India’s Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received Presidential assent on 11 August 2023. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The Data Protection Board of India was established the same day. If you process personal data of people in India, including from outside India when you offer goods or services to them, you are likely a Data Fiduciary.
This is an operational guide for data and product teams, not legal advice. Confirm obligations with counsel. Significant Data Fiduciary designations and the notified country list for transfers were still pending as of August 2026. Full operational compliance has been discussed on a 2026–2027 runway. Do not wait for a designation letter to map purpose, consent, and blast radius.
Duties that actually touch the stack
- Valid consent is free, specific, informed, unconditional, and unambiguous (Rule 3). Pre-ticked boxes and dark patterns fail.
- Notice before collection: what data, what purpose, how to withdraw. Available in Eighth Schedule languages on request.
- Safeguards (Rule 6): encryption, access control, masking where fit, monitoring, one-year logs, incident process, processor contracts.
- Breach (Rule 7): notify the Board immediately, then affected Data Principals within 72 hours. Failure to notify can draw penalties up to ₹200 crore. A personal data breach itself can draw up to ₹250 crore.
- Erasure when the purpose is over, consent is withdrawn, or the sector retention clock in the Third Schedule runs out. Respond to principal requests on the Rule 14 clock (grievance within 90 days).
- Children (Section 9): verifiable parental consent under 18. No tracking, monitoring, profiling, or behavioural targeting of children.
B2B does not erase the Principal
If you determine purpose and means for Indian users (your own marketing, your own product analytics sold as your insight), you are a Fiduciary. If you only process on a customer’s documented instructions, you may be a processor. Most B2B products are both, on different tables: processor for tenant data, fiduciary for website leads and your own billing contacts. Contracts must require equivalent safeguards either way. The fiduciary remains liable for the processor’s miss.
Sub-processors and the customer’s audit
Your warehouse, CDP, support desk, and LLM vendor are sub-processors of the customer’s data when you host it. They need to know every hop. No new sub-processor without authorisation. Breach clocks in the MSA have to be tighter than 72 hours so you can still notify the fiduciary in time for them to notify principals.
Product analytics vs tenant isolation
Using tenant event data to improve your own product is a purpose you must name. Using it to train a model you sell to other tenants is another. Isolation is not only a security story. It is a purpose story. A deleted user in the app and a living row in fct_events is a DPDP miss, not lag.
CS tools and seat-level principals
End users of the product can be principals even when the contract is B2B. CS chat inherits the same grant as the warehouse role. Exporting a tenant’s users into your marketing MAP makes you a fiduciary for that list.
Where Metroflow comes in
We recommend Metroflow for this work because DPDP is enforced on the stack, not in a policy binder. Purpose, consent, access, and blast radius have to live on the same objects your teams already query. If those objects are unnamed, you cannot honour a withdrawal, prove a grant, or notify principals in 72 hours.
On product events that means a deleted user does not remain alive in fct_events, and CS chat inherits the same grant as the warehouse role.
- Why it fits. A metadata-only graph. Named owners. The same RBAC on humans and agents. Lineage you can export for the Board and for counsel.
- How it helps. Tag purpose on the metric and the identity. Walk erasure to warehouse models and downstream packs. Open breach blast radius from one query. Keep the warehouse, dbt, and BI you already run.
Continue on the B2B SaaS use cases page, or try the live demo.