DPDP

WoltSign and DPDP: How We Handle Personal Data in India's E-Signature Workflows

When your customers, employees, or vendors sign a document through WoltSign, that session processes their personal data. Here is what WoltSign does with that data under India's Digital Personal Data Protection Act, 2023, and where your organization's obligations as the Data Fiduciary begin.

Your role

WoltSign as a Data Processor under the DPDP Act

Under India's DPDP Act, 2023, the organization that determines why personal data is collected and what it is used for is the Data Fiduciary. WoltSign is a Data Processor. It processes personal data (signer names, email addresses, IP addresses, signing timestamps, and document content) on behalf of the Data Fiduciary (your organization) according to your instructions and the terms of a Data Processing Agreement.

Section 8(2) of the DPDP Act permits a Data Fiduciary to engage a Data Processor only under a valid contract. WoltSign's Data Processing Agreement at DPA serves as that contract. WoltSign does not use the personal data it processes through signing workflows for its own purposes beyond operating the service.

Electronic signatures are legally recognized in India under the Information Technology Act, 2000 (Sections 5 and 10A). The DPDP Act adds data protection requirements on top of the signing workflow, specifically around how signer data is collected, stored, and deleted.

Personal data may be processed on secure cloud infrastructure; specific regions are listed in the Data Processing Agreement. Data is encrypted in transit using TLS and at rest using AES-256. The signing audit trail records the signer's identity, the time of signing, and the IP address at the time of signing. This record is retrievable on demand and serves as evidentiary proof of the signing event.

Controls

Data protection controls in WoltSign

Specific technical and organizational measures described in our security documentation and Data Processing Agreement.

ControlStatus
Data in transit encryptionTLS between your browser and WoltSign
Data at rest encryptionAES-256 for documents, signatures, and metadata
Storage regionsSecure cloud infrastructure; specific regions listed in the DPA
Cross-border data transferDPDP Rules 2025 do not restrict transfers to any listed country as of July 2026; posture described in the DPA
Signing audit trailTimestamp, signer identity, and IP address, retrievable on demand
Data Processing AgreementAvailable at DPA; covers Section 8(2) contract requirement
Sub-processorsListed in the DPA
Access controlsRole-based access controls with multi-factor authentication support
Audit loggingSigning events, document actions, and authentication attempts are logged
Data deletion on account cancellationCustomer data deleted or made inaccessible within a reasonable period after termination, triggered by Data Fiduciary instruction per Section 8(7) (see DPA Section 11)
Breach notificationWoltSign notifies the Data Fiduciary without delay of any breach in WoltSign's systems
Agreement

Data Processing Agreement

WoltSign offers a Data Processing Agreement (DPA) to all customers. The DPA covers WoltSign's obligations as a Data Processor under the DPDP Act, including the Section 8(2) requirement that a Data Fiduciary may engage a Data Processor only under a valid contract. The DPA describes the sub-processors WoltSign uses, the security measures in place, and the process for handling Data Principal rights requests.

Review the WoltSign DPA at DPA. If you need a countersigned DPA for your records, contact WoltSign at support@woltsign.com. Enterprise customers receive DPA execution as part of their onboarding.

Shared responsibility

What your organization is responsible for

WoltSign is a Data Processor under the DPDP Act. Your organization, as the Data Fiduciary, is responsible for decisions that WoltSign does not and cannot make on your behalf.

WoltSign is not a Consent Manager. It is not registered with the Data Protection Board of India as a Consent Manager and does not provide or manage consent notices on behalf of your organization's Data Principals.

Your organization is responsible for:

  • Establishing a valid legal basis for processing signer data (consent under Section 6 or a legitimate use under Section 7 of the DPDP Act) before sending documents through WoltSign
  • Giving Data Principals a notice that meets Section 5 requirements before or at the time of data collection, including the purpose, a description of personal data to be processed, and a means to withdraw consent
  • Responding to Data Principal rights requests: access (Section 11), correction and erasure (Section 12), grievance redressal (Section 13), and nomination (Section 14)
  • Notifying the Data Protection Board within 72 hours of a personal data breach in your systems, in line with Rule 7 of the DPDP Rules 2025
  • Ensuring the document content you send through WoltSign does not contain personal data you are not authorized to process

WoltSign will notify your organization without delay of any personal data breach that occurs within WoltSign's systems, as described in the DPA, so you can meet your Board notification obligations.

FAQ

Common DPDP questions

Is WoltSign DPDP compliant?
WoltSign is designed to support your obligations as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023. DPDP compliance is not a certification. It describes a set of practices. WoltSign provides a Data Processing Agreement that covers the Section 8(2) contract requirement, processes data only as instructed by the customer, maintains a tamper-evident signing audit trail, and will notify your organization without delay of any breach in WoltSign's systems. Whether your specific use of WoltSign satisfies your organization's DPDP obligations is a determination your Data Protection Officer or legal team must make.
Does WoltSign help with consent collection under the DPDP Act?
WoltSign produces a timestamped signing audit trail that records who signed, when, and from which IP address. This audit trail can serve as part of the evidentiary record of a signing event. However, WoltSign is not a Consent Manager registered with the Data Protection Board of India. Your organization, as the Data Fiduciary, is responsible for giving Data Principals the consent notice required by Section 5 of the DPDP Act before or at the time their data is collected, and for managing consent withdrawal as required by Section 6. WoltSign does not draft or deliver those notices on your behalf.
How does WoltSign handle personal data breach notification under the DPDP Act?
If a personal data breach occurs within WoltSign's systems, WoltSign will notify your organization without delay. The DPDP Act (Section 8(6)) and DPDP Rules 2025 (Rule 7) require the Data Fiduciary, your organization, to notify affected Data Principals without delay and to submit a detailed report to the Data Protection Board within 72 hours of becoming aware of the breach. WoltSign's prompt notification to your organization is designed to give you the time needed to meet those requirements. The full process is described in the Data Processing Agreement at DPA.
Where does WoltSign store data from India-based signers?
Personal data from India-based signers may be processed and stored on secure cloud infrastructure used by WoltSign. The DPDP Rules 2025 do not restrict cross-border transfer of personal data to any specific country as of July 2026. Current sub-processors, regions, and transfer practices are described in the Data Processing Agreement at DPA. If your organization has specific data residency requirements, review the DPA and contact WoltSign before deployment.

Next steps

Ready to evaluate WoltSign for your team?

Review the Data Processing Agreement, explore security controls, or start a trial. Enterprise customers can request a countersigned DPA during onboarding.