Confidential Dispatch

Are you a Data Processor handling data for clients? Your duties when it isn't your data

4 min readUpdated 2026-07-04
On this page
  1. 01When you’re acting as a Processor
  2. 02What you must do — even though it isn’t your data
  3. 03The line you can’t cross without becoming a Fiduciary
  4. 04What your client’s contract should cover
  5. 05FAQ
At a glance

If you handle personal data on a client’s instructions — an agency running their CRM, a freelancer building their app, a SaaS tool storing their records — you’re acting as a Data Processor under India’s DPDP Act. You don’t carry the full set of a Data Fiduciary’s duties, but you are bound by your contract with the client: process the data only for their stated purpose, keep it secure, don’t reuse it for your own ends, and delete it when they say. The moment you decide your own purpose for that data, you become a Fiduciary for it.

Educational resource only. This explains a Data Processor’s duties under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.

The situation

You’re an agency, a freelance developer, or a small SaaS, and clients hand you their customers’ data to work with. It isn’t your data — so it’s easy to assume DPDP is your client’s problem, not yours. It’s partly theirs and partly yours, and knowing your slice keeps you out of trouble (and makes you easier to hire).

When you’re acting as a Processor

You’re a Processor whenever you handle personal data on a client’s instructions, for the client’s purpose — not one you set. Typical cases: an agency operating a client’s email list or ad audience, a developer working on a client’s user database, a payroll or analytics vendor, a cloud host storing a client’s records. In each, the client (the Data Fiduciary) decided why and how; you’re carrying it out.

You can hold both roles at once, though: you’re a Processor for that client data, and a Data Fiduciary for your own business data — your staff, your own customers, your leads. This page is about the Processor hat.

What you must do — even though it isn’t your data

Your obligations run through your contract with the Fiduciary, and they’re real. As a Processor you must:

  • Work only under a valid contract. The Act allows a Fiduciary to engage you only under one, so expect (and want) a written agreement — it defines and limits your exposure.
  • Stick to the stated purpose. Use the data strictly for what the client engaged you to do — nothing more.
  • Keep it secure. Apply proper safeguards; a breach on your watch is both a contract failure and something your client answers to the regulator for.
  • Help with rights and breaches. Support the Fiduciary when an individual exercises a right, or when a breach must be reported — you’re often the one who has to surface the facts.
  • Delete or return data when the purpose ends. Don’t keep client data after the engagement is over.

The line you can’t cross without becoming a Fiduciary

The instant you use a client’s data for your own purpose, you stop being a mere Processor and become a Fiduciary for that use — with all the duties. Reusing a client’s customer list to market your own services, training your own product on their data, or enriching your own database from theirs are all your-purpose decisions. Do that, and you’ve stepped over the line and taken on Fiduciary obligations (and liability) for it. Staying a Processor means staying strictly inside the client’s instructions.

What your client’s contract should cover

A clear Data Processing Agreement protects you as much as the client — insist on one. At minimum it should pin down: the purpose and scope of what you may do; security expectations; whether you may use sub-processors; how you’ll support rights requests and breach reporting; and what happens to the data when the engagement ends. A vague contract leaves you carrying undefined risk; a precise one draws the boundary of your responsibility.

FAQ

Do I have DPDP duties if the data belongs to my client?

Yes — as a Processor you must handle it only for the client’s purpose, keep it secure, support rights and breach obligations, and delete it when done. Those duties run through your contract.

Do I need a contract to process a client’s data?

Effectively yes. The Act lets a Fiduciary engage a Processor only under a valid contract, so you should expect a written agreement — it’s also your protection.

Can I use a client’s data to promote my own services?

No — that’s using the data for your own purpose, which makes you a Fiduciary for that use, with the full duties. Stay within the client’s instructions.

Am I liable to the individuals directly?

The Fiduciary is primarily accountable to individuals and the regulator; you answer to the Fiduciary under your contract. But a security failure on your side has real consequences for both of you.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →