Confidential Dispatch

What is a Data Processor?

1 min readUpdated 2026-07-02

A Data Processor is any person or business that processes personal data on behalf of a Data Fiduciary — on the fiduciary’s instructions, not for its own purposes. Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the processor is the hired hand: it handles the data to do a job the fiduciary set, and doesn’t decide why the data is used.

Educational resource only — not legal advice.

Think of a clinic (the Data Fiduciary) that uses an outside billing service or a cloud tool to store patient records. Those vendors are Data Processors — they act under a contract, for the clinic’s stated purpose, and only within it.

Why it matters to you. If you process data for clients — an agency, a SaaS tool, an outsourced back-office — you may be a Data Processor rather than a Data Fiduciary, and your duties run to your client’s instructions. If you’re the fiduciary, you stay accountable for what your processors do, and must be able to have them erase data when it’s required.

What it is not. A Data Processor is not a Data Fiduciary: it doesn’t decide the purpose or means of processing. Accountability to the individual sits with the fiduciary — though the processor still carries its own security obligations.

Reviewed by Confidential Dispatch Editorial Team
Last updated 2 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →