DPDPA for SaaS and IT Services: Processor or Fiduciary?
DPDPA for SaaS and IT Services: Processor or Fiduciary?
The moment you decide why, you are the fiduciary.
The scene
The SaaS platform processed customer data for its clients, cleanly, as a processor. Then product built a benchmarking feature that pooled usage across clients. Nobody noticed that for that feature, the company had started deciding the purpose. It had quietly become a fiduciary.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
We're only a processor.
Features that use client data for your own purposes make you a fiduciary for them.
Map role per processing activity, not per company.
We serve foreign clients, so DPDPA doesn't apply.
Section 17(1)(d) exempts certain processing of non-residents' data under foreign contracts, not everything.
Know the edges of the exemption; your own staff data is still in scope.
The client's DPA covers it.
Client paper protects the client. Your sub-processors need your paper.
Flow obligations down, and evidence them up.
Selling resilience
Enterprise buyers in India are rewriting procurement questionnaires around DPDPA. A vendor that can show its breach clock, its sub-processor map and its role analysis wins the security review faster.
The full SaaS & IT services briefing 3 deep dives
Deep dive 01 →
The moment you decide why, you are the fiduciary.
Your contract says processor. Your roadmap may disagree.
Deep dive 02 →
Your customer trusts you. You trust twenty others.
Every tool your engineers love is a link in someone else's liability.
Deep dive 03 →
The DPDPA questionnaire is the new security review.
The vendor with the answers ready is the vendor that gets signed.
Monday morning
01 List every feature that uses client data for your own purpose.
02 Map sub-processors, including monitoring and support tools.
03 Pre-write answers to the DPDPA questions buyers now ask.
Questions, answered plainly
Is a SaaS company a Data Fiduciary or Data Processor under DPDPA? +
It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.
Does DPDPA apply to Indian IT companies processing foreign clients' data? +
Section 17(1)(d) exempts certain provisions for processing personal data of persons not within India under a contract with a person outside India. Obligations such as security safeguards and the company's own employee data remain relevant.
Sector · Telecom A billion subscribers. A billion Data Principals. Read →
Sector · Insurance Your agent's phone is part of your data estate. Read →
Sector · HR & Staffing The candidate you never hired is still your Data Principal. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
