Skip to main content

Sources last verified on 17 August 2026. Methodology

Industry guide

DPDP for SaaS

SaaS companies usually sit on both sides of the framework: Data Fiduciary for their own users and Data Processor for customer data. The distinction decides which duties are yours directly.

How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.

Where the framework usually bites first

  • Know your role per data flowSection 2, official text →

    Your marketing site users and your customers' end users put you in different roles with different duties. The roles are defined in the Act.

  • Processor contract termsRule 6, official text →

    Safeguard obligations reach processing done on a fiduciary's behalf, which shows up in your customer contracts.

  • Breach duties across the chainRule 7, official text →

    A breach at a processor triggers fiduciary duties upstream; contracts should say who does what within the clocks.

Tools for this sector