Privacy Law · India · DPDPA

India DPDPA Compliance Guide for B2B SaaS (2025)

The Digital Personal Data Protection Act, 2023 (DPDPA) applies extraterritorially — one India-resident user is enough to trigger it. Enforcement by the Data Protection Board is expected late 2026. Fines reach ₹250 crore (~$30M USD) per failure. This guide covers who is in scope, what notice and consent require, data principal rights, Significant Data Fiduciary obligations, and the fine schedule.

Decision-support only. Not a legal opinion. For binding DPDPA interpretation, retain India-licensed privacy counsel.

1. Does DPDPA Apply to You?

DPDPA applies to processing of digital personal data of data principals within India. There is no minimum user count, no revenue threshold, and no requirement to have a local entity. Check each scenario:

US SaaS with a free tier accessible from India
B2B software sold to Indian companies processing user data on your platform
Marketing emails sent to India-based contacts
India CDN endpoint loading JS from a US server
Non-personal or fully anonymised data only
Processing data of non-India residents only
Data processing for personal or domestic purposes

2. Notice and Consent Requirements (Sections 5-7)

The consent framework under DPDPA is more prescriptive than GDPR. Section 5 mandates a specific notice structure; Section 6 defines valid consent; Section 7 enumerates the narrow categories of processing that can proceed without consent. The sequence is fixed: notice first, consent second.

Notice must precede consent

Section 5: notice must be given BEFORE seeking consent. Notice then consent — never the reverse.

Notice contents (Section 5)

Personal data to be collected; purpose of processing; how to withdraw consent and access/correct/erase data; contact details for Data Protection Officer (if applicable) or grievance mechanism.

Consent language

Section 6: free, specific, informed, unconditional, and unambiguous. A single affirmative act. No pre-ticked boxes. No consent bundled into terms of service.

Consent for each purpose

Processing for purposes beyond what was disclosed at consent is not permitted without fresh notice + consent. This matters for secondary analytics use cases.

Withdrawal mechanism

Must be as easy as giving consent. If consent is given by email, withdrawal cannot require a legal process. A single "withdraw consent" link is the minimum.

Legitimate uses without consent

Section 7 creates narrow exceptions: state functions, medical emergencies, public health, employment law obligations, court orders. These do not apply to typical SaaS products.

3. Data Principal Rights (Sections 11-14)

Right to access (Section 11)

Summary of personal data being processed and information about the entities to whom it was disclosed in the preceding 12 months. Must be provided on request.

Right to correction and erasure (Section 12)

Correct inaccurate or misleading personal data; update data that is out of date; erase data no longer necessary for the purpose it was collected for (subject to retention obligations under other laws).

Right to grievance redress (Section 13)

Each Data Fiduciary must have a grievance mechanism. Data principals can escalate to the Data Protection Board if the grievance is not resolved in a reasonable time.

Right to nominate (Section 14)

A data principal can nominate another individual to exercise their rights in the event of death or incapacity. This is unique to DPDPA — no equivalent in GDPR or CCPA.

4. Significant Data Fiduciary (SDF) — Section 10

The Data Protection Board may designate any Data Fiduciary as a "Significant Data Fiduciary" based on the following criteria. SDF designation brings four additional obligations on top of the standard framework:

Volume of personal data processed
Sensitivity of personal data (health, financial, children's data)
Risk to national security or public order
Risk to electoral democracy or fundamental rights
Potential impact on sovereignty, integrity, or security of India
Risk to individual data principals

Additional SDF obligations:

+
Data Protection Officer (DPO)

Must appoint a DPO based in India (or accessible from India). Contact details published. DPO must be a person, not just an email address.

+
Data Protection Impact Assessment

Periodic DPIAs on the processing that led to the SDF designation. Assessment must cover the risk to data principals and the mitigating measures in place.

+
Independent audit

Periodic independent audits of processing activities and compliance posture. Audit reports provided to Data Protection Board on request.

+
Data localisation (if notified)

Government may notify specific SDF categories for mandatory data localisation. Not yet in force for general SaaS — watch this space.

5. DPDPA Fine Schedule (Section 33)

BreachMax fine
Failure to safeguard personal data (data breach resulting from non-implementation of reasonable security)₹250 crore (~$30M USD)
Failure to notify Data Protection Board and affected data principals of a personal data breach₹200 crore (~$24M USD)
Breach of obligations applicable to Significant Data Fiduciaries₹150 crore (~$18M USD)
Failure to comply with data principal rights (access, correction, erasure, grievance, nomination)₹50 crore (~$6M USD)
Failure to observe obligations for processing children's data (no parental consent)₹200 crore (~$24M USD)

Get your DPDPA gap audit — $19 one-time

Section-by-section mapping of your current posture to DPDPA notice, consent, data principal rights, DPO appointment, and Significant Data Fiduciary criteria. Includes a DPO appointment letter template. PDF delivered within 24 hours.

Get DPDPA Gap Audit — $19 →

Contract Risk — $97

Review Your Data Processing Agreements for DPDPA in 60 Seconds

Data Processing Agreements with Indian vendors or covering Indian data subjects need new consent clauses, Data Principal rights provisions, breach notification timelines (72 hours to Data Protection Board), and cross-border transfer authorizations. BizLegal AI reviews your DPAs against DPDPA requirements and flags every missing provision.

Scan Your Data Processing Agreement →

Frequently asked questions

Does DPDPA apply to a US company with no employees in India?

Yes. Section 3 of the DPDPA applies to the processing of digital personal data of data principals within India — regardless of where the data fiduciary (you) is located. If any of your users are India-resident individuals, and you process their personal data in digital form, the DPDPA applies. There is no minimum number of Indian users, no revenue threshold, and no "substantial nexus to India" requirement.

When does DPDPA enforcement actually begin?

The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. The Data Protection Board and the implementing rules were finalized in 2025. Enforcement (including fines) is expected to begin in late 2026 once the Board is fully operational. This timeline is consistent with government statements, but no exact date has been gazette-notified as of July 2025.

What is the difference between a Data Fiduciary and a Data Processor under DPDPA?

A Data Fiduciary determines the purpose and means of processing personal data — that is you (the SaaS company) when you collect and use customer data for your product. A Data Processor processes personal data on behalf of a Data Fiduciary — that is your subprocessors (AWS, Stripe, Intercom, etc.) when they handle customer data under your instructions. The primary obligations under DPDPA rest with the Data Fiduciary. Processors have limited obligations set by contract.

How is DPDPA consent different from GDPR consent?

Both require specific, informed, unambiguous consent for processing beyond legitimate use. Key DPDPA differences: (1) DPDPA requires notice first, consent second — in strict sequence; (2) DPDPA requires a "right to nominate" (unique to India); (3) GDPR has 6 lawful bases; DPDPA has consent plus narrow legitimate-use exemptions in Section 7 (state functions, emergencies, employment law) — there is no "legitimate interests" basis in DPDPA. For most B2B SaaS, DPDPA essentially requires consent for everything that GDPR might rely on legitimate interests for.

My product is B2B — do I still need to worry about data principal rights?

Yes. Even in B2B SaaS, if you process personal data of your customers' employees (names, emails, usage logs), those individuals are data principals with rights under DPDPA. Your enterprise customer (the direct business) is also a data principal if they are a sole trader or partnership. You need a mechanism for data principals to exercise their access, correction, erasure, and grievance rights — not just for individual consumers.

Related compliance resources

India DPDPA Compliance Hub →GDPR Compliance Checklist →Privacy Policy Auto-Refresh →Compliance Health Score →All Compliance Guides →