The Complete Compliance Checklist for IT and SaaS Startups in India

A practical compliance checklist for Indian IT and SaaS startups covering DPDP, labour laws, POSH, GST and company law essentials for 2026.

ComplianceCheck Team·Published 10 July 2026

IT and SaaS startups in India face a compliance profile that looks different from a traditional SME - lighter on premises and heavier on data protection, contracts, and company law, alongside the same core labour obligations every employer eventually hits.

Key facts at a glance

  • DPDP's full substantive obligations - notice, consent, security safeguards, breach reporting, data-principal rights - become enforceable from 13 May 2027.
  • The DPDP Consent Manager registration framework becomes operational on 13 November 2026.
  • Penalties for failing to implement reasonable security safeguards under DPDP can reach up to Rs 250 crore per instance.
  • EPF becomes mandatory at 20 or more employees; ESI at 10 or more employees (wage ceilings Rs 15,000 and Rs 21,000/month respectively).
  • A POSH Internal Committee is mandatory once a startup crosses 10 employees.
  • CERT-In cybersecurity incident reporting directions generally expect qualifying incidents to be reported within 6 hours of detection.

Company law and business registration basics

Most SaaS startups incorporate as a Private Limited Company under the Companies Act, which brings recurring compliance: annual financial statement filing, annual return filing, board meeting cadence, and statutory registers - all administered through the MCA portal. Missing these filings triggers escalating penalties and can affect fundraising due diligence, since investors routinely check MCA filing history before closing a round.

Startups should also register under the applicable state Shops and Establishments Act even for a purely office-based, non-manufacturing business - this is often overlooked because it feels more relevant to retail or hospitality, but it applies to any commercial establishment with employees.

DPDP: the sector's defining compliance area

For a SaaS company, DPDP Act 2023 compliance is not a side item - it is often core to the product itself, especially if the platform processes customer data, employee data of B2B clients, or end-user data at scale. Key preparation areas ahead of the 13 May 2027 enforcement date include:

  • Clear, specific notice and consent flows before collecting personal data.
  • Data minimisation - collecting only what is needed for the stated purpose.
  • Security safeguards proportionate to the sensitivity of data handled, given the steep penalty exposure for failures here.
  • A documented breach notification process to both the Data Protection Board and affected individuals.
  • Honouring data-principal rights - access, correction, erasure, and grievance redressal.

Startups that process data on behalf of other businesses (as a data processor) should also review their contracts to ensure obligations flow correctly between fiduciary and processor.

Labour compliance as headcount scales

RequirementThresholdKey detail
EPF20+ employeesRs 15,000 wage ceiling; 12% + 12% contribution
ESI10+ employeesRs 21,000 wage ceiling; 0.75% employee, 3.25% employer
POSH Internal Committee10+ employeesMandatory; recommended earlier as good practice
Shops & EstablishmentsApplies from day oneRegistration and display requirement

Startups also frequently issue ESOPs, work with remote and hybrid teams across states, and engage contractors and consultants - the classification between employee and independent contractor affects PF/ESI applicability and should be handled deliberately rather than by default, since misclassification is a common gap found during due diligence.

Cybersecurity and CERT-In obligations

Separate from DPDP, entities covered under CERT-In's cybersecurity directions are expected to report specified categories of security incidents - such as data breaches, unauthorised access, or ransomware - within a tight window, generally cited as 6 hours of detection. SaaS companies should not treat this as a paperwork exercise; it requires an actual incident response runbook that can be executed under pressure, not just a policy document.

GST and tax on services

GST registration is generally required once turnover crosses the applicable threshold, and SaaS revenue - whether domestic subscriptions or export contracts - needs to be classified and invoiced correctly. Export of services to overseas customers can be a zero-rated supply, but this usually requires filing a Letter of Undertaking and meeting conditions around payment receipt in convertible foreign exchange; getting this wrong can mean unnecessary GST outflow or refund friction later.

Bringing it together

A SaaS startup's compliance risk concentrates in three areas: data protection (DPDP), company law filings (MCA), and labour law once the team scales past 10-20 people. Because DPDP enforcement dates are fixed and known well in advance, this is one of the few areas where a startup can plan a compliance roadmap on a calendar rather than reacting to a surprise inspection.

If you are not sure where your SaaS company stands on data protection compliance, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.

Sources

  • Ministry of Electronics and Information Technology (DPDP Act and Rules) - meity.gov.in
  • Indian Computer Emergency Response Team (CERT-In) - cert-in.org.in
  • Ministry of Corporate Affairs - mca.gov.in
  • Employees' Provident Fund Organisation (EPFO) - epfindia.gov.in
  • Employees' State Insurance Corporation (ESIC) - esic.gov.in
  • GST portal - gst.gov.in

This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.

Frequently Asked Questions

When do DPDP obligations become enforceable for a SaaS company?
The Data Protection Board provisions are already in effect, the Consent Manager registration framework becomes operational on 13 November 2026, and full substantive obligations - notice, consent, security safeguards, breach reporting, data-principal rights - become enforceable from 13 May 2027.
Does a small SaaS startup with under 10 employees need to worry about POSH?
The Internal Committee requirement only becomes mandatory at 10 or more employees, but the underlying prohibition on workplace harassment applies regardless of size, so many early-stage startups adopt a policy voluntarily ahead of the threshold.
Is EPF mandatory for a 15-person startup?
No, EPF registration becomes mandatory once a company reaches 20 or more employees; below that, it is optional but some startups register voluntarily to offer the benefit and standardise payroll early.
Does a SaaS company need GST registration if it sells only to customers outside India?
Export of services can qualify as a zero-rated supply under GST, but registration is still generally required once turnover crosses the applicable threshold, and export transactions still need to be reported and often require a Letter of Undertaking to avoid upfront tax payment.
What is a Consent Manager under DPDP and does a startup need to become one?
A Consent Manager is a registered entity that helps individuals manage and withdraw consent for data processing across multiple platforms; most SaaS startups will interact with Consent Managers as data fiduciaries rather than register as one themselves, unless that is their specific business model.
Does CERT-In incident reporting apply to SaaS companies?
Yes, entities covered under CERT-In's cybersecurity incident reporting directions are generally expected to report qualifying incidents within 6 hours of detection - SaaS companies handling customer or user data should have an incident response process that can meet this timeline.

Check your status

DPDP Gap Assessment

A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.

Start free assessment →From ₹2,499 · no subscription
Share:LinkedInXWhatsApp