Skip to main content
Finin2minCurrent Action Brief · 13 Aug 2026
DPDP, Privacy & AI GovernanceUpdated 5 October 2026

Data Shared with Overseas SaaS Vendor: DPDP Processor, Security and Contract Checklist

By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026

2-minute summary

Current position

The DPDP Act allows the Central Government to restrict transfers to specified countries/territories under the statutory framework; the substantive processing provisions are on staggered commencement. On 5 October 2026, businesses should distinguish what is already in force from future obligations and build a source-controlled vendor register rather than claiming an unrestricted or blanket localisation rule.

Control and evidence map

#Control / evidence requirement
1Record vendor legal entity, hosting regions, support-access countries and material sub-processors.
2Classify the data actually exported, including logs, attachments, backups and support dumps.
3Put documented instructions, confidentiality, security, breach cooperation and deletion/return in the contract.
4Maintain an exit plan that can export business data and delete vendor copies within a testable period.
5Monitor any Central Government transfer restriction before changing hosting or support locations.

Worked example

An Indian SaaS company stores customer tickets in Singapore while vendor support staff in three countries can access them. The cross-border map must therefore capture both storage and remote access. The company should know which personal fields are present, who the sub-processors are and how it will remove data when a customer account closes.

Common mistakes

  1. Equating “cloud region India” with zero overseas access.
  2. Failing to list vendor sub-processors.
  3. Saying DPDP imposes universal data localisation.
  4. Leaving deletion obligations to a generic “commercially reasonable” clause.

Frequently asked questions

Does DPDP impose blanket localisation?

No; the Act uses a government-restriction mechanism for transfers.

Are most substantive duties already live?

Not yet on 5 October 2026.

What should the vendor register capture?

Entities, regions, access countries, sub-processors, data types and deletion commitments.

Why act now?

Contract and architecture changes take time before the main commencement date.

Official sources

Disclaimer: Educational and informational content only. Apply the current law, instrument, policy/contract and facts before acting; obtain professional advice for material or disputed matters.

Disclaimer

Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.

Educational and professional reference only — not financial, tax or legal advice. Verify the current official position from the primary source before relying on any figure, rate, provision or deadline.