Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Industry guide

DPDP for SaaS

SaaS companies usually sit on both sides of the framework: Data Fiduciary for their own users and Data Processor for customer data. The distinction decides which duties are yours directly.

What does the DPDP framework mean for SaaS?

SaaS companies usually sit on both sides at once: Data Fiduciary for their own users, Data Processor for customer data. Work out which role applies to each data flow first, because that decides which duties are yours directly. Then the processor contract terms, then breach duties across the chain.

How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.

Where the framework usually bites first

  • Know your role per data flowSection 2, official text →

    Your marketing site users and your customers' end users put you in different roles with different duties. The roles are defined in the Act.

  • Processor contract termsRule 6, official text →

    Safeguard obligations reach processing done on a fiduciary's behalf, which shows up in your customer contracts.

  • Breach duties across the chainRule 7, official text →

    A breach at a processor triggers fiduciary duties upstream; contracts should say who does what within the clocks.

Tools for this sector

Guides written for this audience