What is a Data Fiduciary under the DPDP Act?

A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data. The obligations of the Act fall primarily on the Data Fiduciary: giving notice, obtaining and honouring consent, keeping data accurate, protecting it with reasonable security safeguards, reporting breaches, and answering data principal requests.

Jupinder Bedi

A Data Processor, by contrast, processes personal data on behalf of a Data Fiduciary under contract. Engaging a processor does not transfer the obligation — the fiduciary remains answerable for the data.

The Data Principal is the individual to whom the personal data relates. Many organisations are a fiduciary for some data and a processor for other data at the same time; writing that split down is usually the first useful step in a programme.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Jupinder BediJupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →