The Indian SaaS stack is not the American SaaS stack. When a US compliance tool lists its integrations — Workday, Salesforce, AWS, Okta, ServiceNow — it is describing the infrastructure of a Fortune 500 company. It is not describing the infrastructure of a 200-person Bengaluru startup running payroll on Keka, CRM on Zoho, and customer support on Freshdesk. The gap matters enormously for DPDP compliance.
Where Indian companies actually hold personal data
- Keka HR: Used by over 6,500 Indian companies for HRMS. Holds: Aadhaar numbers, PAN cards, bank account details, salary structures, biometric attendance data, performance reviews, Form 16 data. One of the densest concentrations of sensitive personal data in the Indian SMB ecosystem.
- Zoho People / Zoho CRM: Zoho's suite spans HRMS, CRM, and finance across millions of Indian business users. Zoho People holds employee personal data; Zoho CRM holds customer contact data, communication history, and deal data that often includes sensitive financial information.
- Razorpay: Processes payments for 85% of Indian internet startups. Holds: bank account numbers, UPI IDs, PAN cards, and transaction histories linked to individual data principals. Under DPDP, this is financial personal data with the highest sensitivity classification.
- Freshdesk / Freshworks: Customer support platform used widely in Indian B2B SaaS. Support tickets frequently contain personal data — health information shared for a healthtech issue, financial details shared for a fintech problem, identity documents shared for KYC issues.
- DigiLocker / KYC APIs: KYC workflows for Indian startups typically involve Aadhaar-based verification via APIs that pull government identity data. This creates a direct processing relationship with the most sensitive category of personal data under DPDP.
The data residency dimension
DPDP does not impose blanket data localisation (unlike the earlier draft that caused significant concern). However, for specific categories of personal data — government-designated sensitive data — cross-border transfer restrictions apply. The government retains the power to notify countries with which data transfers are permitted (a whitelist model).
This matters for SaaS companies using US-hosted tools to store Indian personal data. If a company stores Aadhaar copies on AWS US-East, that may create a cross-border transfer question depending on how DPDP's transfer provisions are finally notified. Companies using Indian-hosted SaaS (Zoho's Indian data centres, AWS Mumbai, Azure Pune) have a cleaner position.
Zoho famously operates all its products from its own infrastructure, with data centres in India. For Indian companies that are concerned about DPDP cross-border transfer requirements, Zoho's India-hosted products represent a lower-complexity compliance position than equivalent US-hosted alternatives.
What integration depth means for compliance
A compliance tool that cannot read your Keka data cannot tell you whether your employee Aadhaar numbers are adequately protected. A tool that cannot connect to Razorpay cannot assess the personal data risk in your payment processing. Integration depth is not a nice-to-have feature — it is the difference between a compliance tool that knows your actual exposure and one that describes a generic risk landscape.
The current state of the Indian compliance tooling market is that most tools offer PostgreSQL and AWS integration — covering the underlying infrastructure but not the application layer where most personal data actually lives. The application-layer integrations (Keka, Zoho, Razorpay, Freshdesk) are where the high-density personal data is, and where most tools have no coverage.
The integration roadmap for DPDP readiness
- 1Phase 1 (now): Direct database connections (PostgreSQL, MySQL) and cloud storage (S3, GCS, Azure Blob). This covers the infrastructure layer and provides the baseline inventory.
- 2Phase 2 (near-term): HRMS integrations — Keka, Zoho People, Darwinbox. This covers the highest-density personal data in the Indian SMB ecosystem.
- 3Phase 3: Business SaaS — Zoho CRM, Freshdesk, Razorpay, Jira. This covers the application layer where customer and transaction data lives.
- 4Phase 4: Sector-specific — Healthtech platforms (Practo, HealthPlix), Fintech core systems, EdTech LMS platforms.
The vCISO opportunity
Fractional CISOs managing DPDP compliance for multiple Indian startups need a tool that understands the Indian SaaS stack. A vCISO running compliance for five clients — three on Keka, two on Zoho People, all on Razorpay — needs one platform that can connect to all of them, aggregate findings across clients, and generate per-client Proof Packs.
This use case — the vCISO managing multiple tenants — is one of the highest-leverage deployment patterns for DPDP tooling in India. One vCISO with the right platform can bring 10 startups to defensible DPDP posture in the time it would previously have taken to do one.
Takeaway
DPDP compliance in India requires understanding where personal data actually lives in Indian companies — not where it lives in a Silicon Valley startup. The tools that will win in the Indian market are the ones that can connect to Keka and Zoho and Razorpay, not just to Workday and Salesforce. That is the integration challenge. It is also the market opportunity.