SaaS and IT services
DPDP compliance for SaaS and IT services companies
A SaaS company is usually two things at once: a processor for its customers' data, and a Data Fiduciary for its own users, staff and leads. Customers will ask how you handle both.
The data you hold
- Customer users' accounts and logs
- Data your customers upload
- Your own leads and marketing lists
- Employee records
- Support tickets
What the Act asks of you
- Customers need you under contract
- Your customers may only use you as a processor under a valid contract, so expect DPA requests in every security review. Process their data only on their instructions.
- Section 8(2)
- Know where data is hosted
- Data can go to any country unless the government restricts it by notification. Keep a current list of where you and your sub-processors host data.
- Section 16, Rule 15
- Tell customers about breaches fast
- Your customers must report breaches to the Board and to affected people, with a detailed report within 72 hours. They can only do that if you tell them quickly.
- Section 8(6), Rule 7
- Your own data is your duty
- For your own users, staff and marketing, you are the Data Fiduciary: notice, consent, rights and erasure all apply to you directly.
- Sections 5, 6, 8
How GRC Flow handles it
Read-only AWS and GitHub checks show where data is stored and back findings with evidence.
See how it worksDPA drafts with a schedule per vendor, built from the vendor register.
See how it worksThe data-flow map flags every flow that leaves India.
See how it works