Does DPDP apply to B2B companies that only process corporate data?
Many B2B companies assume the DPDP Act does not apply to them because they do not sell to consumers. This assumption is often wrong.
What data does a B2B company process that is personal data?
Even a purely B2B company processes personal data: employee records (payroll, performance, health insurance, attendance); vendor contact data (the name, email, and phone of individual vendor representatives); client contact data in the CRM; prospect contact data in the marketing database; and personal data of individuals in any documentation (contracts signed by individuals, invoices to sole proprietors). If your product processes data about individuals on behalf of your enterprise clients, that is also in scope.
Are B2B SaaS companies Data Processors, Fiduciaries, or both?
B2B SaaS companies are typically Data Processors for their clients' data — they process personal data on behalf of their client companies. However, they are Data Fiduciaries for: their own employee data; prospect and client contact data in their CRM; website visitor analytics data; and any data they collect for their own business intelligence or product improvement purposes. Many B2B SaaS companies have not fully recognised their Fiduciary obligations for their own data — focusing only on their Processor obligations to enterprise clients.
What must B2B companies do about their CRM contact databases?
A CRM database holding individual contact names, emails, phones, and job titles at client and prospect companies contains personal data. DPDP applies: you need a privacy notice covering this processing, a legitimate purpose (managing the business relationship), a retention schedule (delete stale contacts after a defined period), and a mechanism for individuals to access and erase their contact records. The legitimate use basis (employment/business relationship) covers the core CRM use, but marketing communications to those contacts still need consent.
Do B2B companies need consent to send emails to business contacts?
Sending emails to an individual at a business (their work email) for a business purpose — following up on a proposal, sending an invoice, scheduling a meeting — can be covered by the legitimate use basis (it is part of the business relationship). However, adding that individual to a marketing nurture sequence, sending them newsletters, or profiling them for cross-sell requires consent or a clearly disclosed legitimate use. B2B marketing automation that sends multiple marketing emails to individual contacts without consent is a DPDP risk that many companies are not aware of.
What if your B2B product processes your client's customers' personal data?
If you build software that processes personal data on behalf of your enterprise clients — a CRM, an HRMS, a marketing automation tool, a healthcare management system — you are a Data Processor under the DPDP Act for that client data. Your enterprise clients are the Data Fiduciaries. You need: a DPDP-compliant DPA in your enterprise contracts; security safeguards for the personal data you process; breach notification procedures to notify clients within your contractual SLA; and sub-processor controls for any third parties you use to deliver your service.
How does DPDP apply to B2B companies selling to government clients?
B2B companies providing services to government departments or PSUs process personal data of government employees and potentially citizens benefiting from government services. Government employee data is subject to DPDP in the same way as private sector employee data. Citizen data processed through a government contract may be subject to the legitimate use basis (State functions), but your security obligations and DPA requirements still apply. Many government contracts now include data security clauses — ensure your DPDP compliance programme covers government client engagements.
Frequently asked questions
Is a company that sells only to other companies completely outside DPDP scope?
No B2B company is completely outside DPDP scope because every company processes employee personal data. The question is the scale of non-employee personal data processing. A purely B2B company with no consumer-facing product, no marketing database, and no product that processes individuals' data may have relatively minimal DPDP obligations — employee data, vendor contacts, CRM contacts. But these obligations still exist and must be met.
Can we use the legitimate use basis for all B2B data processing to avoid consent?
The legitimate use basis covers processing necessary for the business relationship and for statutory compliance. It does not cover: marketing to individual contacts beyond the core business relationship purpose; profiling contacts for commercial intelligence; sharing contact data with third-party marketing partners; or using contact data for AI training. The key test: is this processing strictly necessary for the business relationship and its legal obligations? If yes, legitimate use may apply. If it's a commercial enhancement, consent is likely needed.
If we are a Data Processor for our enterprise clients, who is responsible for notifying affected individuals of a breach?
The Data Fiduciary (your enterprise client) is responsible for notifying affected individuals — their customers whose data was breached. You, as the Data Processor, are responsible for notifying your client within the period specified in your DPA (24–48 hours is the recommended standard). The client then makes the notification decisions to the Board and to individuals. Your DPA and your client's DPA with their customers must together create a complete notification chain.
Assess your B2B DPDP compliance obligations
Niti Bharat's DPDP Readiness Assessment covers B2B companies — employee data, CRM contacts, Processor obligations for client data, and enterprise contract DPA requirements.
Start B2B DPDP Assessment