Every SaaS tool your business uses touches customer or employee data somewhere in its pipeline. Under the DPDP Act, that makes your vendor list part of your compliance surface — this issue is about auditing it properly.
Enforcement guidance under the DPDP Act continues to clarify the Data Fiduciary's obligations when a breach occurs at a third-party processor. Early indications suggest primary accountability will sit with the entity that decided to use the vendor — reinforcing why data processing terms in vendor contracts matter now, not once rules are finalised.
Data Processing Agreements Under the DPDP Act: A Practical Checklist for SaaS Buyers →
Six specific things to verify in any SaaS vendor contract — purpose limitation, breach notification timelines, sub-processor flow-down, audit rights, data localisation, and deletion on termination.
Ask your top three SaaS vendors (by data sensitivity, not spend) whether they have a standard Data Processing Addendum (DPA) available. Most established vendors do — requesting it costs you nothing and immediately tells you how seriously they take the obligation.
Q: We use dozens of small SaaS tools — do we need to audit all of them?
Prioritise by data sensitivity, not tool count. Start with anything touching customer PII, payment data, or employee records, and work outward from there. A tool that only stores your marketing calendar doesn't need the same scrutiny as your CRM or HRMS.
Have a question for a future issue?
Send Us Your Question →20+ years in commercial & corporate practice — in-house at BT, Oracle and Dell before founding AstraLex.