The confidentiality clause in a SaaS agreement under India law
Confidentiality clause in Indian SaaS agreements: legal requirements under ITA 2000, DPDP 2023, enforceability, and best-practice drafting.
Standard Position
In Indian SaaS agreements, the confidentiality clause typically imposes mutual obligations on both the vendor and customer to protect sensitive information. The vendor must safeguard customer data and business information; the customer must protect the vendor's proprietary software, trade secrets, and pricing terms. Standard market practice includes a term matching the agreement duration plus 2 to 3 years post-termination. Most clauses exempt publicly available information, information received from third parties without confidentiality obligations, and information independently developed. A key distinction in India is explicit recognition that confidential information may include personal data governed by the Information Technology Act, 2000 and now the Digital Personal Data Protection Act, 2023.
Legal Basis
Confidentiality obligations in India are enforceable under Section 27 of the Indian Contract Act, 1872 (restraint of trade must be reasonable), and Section 43A of the Information Technology Act, 2000 (compensation for negligence in data handling). The Digital Personal Data Protection Act, 2023 now imposes statutory duties on data processors; a SaaS vendor processing personal data must comply independently, so the confidentiality clause should explicitly reference this. The Indian courts recognize breach of confidence as a tortious wrong under equity principles (following English common law). Trade secrets receive protection under the Indian Penal Code Section 379 (theft) if misappropriated. Importantly, the agreement must clearly state what is confidential; vague definitions may fail enforcement in Indian courts, which require specificity.
Drafting and Negotiation
Define "Confidential Information" to include customer data, technical specifications, API documentation, pricing, and performance metrics. For Indian context, explicitly distinguish between personal data (covered by statutory law) and non-personal business confidential information. Many vendors resist broader customer definitions; negotiate inclusion of "any information marked as confidential or reasonably understood to be confidential." Agree on the permitted use: vendor may use only to provide the service; customer may use only for internal operations. Address return or destruction of data upon termination; Indian law does not mandate automatic destruction, so this must be contractual. Clarify the vendor's permitted disclosures: to subprocessors (with written notice), to comply with court orders or Indian government requests (with prior notice to the other party where lawful), and to auditors and insurers under confidentiality. A "Compelled Disclosure" clause is critical in India, as authorities may demand data; vendors should commit to providing notice and legal challenge opportunity. For SaaS, negotiate the customer's right to audit compliance (annual or on-demand), which is market standard and aligns with DPDP compliance expectations. Clarify whether the clause survives termination indefinitely (rare and unbalanced) or for a specified post-term period (standard: 2-3 years).
Common Pitfalls
Omitting explicit reference to personal data and DPDP 2023 obligations can create gaps in compliance. Many agreements fail to define "Confidential Information" clearly, making enforceability difficult in Indian courts. Vendors sometimes accept "all information is confidential" language, which is impractical and unenforceable; negotiate reasonable carve-outs. Failing to address government disclosure and compelled disclosure is dangerous in India, where law enforcement and tax authorities routinely issue orders; silence implies the vendor must comply without notice. Not clarifying the customer's obligations to secure data it receives from the vendor can expose both parties if a breach occurs. Undefined return-or-destruction procedures at termination create disputes; specify timelines and certification. Some agreements omit audit rights entirely, leaving the customer without verification mechanism, which regulators increasingly expect. Finally, avoid perpetual confidentiality for non-sensitive information; Indian courts may view this as unreasonable restraint of trade under Section 27 ICA.
Sample language
Each party shall keep the other's Confidential Information (including customer data, technical documentation, and pricing) strictly confidential and use it only to perform or receive the Services. Confidential Information excludes publicly available information and information independently developed without reference to the disclosing party's information. Personal data shall be handled in compliance with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023. Upon termination, the receiving party shall return or certify destruction of all Confidential Information within 30 days, except where retention is required by law. Either party may disclose Confidential Information to comply with court orders or statutory authority requests, provided it gives prompt notice to the other party where lawfully permitted to do so.
This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.
Frequently asked questions
- Is confidentiality enforceable in Indian SaaS agreements if not mentioned in the contract?
- Partial enforceability exists under equity principles and Section 43A of the IT Act 2000 (for data mishandling), but an express confidentiality clause is essential for clarity and remedies. Indian courts require specificity; silence may make damages difficult to prove. Always include a written confidentiality clause to ensure full enforceability and define remedies.
- How do I handle government data requests in a confidentiality clause under Indian law?
- Include a Compelled Disclosure clause committing the receiving party to notify the other party of legal or government demands before complying, where permitted by law. This does not prevent compliance with orders but preserves the relationship and allows the disclosing party to seek protective orders. Courts expect this language in India-specific agreements.
- Does the Digital Personal Data Protection Act 2023 change confidentiality obligations in SaaS agreements?
- Yes. DPDP 2023 imposes independent statutory duties on data processors, so the confidentiality clause must explicitly reference it and confirm both parties' compliance. The clause cannot diminish statutory obligations but can clarify how confidentiality and data protection duties interact, such as defining processor permitted uses and sub-processor authorization.
- What happens to confidential information after a SaaS agreement ends in India?
- The clause should specify whether the receiving party must return or destroy Confidential Information within a set period (typically 30 days), with certification to the disclosing party. Confidentiality obligations typically survive termination for 2 to 3 years for non-personal business information, but personal data destruction must comply with DPDP 2023 timelines.
Related in the library
- The confidentiality clause in a non-disclosure agreement (NDA) under India law
- The confidentiality clause in a SaaS agreement under the United States law
- The confidentiality clause in a non-disclosure agreement (NDA) under the United States law
- The limitation of liability clause in a consultancy agreement under India law
- The governing law clause in a SaaS agreement under India law
- The dispute resolution clause in a non-disclosure agreement (NDA) under India law
Adira drafts and reviews contracts under the law of the jurisdiction they work in.
See Adira