AMLEGALS — Strategic Lawyering

Is Your SaaS Company a Data Processor or Data Fiduciary Under DPDPA?

Is Your SaaS Company a Data Processor or Data Fiduciary Under DPDPA?

Your contract says processor. Your roadmap may disagree.

The scene

The product team shipped ‘industry benchmarks’: every customer's metrics pooled, anonymised, compared. It was the most-used feature of the year. It was also the moment the company started deciding the purpose of client data.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

We're a processor everywhere.

Any activity where you set the purpose makes you a fiduciary for it.

Map role per activity, and review it with every release.

Aggregation removes personal data.

Aggregation after processing still required processing personal data for your purpose.

Get a basis for the aggregation step itself.

A role register

One row per activity: whose data, who decides purpose, who decides means, which role you hold. Product should add a row before shipping.

Monday morning

01 List features that use client data for your own purposes.

02 Assign a role to each.

03 Tell legal before the next release, not after.

Questions, answered plainly

How do I know if my company is a Data Fiduciary or Data Processor? +

A Data Fiduciary determines the purpose and means of processing. A Data Processor processes on behalf of a fiduciary. A company can be both, for different activities.

Do Data Processors have direct obligations under DPDPA? +

DPDPA places obligations primarily on Data Fiduciaries, who must ensure processors comply through contract. Processors should expect those obligations to flow down in their contracts.

Sector · SaaS & IT services You think you're the processor. Your contract may disagree. Read →

SaaS & IT services · Deep dive Your customer trusts you. You trust twenty others. Read →

SaaS & IT services · Deep dive The DPDPA questionnaire is the new security review. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).