

The scene

The SaaS platform processed customer data for its clients, cleanly, as a processor. Then product built a benchmarking feature that pooled usage across clients. Nobody noticed that for that feature, the company had started deciding the purpose. It had quietly become a fiduciary.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
We're only a processor. Features that use client data for your own purposes make you a fiduciary for them. Map role per processing activity, not per company.
We serve foreign clients, so DPDPA doesn't apply. Section 17(1)(d) exempts certain processing of non-residents' data under foreign contracts, not everything. Know the edges of the exemption; your own staff data is still in scope.
The client's DPA covers it. Client paper protects the client. Your sub-processors need your paper. Flow obligations down, and evidence them up.

Selling resilience

Enterprise buyers in India are rewriting procurement questionnaires around DPDPA. A vendor that can show its breach clock, its sub-processor map and its role analysis wins the security review faster.

The full SaaS & IT services briefing

3 deep dives
Deep dive 01→

The moment you decide why, you are the fiduciary.

Your contract says processor. Your roadmap may disagree.

Deep dive 02→

Your customer trusts you. You trust twenty others.

Every tool your engineers love is a link in someone else's liability.

Deep dive 03→

The DPDPA questionnaire is the new security review.

The vendor with the answers ready is the vendor that gets signed.

Monday morning

  1. 01List every feature that uses client data for your own purpose.
  2. 02Map sub-processors, including monitoring and support tools.
  3. 03Pre-write answers to the DPDPA questions buyers now ask.

Questions, answered plainly

Is a SaaS company a Data Fiduciary or Data Processor under DPDPA?

It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.

Does DPDPA apply to Indian IT companies processing foreign clients' data?

Section 17(1)(d) exempts certain provisions for processing personal data of persons not within India under a contract with a person outside India. Obligations such as security safeguards and the company's own employee data remain relevant.

Sector · TelecomA billion subscribers. A billion Data Principals.Read → Sector · InsuranceYour agent's phone is part of your data estate.Read → Sector · HR & StaffingThe candidate you never hired is still your Data Principal.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner