Privacy

    Data Fiduciary Under India's DPDP Act: Duties, Liabilities and Compliance Checklist

    Santhosh Kapalavai
    Sep 12, 2026
    Privacy

    What is a Data Fiduciary?

    Under India's Digital Personal Data Protection (DPDP) Act, 2023, a Data Fiduciary is any person, company or public body that alone or with others determines the purpose and means of processing digital personal data. If your organisation decides *why* personal data is collected and *how* it is used, you are a Data Fiduciary — regardless of size, sector or whether the processing is outsourced.

    Three roles matter in the Act:

    • Data Fiduciary — decides the purpose and means of processing, and carries primary accountability
    • Data Processor — processes personal data on behalf of a Data Fiduciary, under contract
    • Data Principal — the individual to whom the personal data relates

    A single organisation can be a Fiduciary for some processing (its own employee and customer data) and a Processor for other processing (data handled for a client). Map this role by role, not company-wide.

    Core obligations of a Data Fiduciary

    1. Lawful basis and notice Processing requires either free, specific, informed and unambiguous consent, or a legitimate use listed in the Act. Every consent request must be accompanied by a clear notice stating the personal data collected, the purpose, how to withdraw consent, how to exercise rights and how to complain to the Data Protection Board.

    2. Purpose limitation and data minimisation Collect only the personal data necessary for the stated purpose. Reusing data for a new purpose needs fresh consent or a valid legitimate use.

    3. Accuracy and completeness Personal data used to make a decision about a Data Principal, or disclosed to another Fiduciary, must be accurate, complete and consistent.

    4. Erasure and retention Erase personal data when consent is withdrawn or the purpose is no longer served, unless retention is required by law. Retention schedules and defensible deletion become operational requirements, not policy statements.

    5. Reasonable security safeguards The Act obliges Fiduciaries to protect personal data in their possession or under their control, including data held by Processors. Access control, encryption, logging, backups and hardening are the practical baseline.

    6. Breach notification Every personal data breach must be reported to the Data Protection Board of India and to affected Data Principals. There is no materiality threshold — small breaches are reportable too, so detection and triage must be fast.

    7. Grievance redressal and contactable escalation Publish the contact details of a Data Protection Officer or an authorised person who can answer questions about processing, and run a grievance mechanism with defined response times.

    8. Children's data Processing the data of anyone under 18 requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.

    9. Processor contracts Processors may only be engaged under a valid contract. Liability for the Processor's failings does not shift away from the Fiduciary.

    Significant Data Fiduciary: the higher tier

    The Central Government may notify a Fiduciary or class of Fiduciaries as a Significant Data Fiduciary based on the volume and sensitivity of data processed, risk to Data Principals, risk to electoral democracy, security of the state and public order. Additional duties apply:

    Additional dutyWhat it means operationally
    Appoint a Data Protection OfficerBased in India, reporting to the board or governing body, and the point of contact for grievances
    Appoint an independent data auditorEvaluates DPDP compliance independently of the compliance owner
    Periodic Data Protection Impact AssessmentDocumented assessment of rights impact and mitigation for each significant processing activity
    Periodic audit and other prescribed measuresRecurring audit cycle with tracked remediation

    Penalties that concentrate the mind

    The Act's schedule sets financial penalties of up to INR 250 crore for failure to take reasonable security safeguards, up to INR 200 crore for failure to notify a breach and for breaches of children's data obligations, and up to INR 150 crore for failure to meet Significant Data Fiduciary duties. Penalties attach to the Fiduciary, which is why outsourcing processing does not outsource risk.

    Practical compliance checklist

    1. Role mapping — document where you are a Fiduciary, a Processor, or both
    2. Data inventory and flow maps — systems, purposes, categories, retention, cross-border transfers
    3. Consent architecture — granular, withdrawable, logged, with itemised notices in the languages required
    4. Rights fulfilment workflow — access, correction, erasure, nomination, grievance, with SLAs and evidence
    5. Retention and deletion schedule — enforced in systems, not only in policy
    6. Processor governance — contract clauses, due diligence, sub-processor visibility, audit rights
    7. Breach readiness — detection, severity assessment, Board and Data Principal notification templates, tabletop rehearsal
    8. Security controls — align to an accepted framework such as ISO/IEC 27001, with ISO/IEC 27701 extending it to privacy
    9. DPO and governance forum — named accountability, board-level reporting, training for high-risk teams
    10. Assurance — internal audit, DPIAs for high-risk processing, and an independent data audit if you are notified as significant

    Key takeaways

    • Fiduciary status follows decision-making authority over personal data, not company size
    • Consent, notice, minimisation, erasure, security and breach reporting form the operating core
    • Significant Data Fiduciaries additionally need an India-based DPO, DPIAs and independent data audits
    • Liability stays with the Fiduciary even when a Processor causes the failure
    • ISO/IEC 27001 and ISO/IEC 27701:2025 give you the control backbone to evidence DPDP readiness

    Treat DPDP as an operating model change rather than a document exercise: the obligations that attract the largest penalties — safeguards and breach reporting — are the ones that depend on day-to-day engineering discipline.

    Hi! I'm your AI Assistant 💬