At a glanceIf you decide why and how personal data is processed, you’re a Data Fiduciary under India’s DPDP Act — and the law’s core duties are yours. In plain terms: give people a clear notice, take valid consent, keep the data accurate and secure, tell people (and the regulator) about a breach, delete data when its purpose is over, run a grievance channel, and stay accountable — even for the vendors you hand data to. Size and industry don’t change this; deciding the purpose does.
Educational resource only. This explains a Data Fiduciary’s obligations under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The starting point
Most Indian businesses are Data Fiduciaries and don’t realise it — the label sounds technical, but it just means you’re the one deciding what happens to personal data. If you run a clinic, a coaching class, an agency, a shop, or an app and you collect customer, client, or employee data, this is almost certainly you. What follows is what the law then expects.
Are you actually a Data Fiduciary?
The test is control, not size: if you decide the purpose and the means of processing personal data, you’re a Data Fiduciary. It doesn’t matter whether you’re a solo consultant or a large company, a tech firm or a corner shop. The moment you decide why you’re collecting personal data and how you’ll use it, the role — and its duties — attach to you.
You’re not a Fiduciary for data you merely handle on someone else’s instructions (that’s a Data Processor), and you’re a Data Principal in your own right for your own personal data. But for the customer and client data your business runs on, you’re the Fiduciary. (For the full role map, see which DPDP role are you.)
The duties the Act puts on you
The Act’s general obligations for a Data Fiduciary (Section 8) come down to a short, concrete list. These are the things you must be able to show you do:
- Give notice and take consent. Before collecting personal data, give a clear notice of what and why, and obtain valid consent (or rely on a genuine legitimate use where one applies).
- Keep data accurate. Where data is used to make a decision about someone or shared with another Fiduciary, it must be correct and complete.
- Secure it. Put reasonable technical and organisational safeguards in place to prevent a breach.
- Report breaches. Notify the Data Protection Board of India and affected individuals if a personal data breach happens.
- Delete when done. Erase personal data once consent is withdrawn or the purpose is served, unless a law requires you to keep it.
- Publish a contact and a grievance route. Make it easy for people to reach you (a Data Protection Officer or named contact) and to raise grievances.
- Honour rights. Act on access, correction, and erasure requests from the people whose data you hold.
The one that surprises people: you answer for your vendors
You stay responsible for personal data even when a processor handles it for you — a contract can’t shift that away. This is the obligation businesses most often miss. Under the Act, a Data Fiduciary is responsible for compliance for processing done by it or on its behalf — so if your payroll vendor, cloud provider, or marketing agency mishandles data you gave them, the accountability still runs back to you.
Two practical consequences: you may engage a processor only under a valid contract, and you should choose and supervise vendors as if their breach were your breach — because to the regulator, it effectively is. This is why vendor due diligence isn’t box-ticking; it’s your own liability shield.
What “good” looks like day to day
Being a compliant Fiduciary is less about paperwork and more about a few habits that hold up under scrutiny. In practice:
- You collect only what you need, for a stated purpose, with consent you can prove later.
- You know where personal data sits, who you’ve shared it with, and under what contract.
- You have a working way for people to ask questions, raise grievances, and exercise rights — and you actually respond.
- You delete what you no longer need instead of hoarding it.
None of this requires a legal department; it requires knowing the data you hold and treating it as someone else’s, held in trust — which is what “fiduciary” means.
FAQ
Is every business a Data Fiduciary?
If it decides why and how it collects personal data, yes — regardless of size or sector. A business is not a Fiduciary only for data it processes purely on another organisation’s instructions.
Do I need consent for everything?
No — consent is the main basis, but some processing runs on defined “legitimate uses” (such as certain employment purposes). You still owe notice, security, and the other duties.
Am I responsible if my software vendor causes a breach?
Yes. Your accountability covers processing done on your behalf, and a contract can’t remove it. Choose and supervise processors accordingly.
What’s the first thing to get right?
Know what personal data you hold and why, then make sure you can show valid notice and consent for it. Most other duties build on that.