miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

Data Fiduciary Obligations Under India’s DPDP Act: The Complete Guide

1st October, 20268 Min Read

A privacy policy can tell people what an organization intends to do with their data. It cannot tell you whether the organization actually knows where that data went six months later.

That distinction is becoming important under India’s DPDP Act. Personal data may pass through business applications, internal teams, Data Processors, and other systems, creating obligations that cannot be managed through consent forms and policy documents alone.

The Data Fiduciary has to establish how processing is governed from collection to erasure, with Section 8 covering accountability, security, breach response, processor contracts, retention, and grievances. The DPDP Rules, 2025 add the operational detail, turning these responsibilities into specific requirements for how personal data is protected, retained, and managed.

The Role Is Defined by Control, Not by Size

A Data Fiduciary is the person who decides the purpose and means of processing personal data. A Data Processor processes personal data on behalf of the Data Fiduciary and according to its instructions.

The distinction is therefore based on control over processing, not the size of the organization.

The same company can be a Data Fiduciary for one activity and a Data Processor for another. For example, an organization may determine how it processes its own employee data while processing customer data according to another organization's instructions.

The DPDP Act covers digital personal data processed in India and certain processing outside India connected with offering goods or services to Data Principals in India. Being a smaller organization does not remove the baseline duties. A Significant Data Fiduciary has additional obligations, but the core Section 8 duties apply to every Data Fiduciary once the relevant provisions commence.

Section 8 Is the Core Obligations Checklist

Section 8 establishes the core Data Fiduciary obligations under the DPDP Act:

  • Accountability: A Data Fiduciary remains responsible for processing carried out by it or by a Data Processor on its behalf under Section 8(1).
  • Processor contracts: A valid contract is required before engaging a Data Processor under Section 8(2).
  • Data quality: Section 8(3) requires completeness, accuracy, and consistency where personal data is used for a decision affecting the Data Principal or disclosed to another Data Fiduciary.
  • Security safeguards: Sections 8(4) and 8(5) require appropriate technical and organizational measures and reasonable security safeguards.
  • Breach notification: Section 8(6) establishes notification obligations for personal data breaches.
  • Retention and erasure: Sections 8(7) and 8(8) address erasure and require the Data Fiduciary to cause its processors to erase applicable data.
  • Contact and grievances: Sections 8(9) and 8(10) require a published contact and a grievance redressal mechanism.

The Rules Hook

The DPDP Rules, 2025 provide the operational detail behind these duties. Rule 6 covers reasonable security safeguards, Rule 7 addresses personal data breach reporting, Rule 8 covers retention and erasure, and Rule 14 addresses rights and grievances.

Hiring a Processor Does Not Transfer Your Liability

Section 8(1) makes the Data Fiduciary responsible for processing carried out on its behalf, regardless of any agreement to the contrary. Section 8(2) requires a valid contract before engaging a Data Processor.

This makes the Data Processor contract under the DPDP Act an important control, not just a procurement document.

The contract should establish responsibilities for processing activities, security safeguards, personal data breach notification, Data Principal requests, sub-processors, retention, and erasure.

The fiduciary also needs visibility into whether those obligations are actually being met. That means understanding what data the processor receives, where it goes, which sub-processors are involved, and how incidents or deletion requests are handled.

A Lawful Processing Setup Needs a Basis, a Notice, and a Plan

A lawful processing setup starts with the requirements established by the Act and Rules:

  • A lawful purpose and applicable basis under Section 4, based on consent or a certain legitimate use.
  • A clear notice under Section 5 and Rule 3 identifying the personal data and specified purpose.
  • Consent that is free, specific, informed, unconditional, and unambiguous, and limited to necessary personal data, under Section 6.
  • Reasonable security safeguards under Section 8(5) and Rule 6.
  • A personal data breach response process aligned with Rule 7.
  • A retention and erasure schedule under Section 8(7) and Rule 8.

The Derived Value

The legal requirements become easier to manage when they are connected through an operational record.

A processing register can map data, purpose, basis, retention, and recipients. Processor contracts can include sub-processor disclosure and flow-down duties. A published DPO or responsible contact can connect with a working grievance channel.

Organizations should also establish workflows for applicable Data Principal requests, including access, correction, erasure, and nomination.

Evidence matters too. Logs, audit trails, and DPIAs where applicable can demonstrate how controls operate instead of relying only on written policies.

Data Fiduciary Obligations: Key Pointers

Obligation What the DPDP Act and Rules Require
Lawful Basis & Notice Section 4 permits processing on consent or a certain legitimate use. Section 5 and Rule 3 require clear, itemized notice covering the personal data and specified purpose.
Accuracy for Decisions Section 8(3) requires completeness, accuracy, and consistency where personal data is used for a decision affecting the person or disclosed to another Data Fiduciary.
Security Safeguards Section 8(5) requires reasonable security safeguards. Rule 6 specifies measures including encryption or masking, access control, logging and monitoring, backups, and processor-contract terms, with logs kept at least one year.
Breach Notification Section 8(6) and Rule 7 require notification to affected Data Principals and the Board. A detailed report is required within 72 hours of becoming aware.
Retention & Erasure Section 8(7) and Rule 8 address erasure once the purpose is served or consent is withdrawn. Certain large platforms have additional three-year inactivity requirements with a 48-hour notice, unless law requires retention.
Processor Contracts Section 8(1) keeps the fiduciary accountable for its processors, while Section 8(2) requires a valid contract before engaging a Data Processor.
Contact & Grievance Sections 8(9) and 8(10), together with Rule 14, require a published DPO or contact point and grievance mechanism, including the applicable 90-day response framework.
Children’s Data Section 9 and Rule 10 address verifiable parental consent and restrictions on tracking, behavioral monitoring, and targeted advertising, subject to prescribed exemptions.
Cross-Border Transfer Section 16 and Rule 15 govern transfers generally, while a Significant Data Fiduciary may face localization requirements for specified data.

These requirements cover the main operational areas a Data Fiduciary needs to connect: lawful processing, data quality, security, breach response, lifecycle management, vendors, rights, children’s data, and cross-border processing.

Every Fiduciary Has a Baseline; SDFs Carry More

Ordinary Data Fiduciary

The baseline includes lawful basis, notice and consent handling, security safeguards, breach reporting, retention and erasure, Data Principal rights, grievance redressal, a published contact, and valid processor contracts.

Significant Data Fiduciary

A Significant Data Fiduciary has additional requirements, including:

  • A Data Protection Officer based in India under Section 10
  • An independent data auditor and data audit
  • An annual DPIA and periodic audit under Rule 13
  • Algorithmic-software due diligence
  • Applicable localization requirements for specified data

The Third Schedule is relevant to the framework for identifying Significant Data Fiduciaries.

What They Share

Both must get the baseline Section 8 duties right. SDF designation adds governance and assurance layers; it does not replace the baseline obligations.

A Practical DPDP Workflow for Data Fiduciaries

The Cycle

For ordinary Data Fiduciaries, the Act does not prescribe an annual audit. The practical approach is to establish the Section 8 controls, then revisit them when the data, purpose, vendors, geography, or decision impact changes.

For a Significant Data Fiduciary, Rule 13 adds a formal DPIA and audit once every twelve months from designation, along with algorithmic-software due diligence.

The Trigger Points

Refresh the compliance program when:

  • A new processing purpose or product is introduced.
  • A new Data Processor, Consent Manager, or sub-processor is engaged.
  • Retention periods, data categories, or transfer destinations change.
  • The organization begins processing children's or guardianship data.
  • The organization is designated, or expects designation, as a Significant Data Fiduciary.

The objective is not to repeat a static assessment. It is to keep the data map and controls aligned with how personal data is actually being processed.

Know Exactly What Section 8 Requires

Get expert guidance on translating Data Fiduciary obligations into practical controls across data, processors, security, retention, and rights.

Accountability Runs Through the Fiduciary, Not the Processor

Section 8(1) fixes responsibility on the Data Fiduciary for processing performed by it or on its behalf. Section 8(2) requires a valid processor contract, while Section 8(8) requires the fiduciary to cause its processor to erase personal data when applicable.

This creates a straightforward operational principle: know what the processor receives, why it receives it, how it protects it, and what happens when processing ends.

Rule 6 connects processor contracts with security safeguards, while Rule 7 establishes breach-related requirements. The relevant operative provisions are scheduled to commence on 13 May 2027.

The Baseline Duties Still Apply

The SDF-specific requirements do not apply to every organization. An India-based Data Protection Officer, independent data auditor, annual DPIA and audit, algorithmic-software due diligence, and applicable localization requirements are additional SDF obligations.

The general Section 8 duties, however, apply to Data Fiduciaries once the relevant provisions commence. These include lawful basis, notice, consent or certain legitimate uses, security, data quality, breach reporting, retention and erasure, rights handling, grievances, and valid processor contracts.

A voluntary DPIA or named privacy contact can still be useful for a smaller fiduciary. Where it is not legally required, it should be presented as good practice rather than as a universal statutory obligation.

Three Data Fiduciary Compliance Claims to Avoid

1. A Contract Shifts Our Liability

Section 8(1) keeps the Data Fiduciary accountable for processing done on its behalf.

Reality: A contract establishes responsibilities and safeguards. It does not remove the fiduciary's accountability.

2. Only SDFs Need to Comply

The baseline Section 8 duties apply to every Data Fiduciary once the relevant provisions commence.

Reality: DPO, independent audit, DPIA, and algorithmic-software due diligence are additional SDF requirements, not the entire DPDP regime.

3. Keep Data Indefinitely, Just in Case

Section 8(7) and Rule 8 require erasure when the purpose is served or consent is withdrawn, unless applicable law requires retention.

Reality: Retention should be tied to the purpose and applicable legal requirements. "We might need it later" is not a retention rule.

From Section 8 Requirements to Operational Controls

The real test of DPDP compliance is whether an organization can account for personal data throughout its lifecycle.

For most Data Fiduciaries, that means knowing what data is processed, why it is processed, how it is protected, which Data Processors handle it, how Data Principal requests are managed, and when the data must be erased. Significant Data Fiduciaries add governance, audit, DPIA, and assurance requirements.

With the core obligations scheduled to take effect on 13 May 2027, organizations can use the transition period to turn Section 8 and the DPDP Rules into working controls across data, systems, vendors, and workflows.

See Your Personal Data Through the DPDP Lens

Understand where personal data enters, moves, gets shared, and should be erased across your applications and vendors.

FAQs

Who counts as a Data Fiduciary under the DPDP Act?

A Data Fiduciary is a person or organization that determines the purpose and means of processing digital personal data. The role depends on control over processing, rather than organizational size.

What are the core obligations of a Data Fiduciary under Section 8?

Section 8 covers accountability, Data Processor contracts, data quality, reasonable security safeguards, breach notification, retention and erasure, published contact information, and grievance redressal.

Can a Data Fiduciary transfer its liability to a Data Processor?

No. Section 8(1) keeps the Data Fiduciary accountable for processing performed on its behalf. A processor contract defines responsibilities and safeguards but does not transfer statutory accountability.

How fast must a Data Fiduciary report a personal data breach?

Rule 7 requires a detailed report to the Data Protection Board of India within 72 hours of becoming aware of a personal data breach, alongside applicable notification requirements for affected Data Principals.

When must a Data Fiduciary erase personal data?

Personal data must be erased when its purpose has been served or consent is withdrawn, subject to applicable legal retention requirements. The fiduciary must also cause relevant processors to erase the data.

Does every Data Fiduciary need a Data Protection Officer?

No. An India-based Data Protection Officer is an additional requirement for Significant Data Fiduciaries. Other fiduciaries still need the applicable published contact mechanism and grievance process.

What extra obligations apply to a Significant Data Fiduciary?

SDFs have additional requirements including an India-based DPO, independent data auditor, data audit, annual DPIA and audit under Rule 13, algorithmic-software due diligence, and applicable localization requirements.

When do the main Data Fiduciary obligations take effect?

The DPDP Rules were notified on 13 November 2025. The core obligations in Sections 5 to 10 and the operational Rules are scheduled to take full effect on 13 May 2027, after the applicable transition period.

About the Author


Minal Purwar

Content Writer

Minal is an experienced B2B content writer. She has written over 250 articles across industries like UI/UX, real estate, automotive, digital marketing, SaaS, AI & ML, and cybersecurity. She brings her interest in cybersecurity to life by creating clear, engaging content tailored for technical, non-technical, and creative pieces. Her aim is to simplify complex topics, highlight product value, and connect with both technical and non-technical audiences.

Leave a Comment