Skip to content

SaaS and IT services

DPDP compliance for SaaS and IT services companies

A SaaS company is usually two things at once: a processor for its customers' data, and a Data Fiduciary for its own users, staff and leads. Customers will ask how you handle both.

The data you hold

  • Customer users' accounts and logs
  • Data your customers upload
  • Your own leads and marketing lists
  • Employee records
  • Support tickets

What the Act asks of you

Customers need you under contract
Your customers may only use you as a processor under a valid contract, so expect DPA requests in every security review. Process their data only on their instructions.
Section 8(2)
Know where data is hosted
Data can go to any country unless the government restricts it by notification. Keep a current list of where you and your sub-processors host data.
Section 16, Rule 15
Tell customers about breaches fast
Your customers must report breaches to the Board and to affected people, with a detailed report within 72 hours. They can only do that if you tell them quickly.
Section 8(6), Rule 7
Your own data is your duty
For your own users, staff and marketing, you are the Data Fiduciary: notice, consent, rights and erasure all apply to you directly.
Sections 5, 6, 8

How GRC Flow handles it

  • Read-only AWS and GitHub checks show where data is stored and back findings with evidence.

    See how it works
  • DPA drafts with a schedule per vendor, built from the vendor register.

    See how it works
  • The data-flow map flags every flow that leaves India.

    See how it works