At a glanceIndia’s DPDP Act defines four roles, and your obligations depend on which you are. The Data Principal is the individual the data is about. The Data Fiduciary is whoever decides why and how personal data is processed — and carries the duties. A Data Processor processes data on a fiduciary’s behalf, under contract. A Significant Data Fiduciary (SDF) is a fiduciary the government notifies as high-volume or high-risk, with extra obligations. Most businesses are Data Fiduciaries.
Educational resource only. This explains the roles defined under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) so you can place yourself; it is not formal legal advice.
Why the role is the first thing to get right
Your duties, liability and paperwork under the Act all flow from which role you occupy — so this is the question to settle before any compliance work.
The DPDP Act assigns responsibilities by role (the definitions are in Section 2). Get the role wrong and you’ll either take on duties that aren’t yours or, more dangerously, miss the ones that are. The good news: for most organisations the answer is clear once you know what each role means. Each role below has its own detailed guide in this section.
Data Principal — the individual
The Data Principal is the person the personal data is about — the holder of the rights.
If your data is being collected, you’re a Data Principal. This is the role every individual occupies: the one who gives or withdraws consent, and who can ask to access, correct or delete their data. Businesses have Data Principals (their customers, clients, employees) — but the business itself isn’t one when it’s the party deciding how that data is used.
Data Fiduciary — the one who decides (and answers for it)
If you decide why and how personal data is processed, you’re a Data Fiduciary — and the Act’s duties are yours.
This is the role most businesses occupy. A clinic, a coaching class, a shop, an app, a solo consultant — anyone who determines the purpose and means of processing personal data is a Data Fiduciary. It’s not about being a tech company or a certain size; it’s about being the one calling the shots on the data. The Fiduciary carries the obligations: give notice, obtain consent, secure the data, limit retention, and honour rights requests. When something goes wrong, the Fiduciary answers for it.
Data Processor — acting on someone else’s behalf
A Data Processor handles data for a Fiduciary, under contract — it doesn’t decide the purpose itself.
If you process personal data on behalf of another organisation and to their instructions — a payroll vendor, a cloud provider, an agency running a client’s CRM — you’re acting as a Data Processor for that data. The Fiduciary you work for stays primarily responsible to the individuals, but you’re bound by your contract with them to handle the data properly. The key distinction: a Processor follows instructions; a Fiduciary sets them.
Significant Data Fiduciary — the heavier tier
An SDF is a Data Fiduciary the government designates as higher-risk, with extra obligations on top.
The government can notify certain Fiduciaries as Significant Data Fiduciaries (Section 10), based on factors like the volume and sensitivity of data they handle and the risks involved. An SDF carries additional duties — such as appointing a Data Protection Officer (DPO) based in India, conducting Data Protection Impact Assessments (DPIAs), and independent audits. You don’t self-declare into this tier; you fall into it if you meet the notified criteria — so the practical question is “does my scale trigger it?”
You can be more than one
Roles aren’t exclusive — you’re a Data Principal in your own life and a Data Fiduciary in your business.
Most business owners occupy two roles at once: a Data Principal when a company holds their data, and a Data Fiduciary for the customer data they hold. Agencies and SaaS providers can be a Processor for a client’s data and a Fiduciary for their own (their staff, their own customers). Being clear about which hat you’re wearing for which dataset is what makes the rest of compliance tractable — see the role-specific guides in this section to go deeper.
FAQ
Is my small business a Data Fiduciary?
Almost certainly, if you decide why and how you collect customer or client data. The role doesn’t depend on size or being a tech company.
What’s the difference between a Fiduciary and a Processor?
A Fiduciary decides the purpose and means of processing; a Processor acts on a Fiduciary’s instructions under contract. Whoever calls the shots on the data is the Fiduciary.
How do I know if I’m a Significant Data Fiduciary?
You’re an SDF only if the government notifies you as one, based on criteria like data volume, sensitivity and risk. Most small and mid-sized businesses won’t meet the threshold.
Can I be both a Data Principal and a Data Fiduciary?
Yes. You’re a Principal for your own personal data and a Fiduciary for the data your business holds about others — the roles apply per dataset.