A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data. The obligations of the Act fall primarily on the Data Fiduciary: giving notice, obtaining and honouring consent, keeping data accurate, protecting it with reasonable security safeguards, reporting breaches, and answering data principal requests.
A Data Processor, by contrast, processes personal data on behalf of a Data Fiduciary under contract. Engaging a processor does not transfer the obligation — the fiduciary remains answerable for the data.
The Data Principal is the individual to whom the personal data relates. Many organisations are a fiduciary for some data and a processor for other data at the same time; writing that split down is usually the first useful step in a programme.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →