KaryaFlow
Back to blog

DPDP: what to ask your SaaS vendors

Kirtesh Sharma8 min read

This is a practical guide to vendor diligence, not legal advice. Get your own counsel before making compliance decisions.

India's Digital Personal Data Protection Rules were notified on 14 November 2025, giving the Digital Personal Data Protection Act, 2023 its operational detail. The Rules phase in: the Data Protection Board came into being immediately, Consent Manager registration follows at the twelve-month mark, and the core obligations most businesses care about — consent notices, purpose limitation, retention and erasure, children's data, security safeguards — land at eighteen months, in May 2027.

If you are reading this in August 2026, that is roughly nine months away. Long enough to do it properly. Not long enough to start in the last quarter.

The part that catches people out

You are the Data Fiduciary. Your CRM vendor, your helpdesk, your marketing tool and your analytics stack are processing personal data on your instructions — but the obligation to the individual sits with you. When a customer asks you to delete their data, "our vendor doesn't support that" is not an answer that helps you.

Penalties under the Act run to significant sums — reporting on the framework puts the ceiling at ₹250 crore per breach depending on severity. The exact exposure will depend on facts and on how the Board enforces, which nobody can tell you yet. The practical point stands regardless: this is not a rounding error, and it is not your vendor's problem.

Eight questions to put to every vendor

Send these before you renew, not after. A vendor who cannot answer them in writing is telling you something.

  1. Deletion. If a person asks to be erased, can you delete every record relating to them, and how long does it take? Ask for the mechanism, not a yes.
  2. Consent records. Can you show what a specific person consented to, when, and through which notice? Consent you cannot evidence is consent you did not get.
  3. Retention. Can you enforce a retention rule automatically, including on inactive records, rather than leaving it to somebody remembering?
  4. Breach notification. How fast will you tell us, in contract? You need to notify the Board within 72 hours, so a vendor who takes a week has already spent your budget.
  5. Logs. How long are access logs retained, and can we get them? Reporting on the Rules points to a one-year log retention expectation.
  6. Children's data. If under-18s are in scope for you, can the vendor support verifiable parental consent? For most B2B tools the honest answer is no, which may be fine — but find out.
  7. Sub-processors. Who else touches the data, where do they sit, and how do we hear when that list changes?
  8. Cross-border. Which countries is our data processed in, and can we constrain that? Transfer rules are part of the phase landing at twelve months.

Why a fragmented stack makes this harder

Run those eight questions across nine separate tools and you get nine different answers, nine contracts, and nine deletion mechanisms that do not agree with each other. The individual asking to be erased does not care that their record exists in three systems — but you have to find all three, and prove you did.

This is the least glamorous argument for consolidation and one of the strongest. One data model means one deletion, one consent record, one retention rule, one log. It does not make you compliant on its own. Nothing does. It changes the work from a reconciliation problem into a configuration one.

We are an Indian company, headquartered in Jaipur, so this is our home regulation rather than an export requirement. What we ship today — encryption, retention controls, an immutable audit log, deletion on request — is listed on our security and compliance page, including the certifications we do not yet hold. Ask us the eight questions too, and hold us to the same standard as everyone else.

Where to check this yourself

Dates and obligations here are drawn from the Rules as reported by India Briefing and the published summary of the Rules, checked 8 August 2026. Sources differ by a day on the exact eighteen-month date, so confirm the precise deadline and your own obligations against the Gazette text and your counsel rather than against a vendor's blog — including this one.