AstraLex Insights — Issue 3

Your SaaS Stack Is a Compliance Surface Now

Every SaaS tool your business uses touches customer or employee data somewhere in its pipeline. Under the DPDP Act, that makes your vendor list part of your compliance surface — this issue is about auditing it properly.

Regulatory Watch

Enforcement guidance under the DPDP Act continues to clarify the Data Fiduciary's obligations when a breach occurs at a third-party processor. Early indications suggest primary accountability will sit with the entity that decided to use the vendor — reinforcing why data processing terms in vendor contracts matter now, not once rules are finalised.

Featured Read

Data Processing Agreements Under the DPDP Act: A Practical Checklist for SaaS Buyers →

Six specific things to verify in any SaaS vendor contract — purpose limitation, breach notification timelines, sub-processor flow-down, audit rights, data localisation, and deletion on termination.

The 60-Second Tip

Ask your top three SaaS vendors (by data sensitivity, not spend) whether they have a standard Data Processing Addendum (DPA) available. Most established vendors do — requesting it costs you nothing and immediately tells you how seriously they take the obligation.

Ask AstraLex

Q: We use dozens of small SaaS tools — do we need to audit all of them?

Prioritise by data sensitivity, not tool count. Start with anything touching customer PII, payment data, or employee records, and work outward from there. A tool that only stores your marketing calendar doesn't need the same scrutiny as your CRM or HRMS.

Have a question for a future issue?

Send Us Your Question →
RS
Written by RS

20+ years in commercial & corporate practice — in-house at BT, Oracle and Dell before founding AstraLex.