DPDP Officer SaaS — Who Should Own Privacy at Your Company?
Practical org-chart guidance on where privacy accountability sits in a 50-person SaaS company — without hiring a full-time privacy head.
Here is a conversation that happens in hundreds of Indian SaaS and IT companies every year: A client questionnaire arrives asking for the name and contact of the Data Protection Officer or Grievance Officer. Someone says "just put the CEO's email." The CEO has never thought about this. The questionnaire goes back with the CEO's email. Six months later, a data subject sends a rights request to that email address. It sits unread for three weeks. The client finds out.
Privacy accountability cannot be an afterthought, and it cannot be a box checked with a name that does not correspond to an actual person who is prepared to do the job. The good news: for a 50-person SaaS vendor, the Grievance Officer role does not require a full-time hire or a privacy law degree. It requires the right person in the right structure with the right support.
What Does the DPDP Act Actually Require?
Section 13 of the DPDP Act 2023 requires every Data Fiduciary to publish a contact for a Grievance Officer to enable data principals (individuals) to raise grievances about the handling of their personal data. The Significant Data Fiduciary designation — which will be notified by the Government for entities processing large volumes or sensitive categories of data — comes with additional requirements, potentially including the appointment of a Data Protection Officer.
For most 50–200 person SaaS vendors who are not Significant Data Fiduciaries, the mandatory requirement is relatively lightweight: a named Grievance Officer, published contact details, and a functioning process to receive and respond to grievances. The harder requirement is the substantive one: someone who actually understands what personal data the company processes, has read the privacy policies, knows what to do if a data breach occurs, and can answer client questions about the company's privacy programme.
That person — whatever their title — needs to exist. Let us look at the realistic options.
Option 1: A Co-Founder
The Co-Founder as Grievance Officer
Pros: Highest authority — can actually make decisions. Closest to product context. Signals to clients that privacy is taken seriously at leadership level. Available and reachable.
Cons: Bandwidth is the constant constraint. Co-founders are already context-switching across sales, product, hiring, and fundraising. Privacy tasks tend to get deprioritised when investor calls and customer escalations are competing for attention. If the co-founder is also the technical lead, there is a conflict-of-interest risk when privacy and engineering priorities collide.
Option 2: The CTO
The CTO as Grievance Officer
Pros: Closest to the technical systems that process personal data. Can directly assess breach risk, authorise security controls, and verify deletion capabilities. Usually already involved in client security questionnaire responses.
Cons: The most common "dual-hatting" risk. A CTO who is also the privacy lead faces a structural conflict every time a privacy-protective measure requires engineering resources. "We don't have the sprint capacity to build the deletion API" is a real conversation that becomes ethically fraught when the person saying it is also the person responsible for ensuring deletion happens. Additionally, most CTOs are not trained in legal analysis, which matters when interpreting DPDP Act obligations.
Option 3: In-House Legal Counsel
In-House Counsel as Grievance Officer
Pros: The natural fit in terms of skills — legal interpretation, policy drafting, rights request handling, DPA negotiation. If the counsel is DPDP-aware, they can manage the full programme, not just the Grievance Officer function.
Cons: Most 50-person SaaS companies do not have in-house counsel. Those that do often have a generalist with a commercial contracts background who is not specifically trained in data protection law. Mistaking "we have a lawyer" for "we have privacy expertise" is a common error.
Option 4: Fractional or Virtual DPO / Privacy Counsel
The Fractional Privacy Lead
Pros: Specialist expertise without full-time cost. A fractional privacy advisor can act as Grievance Officer (in a supportable way — their name and contact published, with your team as point of contact for day-to-day intake), manage your privacy programme structure, negotiate DPAs with clients, and respond to rights requests. Cost is typically ₹15,000–₹50,000 per month for 4–8 hours of specialist time.
Cons: Availability — a fractional advisor is not always reachable within the hour. For urgent breach situations, response time may not meet contractual obligations unless the engagement specifies availability requirements. Also: if the advisor is the only person who understands the privacy programme, key-person dependency is a risk.
What Does the Grievance Officer Actually Do Week-to-Week?
Regardless of which model you choose, the Grievance Officer role involves a predictable set of activities. In a well-run programme at a 50-person company, here is what a typical month looks like:
Regular (monthly): Review any data subject requests received (typical volume: 0–3 per month for B2B SaaS), review any new sub-processor additions for DPDP compliance implications, maintain the Grievance Register (a simple log of all requests, response status, and outcomes).
Quarterly: Review the privacy notice and DPA templates for accuracy, conduct or oversee a brief data inventory refresh (any new data categories added to the product?), review the incident response plan, and deliver or coordinate employee awareness reminders.
Ad hoc: Respond to client questionnaire queries on privacy matters, review and negotiate DPA clauses with enterprise clients, manage any incident that may constitute a personal data breach.
The documentation requirements are equally manageable: a Grievance Register, a sub-processor register, a data inventory (even a spreadsheet), a copy of the current privacy notice, DPA templates, and a one-page incident response playbook. None of this requires specialist software — the first iteration can be Google Sheets and Docs.
The Documents the Grievance Officer Must Maintain
For any model to be credible, the Grievance Officer must be able to produce five categories of documentation on short notice: (1) The Grievance Register — a log of all data principal contacts, the nature of their grievance or request, the date received, actions taken, and resolution. (2) The Privacy Notice — current version with a history of when it was updated. (3) The DPA Library — all executed DPAs with clients and sub-processors. (4) The Data Inventory — even an informal record of what personal data the company holds, for what purpose, in which systems, and with what retention period. (5) The Incident Log — a record of any data security incidents, however minor, and the response taken.
If your Grievance Officer cannot locate these five documents, the role exists in name only. The practical first step after appointment is building this documentation baseline — which is also what feeds into the answer frameworks for client questionnaires described in our post on how to answer DPDP client questionnaires.
For context on the broader compliance programme that the Grievance Officer sits within, see our posts on DPA vs full DPDP readiness and the vendor gap assessment methodology. For the legal background on your obligations as a Data Fiduciary vs. Data Processor, see our earlier post on data fiduciary vs data processor under the DPDP Act. Cost planning guidance is available at what DPDP compliance costs a mid-size IT vendor.
Frequently Asked Questions
Is a Grievance Officer the same as a Data Protection Officer?
Not exactly. The DPDP Act uses the term "Grievance Officer" for the individual responsible for receiving and resolving data principal grievances. A "Data Protection Officer" is a term from GDPR that may be adopted in India for Significant Data Fiduciaries once the rules are finalised. For most mid-size IT vendors, the Grievance Officer role covers all the functions that a DPO would serve — the title may change, but the practical responsibilities are similar.
Can the Grievance Officer be located outside India?
The DPDP Act and proposed rules require the Grievance Officer to be accessible to data principals in India. While the Act does not explicitly require Indian residency, published contact details should be India-reachable (an Indian phone number and email), and the Officer should have working knowledge of the DPDP Act framework. Using a foreign-based DPO without India-specific expertise creates both practical and reputational risk.
What happens if a data principal complaint goes unresolved?
Under the DPDP Act, data principals can escalate unresolved grievances to the Data Protection Board of India. The Board has the power to investigate, direct remediation, and impose penalties. For a vendor, an escalated complaint that reaches the Board is a compliance failure that can trigger penalties of up to ₹250 crore for serious violations, and reputational damage with clients who monitor their own compliance posture.
Ready to Set Up Your Grievance Officer Function?
Our Grievance Officer Kit includes appointment documentation, a Grievance Register template, a response playbook, and a published-contact-page template — everything needed to set up a functioning grievance function in a day.
Get the Grievance Officer Kit — ₹1,499