The Complete Compliance Checklist for IT and SaaS Startups in India
A practical compliance checklist for Indian IT and SaaS startups covering DPDP, labour laws, POSH, GST and company law essentials for 2026.
IT and SaaS startups in India face a compliance profile that looks different from a traditional SME - lighter on premises and heavier on data protection, contracts, and company law, alongside the same core labour obligations every employer eventually hits.
Key facts at a glance
- DPDP's full substantive obligations - notice, consent, security safeguards, breach reporting, data-principal rights - become enforceable from 13 May 2027.
- The DPDP Consent Manager registration framework becomes operational on 13 November 2026.
- Penalties for failing to implement reasonable security safeguards under DPDP can reach up to Rs 250 crore per instance.
- EPF becomes mandatory at 20 or more employees; ESI at 10 or more employees (wage ceilings Rs 15,000 and Rs 21,000/month respectively).
- A POSH Internal Committee is mandatory once a startup crosses 10 employees.
- CERT-In cybersecurity incident reporting directions generally expect qualifying incidents to be reported within 6 hours of detection.
Company law and business registration basics
Most SaaS startups incorporate as a Private Limited Company under the Companies Act, which brings recurring compliance: annual financial statement filing, annual return filing, board meeting cadence, and statutory registers - all administered through the MCA portal. Missing these filings triggers escalating penalties and can affect fundraising due diligence, since investors routinely check MCA filing history before closing a round.
Startups should also register under the applicable state Shops and Establishments Act even for a purely office-based, non-manufacturing business - this is often overlooked because it feels more relevant to retail or hospitality, but it applies to any commercial establishment with employees.
DPDP: the sector's defining compliance area
For a SaaS company, DPDP Act 2023 compliance is not a side item - it is often core to the product itself, especially if the platform processes customer data, employee data of B2B clients, or end-user data at scale. Key preparation areas ahead of the 13 May 2027 enforcement date include:
- Clear, specific notice and consent flows before collecting personal data.
- Data minimisation - collecting only what is needed for the stated purpose.
- Security safeguards proportionate to the sensitivity of data handled, given the steep penalty exposure for failures here.
- A documented breach notification process to both the Data Protection Board and affected individuals.
- Honouring data-principal rights - access, correction, erasure, and grievance redressal.
Startups that process data on behalf of other businesses (as a data processor) should also review their contracts to ensure obligations flow correctly between fiduciary and processor.
Labour compliance as headcount scales
| Requirement | Threshold | Key detail |
|---|---|---|
| EPF | 20+ employees | Rs 15,000 wage ceiling; 12% + 12% contribution |
| ESI | 10+ employees | Rs 21,000 wage ceiling; 0.75% employee, 3.25% employer |
| POSH Internal Committee | 10+ employees | Mandatory; recommended earlier as good practice |
| Shops & Establishments | Applies from day one | Registration and display requirement |
Startups also frequently issue ESOPs, work with remote and hybrid teams across states, and engage contractors and consultants - the classification between employee and independent contractor affects PF/ESI applicability and should be handled deliberately rather than by default, since misclassification is a common gap found during due diligence.
Cybersecurity and CERT-In obligations
Separate from DPDP, entities covered under CERT-In's cybersecurity directions are expected to report specified categories of security incidents - such as data breaches, unauthorised access, or ransomware - within a tight window, generally cited as 6 hours of detection. SaaS companies should not treat this as a paperwork exercise; it requires an actual incident response runbook that can be executed under pressure, not just a policy document.
GST and tax on services
GST registration is generally required once turnover crosses the applicable threshold, and SaaS revenue - whether domestic subscriptions or export contracts - needs to be classified and invoiced correctly. Export of services to overseas customers can be a zero-rated supply, but this usually requires filing a Letter of Undertaking and meeting conditions around payment receipt in convertible foreign exchange; getting this wrong can mean unnecessary GST outflow or refund friction later.
Bringing it together
A SaaS startup's compliance risk concentrates in three areas: data protection (DPDP), company law filings (MCA), and labour law once the team scales past 10-20 people. Because DPDP enforcement dates are fixed and known well in advance, this is one of the few areas where a startup can plan a compliance roadmap on a calendar rather than reacting to a surprise inspection.
If you are not sure where your SaaS company stands on data protection compliance, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Electronics and Information Technology (DPDP Act and Rules) - meity.gov.in
- Indian Computer Emergency Response Team (CERT-In) - cert-in.org.in
- Ministry of Corporate Affairs - mca.gov.in
- Employees' Provident Fund Organisation (EPFO) - epfindia.gov.in
- Employees' State Insurance Corporation (ESIC) - esic.gov.in
- GST portal - gst.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- When do DPDP obligations become enforceable for a SaaS company?
- The Data Protection Board provisions are already in effect, the Consent Manager registration framework becomes operational on 13 November 2026, and full substantive obligations - notice, consent, security safeguards, breach reporting, data-principal rights - become enforceable from 13 May 2027.
- Does a small SaaS startup with under 10 employees need to worry about POSH?
- The Internal Committee requirement only becomes mandatory at 10 or more employees, but the underlying prohibition on workplace harassment applies regardless of size, so many early-stage startups adopt a policy voluntarily ahead of the threshold.
- Is EPF mandatory for a 15-person startup?
- No, EPF registration becomes mandatory once a company reaches 20 or more employees; below that, it is optional but some startups register voluntarily to offer the benefit and standardise payroll early.
- Does a SaaS company need GST registration if it sells only to customers outside India?
- Export of services can qualify as a zero-rated supply under GST, but registration is still generally required once turnover crosses the applicable threshold, and export transactions still need to be reported and often require a Letter of Undertaking to avoid upfront tax payment.
- What is a Consent Manager under DPDP and does a startup need to become one?
- A Consent Manager is a registered entity that helps individuals manage and withdraw consent for data processing across multiple platforms; most SaaS startups will interact with Consent Managers as data fiduciaries rather than register as one themselves, unless that is their specific business model.
- Does CERT-In incident reporting apply to SaaS companies?
- Yes, entities covered under CERT-In's cybersecurity incident reporting directions are generally expected to report qualifying incidents within 6 hours of detection - SaaS companies handling customer or user data should have an incident response process that can meet this timeline.
Check your status
DPDP Gap Assessment
A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.