A data fiduciary is any person who, alone or together with others, decides the purpose and means of processing personal data. That is the definition in Section 2(i) of the Digital Personal Data Protection Act, 2023, and it is the role that carries almost every obligation in the Act. An online retailer collecting delivery addresses, a hospital keeping patient records and an employer running payroll are all data fiduciaries for that processing. The vendor that handles the data on their instructions is not: it is a data processor, and the Act holds the fiduciary responsible for it.
The term is new to most Indian businesses, and it matters more than any other in the Act, because every duty that follows, from notice and consent to breach reporting and erasure, is placed on the data fiduciary. Getting the role right for each set of data is the first decision in any DPDP programme, and one of the most often got wrong.
The definition, read carefully
Three parts of Section 2(i) do most of the work.
- “Any person”. The Act defines a person widely. It covers individuals, companies, firms, Hindu undivided families, associations, the State and other legal persons. An individual acting for personal or domestic purposes is outside the Act under Section 3, but an individual running a business is not.
- “Alone or in conjunction with other persons”. Two organisations can be data fiduciaries for the same processing if they decide its purpose together, for example partners in a co-branded programme.
- “Determines the purpose and means”. The test is decision-making, not possession. Holding or hosting data does not make an organisation a fiduciary. Deciding why the data is collected and how it is used does.
The Act also reaches beyond India. Under Section 3, it applies to a data fiduciary outside India when the processing is connected with offering goods or services to people in India.
Data fiduciary or data processor?
A data processor is anyone who processes personal data on behalf of a data fiduciary, under Section 2(k). The practical question is always the same: who decided why this data is being processed? The organisation that decided is the fiduciary. The one following its instructions is the processor. Many businesses are both, for different data.
| Situation | Data fiduciary | Data processor |
|---|---|---|
| An online retailer hosts its customer database with a cloud provider | The retailer | The cloud provider |
| An employer outsources payroll to an external firm | The employer | The payroll firm |
| A hospital uses a vendor’s laboratory information system | The hospital | The vendor, if it acts only on the hospital’s instructions |
| A software company runs a platform that holds its clients’ customer records | Each client, for its own customers’ data | The software company, for that data |
| The same software company runs its own billing and sales outreach | The software company | Its own vendors, such as its email provider |
The last two rows are the ones that trip up business-to-business companies. A software firm is usually a processor for what its clients load into the product, and a fiduciary for its own account, billing and marketing data, with different obligations for each. Processor relationships run on contract under Section 8(2), which is why the data processing agreement matters so much in business-to-business work.
What a data fiduciary must do
The Act places the following duties on every data fiduciary. Most take effect on 13 May 2027, eighteen months after the DPDP Rules were notified on 13 November 2025.
| Duty | Where it sits |
|---|---|
| Process personal data only for a lawful purpose, on consent or a legitimate use | Sections 4, 6 and 7 |
| Give a clear notice before or with every request for consent | Section 5 and Rule 3 |
| Remain responsible for processing done on its behalf, and engage processors only under a valid contract | Section 8(1) and 8(2) |
| Keep data complete, accurate and consistent where it is used to make decisions or is disclosed | Section 8(3) |
| Protect data with reasonable security safeguards | Section 8(5) and Rule 6 |
| Notify personal data breaches to the Data Protection Board and to affected individuals | Section 8(6) and Rule 7 |
| Erase data once its purpose is served, unless the law requires it to be kept | Section 8(7) and Rule 8 |
| Publish contact details for questions about its processing, and run a grievance process | Section 8(9), 8(10) and Rule 9 |
| Obtain verifiable parental consent before processing a child’s data | Section 9 and Rule 10 |
| Meet additional duties if notified as a Significant Data Fiduciary | Section 10 and Rule 13 |
The penalties follow the weighting our guide to DPDP compliance on a startup budget explains: up to INR 250 crore for failing to take reasonable security safeguards, and up to INR 200 crore for failing to report a breach.
Four mistakes we see most often
Assuming a business-to-business company is only ever a processor. Almost every company is a fiduciary for its own employees, and for its own sales and marketing data.
Assuming the processor carries the risk. Section 8(1) makes the fiduciary responsible for processing done on its behalf, whatever the contract says. A vendor’s failure remains the fiduciary’s problem before the Board.
Forgetting employee data. Processing for employment can rest on a legitimate use rather than consent, but the employer is still the data fiduciary, with the security, breach and erasure duties that go with it.
Overlooking reach outside India. A company based abroad that sells to customers in India is a data fiduciary under the Act for that processing.
Where to start
Begin with one list: every set of personal data you hold, and your role for each, fiduciary or processor. Everything else in a DPDP programme is built on it. If you are choosing outside help for that work, our guide on how to choose a DPDP consultant in India sets out the questions to ask, and our DPDP consulting page explains how we approach it.
Frequently asked questions
Broadly, yes. Both are the party that decides why and how personal data is processed. The duties differ: the DPDP Act has no general legitimate interests basis, only a closed list of legitimate uses, and it imposes no general duty to keep records of processing activities.
Yes, when processing personal data for a business or professional purpose. Processing for purely personal or domestic purposes is outside the Act under Section 3.
Usually both. It is a processor for the data its clients load into the product, and a fiduciary for its own account, billing and marketing data.
Yes. The definition covers a person who determines the purpose and means of processing alone or in conjunction with others.
No. Only a Significant Data Fiduciary must appoint one. Every other data fiduciary must publish the contact details of a person who can answer questions about its processing, under Section 8(9) and Rule 9.
Most apply from 13 May 2027, eighteen months after the DPDP Rules were notified. The Consent Manager provisions apply from 13 November 2026. MeitY proposed in January 2026 to bring the deadline forward, so check the current position before planning.
Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that provides DPDP consulting. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.