Data Shared with Overseas SaaS Vendor: DPDP Processor, Security and Contract Checklist
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
2-minute summary
- Sending Indian customer data to an overseas SaaS vendor is not merely an IT procurement question; it needs processor, security, sub-processor and cross-border governance.
- The final DPDP Rules and commencement notification create a transition period, but businesses should not postpone vendor mapping until May 2027.
- Contract language should identify processing instructions and deletion/return, while architecture should minimise what leaves the Indian business.
Current position
Control and evidence map
| # | Control / evidence requirement | |
|---|---|---|
| 1 | Record vendor legal entity, hosting regions, support-access countries and material sub-processors. | |
| 2 | Classify the data actually exported, including logs, attachments, backups and support dumps. | |
| 3 | Put documented instructions, confidentiality, security, breach cooperation and deletion/return in the contract. | |
| 4 | Maintain an exit plan that can export business data and delete vendor copies within a testable period. | |
| 5 | Monitor any Central Government transfer restriction before changing hosting or support locations. | |
Worked example
An Indian SaaS company stores customer tickets in Singapore while vendor support staff in three countries can access them. The cross-border map must therefore capture both storage and remote access. The company should know which personal fields are present, who the sub-processors are and how it will remove data when a customer account closes.
Common mistakes
- Equating “cloud region India” with zero overseas access.
- Failing to list vendor sub-processors.
- Saying DPDP imposes universal data localisation.
- Leaving deletion obligations to a generic “commercially reasonable” clause.
Frequently asked questions
Does DPDP impose blanket localisation?
No; the Act uses a government-restriction mechanism for transfers.
Are most substantive duties already live?
Not yet on 5 October 2026.
What should the vendor register capture?
Entities, regions, access countries, sub-processors, data types and deletion commitments.
Why act now?
Contract and architecture changes take time before the main commencement date.
Official sources
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Act, 2023 (Act 22 of 2023; 2023-08-11)
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E); 2025-11-13)
- Ministry of Electronics and Information Technology - DPDP Act commencement notification (G.S.R. 843(E); 2025-11-13)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.