How should a SaaS company approach DPDP?
You're usually both a processor and a fiduciary. Here's how to balance both roles.
The processor role and customer obligations
As a processor, you process customer data only on their documented instructions. You must sign a DPA covering scope, security, breach notification, sub-processor approval, and rights-request support. Your SLA for DSAR responses must be tight — if a customer's customer asks for data, your customer needs your data within days to meet their 30-day Board deadline.
Sub-processor and supply-chain risk
You likely rely on payment processors, email delivery services, analytics platforms and infrastructure providers. Each is a sub-processor. You must document every one, get customer (or customer-customer) sign-off for new subs, and maintain agreements with them. A breach by a vendor is your compliance failure too.
Your own fiduciary data
Your SaaS account holder's name, email, billing address, usage patterns and support history are your fiduciary data. Separately consent to marketing, analytics and product improvements. Set retention limits — former customers' data should be deleted within a reasonable period after churn.
Frequently asked questions
Do I need a DPA even for a small customer?
Yes. DPDP applies to all processing. A simple DPA works for small customers; larger ones will supply their own template. Have a standard DPA ready.
What if my customer doesn't ask for a DPA?
You still have the obligation. A customer's silence doesn't waive your compliance. Offer the DPA proactively.
How fast must I respond to DSAR?
Customers need your data within a few business days so they can meet their 30-day Board deadline. Plan for turnaround within 3 business days.
Build your processor compliance
Run the DPDP for SaaS guide to map processor obligations, DPA requirements and sub-processor controls.
DPDP for SaaS