Sector guide
SaaS and IT services companies have a problem other sectors do not: they are usually a Data Fiduciary and a Data Processor at the same time, for different data, and the obligations differ. Getting that split wrong is the most common structural error in this sector.
Two categories of personal data, two sets of duties.
Once your customers start their own DPDP programmes, you become an item in their vendor register — and they will send you the assessment. Being ready for it is a commercial advantage, not just a compliance one.
Write the fiduciary/processor split down and get it agreed between legal, product and security. Everything else — notices, consent, DSR handling, contracts — follows from it.
Then prepare the answers to the five questions above as a standing document, because you will be asked them repeatedly.
Usually both. You are a Data Fiduciary for your own employee, marketing and billing data, and typically a Processor for the data your customers put into your product, acting on their documented instructions.
Yes. The Act does not exempt small companies from its core obligations, though the additional duties that attach to Significant Data Fiduciaries — DPO, DPIA, independent audit — depend on that classification.
Where data is stored, whether it leaves India, whether you can delete on instruction and prove it, whether you can support their data principal requests inside their timeline, your breach notification commitment, and your sub-processor list.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →