At a glanceOne test settles it: whoever decides why and how personal data is processed is the Data Fiduciary; whoever processes it on someone else’s instructions is the Data Processor. Decide the purpose — you’re the Fiduciary, and the law’s duties are yours. Just follow a client’s instructions — you’re their Processor, bound mainly by your contract with them. Most businesses are Fiduciaries for their own customer data, and can be Processors when they handle data for a client.
Educational resource only. This explains the Data Fiduciary and Data Processor roles under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
Why this is the confusing one
Fiduciary and Processor are the two roles businesses genuinely mix up — because a single company can be both, on different data. Sorting out which hat you’re wearing for which dataset is what makes the rest of your DPDP duties fall into place.
The one test that settles it
Ask a single question: who decides the purpose and the means of the processing? Whoever answers “we do” is the Data Fiduciary. Whoever is simply carrying out another organisation’s instructions — not setting the purpose themselves — is the Data Processor for that data.
The definitions sit in the Act (Section 2), but you rarely need them once you have the test. Decide why the data is collected and how it’s used → Fiduciary. Act on someone else’s why and how → Processor. Ownership of the decision, not possession of the data, is what draws the line.
What a Data Fiduciary is on the hook for
The Fiduciary carries the law’s full set of duties — and answers to the individuals. Notice, consent, accuracy, security, breach reporting, deletion, grievance handling, and honouring rights requests all sit with the Fiduciary. Critically, the Fiduciary stays accountable even for processing a Processor does on its behalf. If you’re the Fiduciary, the buck stops with you.
What a Data Processor is on the hook for
The Processor’s duties flow mainly from its contract with the Fiduciary — it doesn’t set the purpose, so it doesn’t carry the Fiduciary’s full load. A Processor may be engaged only under a valid contract, and must handle the data strictly for the Fiduciary’s stated purposes and instructions — keeping it secure, not repurposing it, and deleting it when the Fiduciary’s purpose ends. What a Processor must not do is quietly use that data for its own ends; the moment it decides its own purpose for the data, it becomes a Fiduciary for that use, with all the duties attached.
Worked examples
The same activity can put you on either side of the line — it depends on whose purpose you’re serving.
| You are… | For this data… | Your role |
|---|---|---|
| A marketing agency running a client’s campaign database | The client’s customer list | Processor (for the client) |
| The same agency, collecting leads for your own business | Your own prospects | Fiduciary |
| A cloud/SaaS provider hosting a company’s records | The customer’s stored data | Processor |
| A clinic collecting patient details to treat them | Patient data | Fiduciary |
| A payroll vendor processing salaries for an employer | The employer’s staff data | Processor (for the employer) |
Notice the agency appears twice: Processor for the client’s data, Fiduciary for its own. That dual position is normal — the role is decided per dataset, not per company.
Why getting it right matters
Your entire compliance load — duties, contracts, and liability — is set by which role you’re in for a given dataset. Misread it and you’ll either shoulder obligations that aren’t yours, or, more dangerously, skip the ones that are. A Fiduciary that thinks it’s “just a processor” can miss notice, consent, and breach-reporting duties it actually owes. Settle the role first; everything else follows from it.
FAQ
Can a company be both a Fiduciary and a Processor?
Yes — commonly. You’re a Fiduciary for your own customer and staff data, and a Processor for any client data you handle on their instructions. The role is decided per dataset.
If I only store data for a client, am I a Processor?
Generally yes, provided you act on their instructions and don’t decide your own purpose for the data. Using it for your own ends would make you a Fiduciary for that use.
Does a Processor need consent from individuals?
No — the Fiduciary obtains consent. The Processor acts under its contract with the Fiduciary and must stay within the stated purpose.
Who is liable if a Processor causes a breach?
The Fiduciary remains accountable to individuals and the regulator, while the Processor answers to the Fiduciary under their contract. (See the vendor-responsibility guide.)