Confidential Dispatch

Data Fiduciary vs Data Processor: which one are you?

4 min readUpdated 2026-07-04
On this page
  1. 01The one test that settles it
  2. 02What a Data Fiduciary is on the hook for
  3. 03What a Data Processor is on the hook for
  4. 04Worked examples
  5. 05Why getting it right matters
  6. 06FAQ
At a glance

One test settles it: whoever decides why and how personal data is processed is the Data Fiduciary; whoever processes it on someone else’s instructions is the Data Processor. Decide the purpose — you’re the Fiduciary, and the law’s duties are yours. Just follow a client’s instructions — you’re their Processor, bound mainly by your contract with them. Most businesses are Fiduciaries for their own customer data, and can be Processors when they handle data for a client.

Educational resource only. This explains the Data Fiduciary and Data Processor roles under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.

Why this is the confusing one

Fiduciary and Processor are the two roles businesses genuinely mix up — because a single company can be both, on different data. Sorting out which hat you’re wearing for which dataset is what makes the rest of your DPDP duties fall into place.

The one test that settles it

Ask a single question: who decides the purpose and the means of the processing? Whoever answers “we do” is the Data Fiduciary. Whoever is simply carrying out another organisation’s instructions — not setting the purpose themselves — is the Data Processor for that data.

The definitions sit in the Act (Section 2), but you rarely need them once you have the test. Decide why the data is collected and how it’s used → Fiduciary. Act on someone else’s why and how → Processor. Ownership of the decision, not possession of the data, is what draws the line.

What a Data Fiduciary is on the hook for

The Fiduciary carries the law’s full set of duties — and answers to the individuals. Notice, consent, accuracy, security, breach reporting, deletion, grievance handling, and honouring rights requests all sit with the Fiduciary. Critically, the Fiduciary stays accountable even for processing a Processor does on its behalf. If you’re the Fiduciary, the buck stops with you.

What a Data Processor is on the hook for

The Processor’s duties flow mainly from its contract with the Fiduciary — it doesn’t set the purpose, so it doesn’t carry the Fiduciary’s full load. A Processor may be engaged only under a valid contract, and must handle the data strictly for the Fiduciary’s stated purposes and instructions — keeping it secure, not repurposing it, and deleting it when the Fiduciary’s purpose ends. What a Processor must not do is quietly use that data for its own ends; the moment it decides its own purpose for the data, it becomes a Fiduciary for that use, with all the duties attached.

Worked examples

The same activity can put you on either side of the line — it depends on whose purpose you’re serving.

You are… For this data… Your role
A marketing agency running a client’s campaign database The client’s customer list Processor (for the client)
The same agency, collecting leads for your own business Your own prospects Fiduciary
A cloud/SaaS provider hosting a company’s records The customer’s stored data Processor
A clinic collecting patient details to treat them Patient data Fiduciary
A payroll vendor processing salaries for an employer The employer’s staff data Processor (for the employer)

Notice the agency appears twice: Processor for the client’s data, Fiduciary for its own. That dual position is normal — the role is decided per dataset, not per company.

Why getting it right matters

Your entire compliance load — duties, contracts, and liability — is set by which role you’re in for a given dataset. Misread it and you’ll either shoulder obligations that aren’t yours, or, more dangerously, skip the ones that are. A Fiduciary that thinks it’s “just a processor” can miss notice, consent, and breach-reporting duties it actually owes. Settle the role first; everything else follows from it.

FAQ

Can a company be both a Fiduciary and a Processor?

Yes — commonly. You’re a Fiduciary for your own customer and staff data, and a Processor for any client data you handle on their instructions. The role is decided per dataset.

If I only store data for a client, am I a Processor?

Generally yes, provided you act on their instructions and don’t decide your own purpose for the data. Using it for your own ends would make you a Fiduciary for that use.

Does a Processor need consent from individuals?

No — the Fiduciary obtains consent. The Processor acts under its contract with the Fiduciary and must stay within the stated purpose.

Who is liable if a Processor causes a breach?

The Fiduciary remains accountable to individuals and the regulator, while the Processor answers to the Fiduciary under their contract. (See the vendor-responsibility guide.)

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →