ConsentKit DPDP

For SaaS products, IT services and software agencies

DPDP compliance for SaaS and IT services

You are a data processor for your customers’ data and a data fiduciary for your own users and leads. Enterprise buyers will ask for DPDP answers in every security review from now on. ConsentKit helps with both roles, and gives your customers consent tooling they can switch on inside your product.

Your role
Processor and fiduciary
Customer security reviews
Now include DPDP
Full compliance
13 May 2027
app.fieldbook.ioStart free trial

Fieldbook asks for your consent

Choose how we may use your details. You can change this anytime.

Withdraw consent anytime
Consent logRecording

    Where the DPDP Act touches a SaaS business

    The same company holds data in two roles. Pick an area to see which role applies and what it asks of you.

    What changes for SaaS on 13 May 2027

    Processors have fewer direct duties under the DPDP Act, but your customers will pass theirs on to you by contract.

    Know which role you are inSections 2 and 8

    For your own users and leads you are a fiduciary. For your customers’ data you are a processor acting on their instructions.

    A data map that tags each dataset as fiduciary or processor data.

    DPAs with every customerSection 8(2)

    Fiduciaries may only use processors under a valid contract. Expect every enterprise customer to ask for DPDP terms.

    A DPDP-ready DPA template and a sub-processor list page.

    Security safeguards customers will auditSection 8(5) and Rule 6

    Encryption, access control, monitoring, backups and logs kept for at least a year.

    Access logging and evidence exports for security questionnaires.

    Help customers hit the 72-hour clockRule 7

    Your customers must report breaches within 72 hours, so they need to hear from you much faster.

    An incident workflow that notifies affected customers with the details they need.

    Consent tooling inside your productSections 5 and 6

    Customers collecting data through your product need notices and consent there too.

    Embed ConsentKit through our API so your customers can switch it on.

    Cross-border transfers are allowed, with limitsSection 16

    Transfers abroad are permitted except to countries the government restricts. Keep track of where data lives.

    A hosting and transfer register for customer reviews.

    A plan for product and security teams

    Security reviews already ask about DPDP. Get your paperwork ready first, then the product.

    1. Data map and roles

      Tag every dataset as fiduciary or processor data and list sub-processors.

    2. Contracts and trust page

      Publish a DPA, sub-processor list and security overview.

    3. Product changes

      Consent on sign-up, in-app deletion, and consent tooling for customers.

    4. Incident readiness

      Set customer breach notice timelines and rehearse.

    For every kind of software business

    Templates for your model.

    B2B SaaS

    Enterprise customers and security reviews.

    B2C apps

    You are the fiduciary for your users.

    IT services and outsourcing

    Processor for many clients.

    Web and app agencies

    Building consent into client projects.

    Hosting and cloud providers

    Infrastructure processors.

    AI products

    Training data and customer data limits.

    Questions SaaS teams are asking

    For the full picture, read our DPDP Act guide or compliance checklist.

    Are we a data fiduciary or a processor?

    Usually both. You are a fiduciary for your own users, leads and staff, and a processor for data your customers put into your product.

    Do processors have direct duties under the Act?

    Most duties sit with fiduciaries, but fiduciaries must use processors only under a contract and remain responsible for them, so customers will pass requirements on to you.

    Can we store Indian customers’ data abroad?

    Yes, except in countries the government restricts by notification. Sector rules, such as RBI’s for payments data, may still require local storage.

    Can we use customer data to train our AI models?

    Not as a processor acting on customer instructions, unless the customer agrees and has a lawful basis for it.

    Can we offer ConsentKit to our own customers?

    Yes. Our API lets you embed consent notices and records in your product. Talk to us about partner pricing.

    Be ready for your next security review

    The readiness check takes about ten minutes and gives you a gap report for SaaS and IT businesses.