📄 Article
✓ Link checked
India
Free
Intermediate
If you sell into Indian enterprises, DPDP is now part of the security review alongside SOC 2. This lays out the obligations that show up in a buyer's DPA: consent, breach notification to the Data Protection Board, deletion rights and cross border transfer limits.
What SaaS Providers Need to Know About India's Digital Personal Data Protection Act 2023
From Wattlecorp Cybersecurity Labs by Irshad Rafeekhudheen PK 16 min read
- Penalties run up to Rs 250 crore for failing to implement reasonable security safeguards.
- A SaaS platform serving Indian users is a data fiduciary, accountable for what it collects, processes and stores.
- Consent must be clear, informed and purpose specific, and children under 18 need verifiable parental consent.
- Breaches must be reported to the Data Protection Board of India and to affected users, and cross border transfers are limited to government approved territories.