Pricoris

What Is a Data Fiduciary Under the DPDP Act? Meaning, Examples and Duties

A data fiduciary is any person who, alone or together with others, decides the purpose and means of processing personal data. That is the definition in Section 2(i) of the Digital Personal Data Protection Act, 2023, and it is the role that carries almost every obligation in the Act. An online retailer collecting delivery addresses, a hospital keeping patient records and an employer running payroll are all data fiduciaries for that processing. The vendor that handles the data on their instructions is not: it is a data processor, and the Act holds the fiduciary responsible for it.

The term is new to most Indian businesses, and it matters more than any other in the Act, because every duty that follows, from notice and consent to breach reporting and erasure, is placed on the data fiduciary. Getting the role right for each set of data is the first decision in any DPDP programme, and one of the most often got wrong.

The definition, read carefully

Three parts of Section 2(i) do most of the work.

  • “Any person”. The Act defines a person widely. It covers individuals, companies, firms, Hindu undivided families, associations, the State and other legal persons. An individual acting for personal or domestic purposes is outside the Act under Section 3, but an individual running a business is not.
  • “Alone or in conjunction with other persons”. Two organisations can be data fiduciaries for the same processing if they decide its purpose together, for example partners in a co-branded programme.
  • “Determines the purpose and means”. The test is decision-making, not possession. Holding or hosting data does not make an organisation a fiduciary. Deciding why the data is collected and how it is used does.

The Act also reaches beyond India. Under Section 3, it applies to a data fiduciary outside India when the processing is connected with offering goods or services to people in India.

Data fiduciary or data processor?

A data processor is anyone who processes personal data on behalf of a data fiduciary, under Section 2(k). The practical question is always the same: who decided why this data is being processed? The organisation that decided is the fiduciary. The one following its instructions is the processor. Many businesses are both, for different data.

SituationData fiduciaryData processor
An online retailer hosts its customer database with a cloud providerThe retailerThe cloud provider
An employer outsources payroll to an external firmThe employerThe payroll firm
A hospital uses a vendor’s laboratory information systemThe hospitalThe vendor, if it acts only on the hospital’s instructions
A software company runs a platform that holds its clients’ customer recordsEach client, for its own customers’ dataThe software company, for that data
The same software company runs its own billing and sales outreachThe software companyIts own vendors, such as its email provider

The last two rows are the ones that trip up business-to-business companies. A software firm is usually a processor for what its clients load into the product, and a fiduciary for its own account, billing and marketing data, with different obligations for each. Processor relationships run on contract under Section 8(2), which is why the data processing agreement matters so much in business-to-business work.

What a data fiduciary must do

The Act places the following duties on every data fiduciary. Most take effect on 13 May 2027, eighteen months after the DPDP Rules were notified on 13 November 2025.

DutyWhere it sits
Process personal data only for a lawful purpose, on consent or a legitimate useSections 4, 6 and 7
Give a clear notice before or with every request for consentSection 5 and Rule 3
Remain responsible for processing done on its behalf, and engage processors only under a valid contractSection 8(1) and 8(2)
Keep data complete, accurate and consistent where it is used to make decisions or is disclosedSection 8(3)
Protect data with reasonable security safeguardsSection 8(5) and Rule 6
Notify personal data breaches to the Data Protection Board and to affected individualsSection 8(6) and Rule 7
Erase data once its purpose is served, unless the law requires it to be keptSection 8(7) and Rule 8
Publish contact details for questions about its processing, and run a grievance processSection 8(9), 8(10) and Rule 9
Obtain verifiable parental consent before processing a child’s dataSection 9 and Rule 10
Meet additional duties if notified as a Significant Data FiduciarySection 10 and Rule 13

The penalties follow the weighting our guide to DPDP compliance on a startup budget explains: up to INR 250 crore for failing to take reasonable security safeguards, and up to INR 200 crore for failing to report a breach.

Four mistakes we see most often

Assuming a business-to-business company is only ever a processor. Almost every company is a fiduciary for its own employees, and for its own sales and marketing data.

Assuming the processor carries the risk. Section 8(1) makes the fiduciary responsible for processing done on its behalf, whatever the contract says. A vendor’s failure remains the fiduciary’s problem before the Board.

Forgetting employee data. Processing for employment can rest on a legitimate use rather than consent, but the employer is still the data fiduciary, with the security, breach and erasure duties that go with it.

Overlooking reach outside India. A company based abroad that sells to customers in India is a data fiduciary under the Act for that processing.

Where to start

Begin with one list: every set of personal data you hold, and your role for each, fiduciary or processor. Everything else in a DPDP programme is built on it. If you are choosing outside help for that work, our guide on how to choose a DPDP consultant in India sets out the questions to ask, and our DPDP consulting page explains how we approach it.

Frequently asked questions

Is a data fiduciary the same as a data controller under the GDPR?

Broadly, yes. Both are the party that decides why and how personal data is processed. The duties differ: the DPDP Act has no general legitimate interests basis, only a closed list of legitimate uses, and it imposes no general duty to keep records of processing activities.

Can an individual be a data fiduciary?

Yes, when processing personal data for a business or professional purpose. Processing for purely personal or domestic purposes is outside the Act under Section 3.

Is a SaaS company a data fiduciary or a data processor?

Usually both. It is a processor for the data its clients load into the product, and a fiduciary for its own account, billing and marketing data.

Can two organisations be joint data fiduciaries?

Yes. The definition covers a person who determines the purpose and means of processing alone or in conjunction with others.

Does every data fiduciary need a Data Protection Officer?

No. Only a Significant Data Fiduciary must appoint one. Every other data fiduciary must publish the contact details of a person who can answer questions about its processing, under Section 8(9) and Rule 9.

When do data fiduciary obligations apply?

Most apply from 13 May 2027, eighteen months after the DPDP Rules were notified. The Consent Manager provisions apply from 13 November 2026. MeitY proposed in January 2026 to bring the deadline forward, so check the current position before planning.


Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that provides DPDP consulting. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top