Confidential Dispatch

Your personal and business liability as a Data Fiduciary, explained

5 min readUpdated 2026-07-04
On this page
  1. 01Who actually bears the liability?
  2. 02What you can be penalised for
  3. 03Company vs proprietor: where “personal” really bites
  4. 04Beyond fines: the costs the penalty table doesn’t show
  5. 05How to limit your exposure
  6. 06FAQ
At a glance

As a Data Fiduciary you carry the accountability for the personal data you hold — and a contract can’t move it elsewhere. If you breach the DPDP Act, the Data Protection Board of India can impose financial penalties (up to ₹250 crore at the top tier) after an inquiry, and that money goes to the government, not to the affected people. For a company, the company bears the penalty; for a sole proprietor or solo professional, business and personal liability are the same thing — because you and the business are one legal person.

Educational resource only. This explains a Data Fiduciary’s liability under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.

The starting point

Liability is the part of DPDP that makes owners sit up — and it’s worth understanding precisely rather than fearfully. The exposure is real, but it’s specific: it attaches to the Fiduciary, it’s decided by the regulator after an inquiry, and it scales with the seriousness of what went wrong.

Who actually bears the liability?

The accountability sits with the Data Fiduciary, and the Act makes it non-delegable. Under the Act, a Fiduciary is responsible for compliance for processing done by it or on its behalfirrespective of any agreement to the contrary (Section 8). So you can’t sign the responsibility away to a vendor or a customer. If you decided the purpose for the data, you answer for it.

That’s the outward-facing position: to the individual whose data it is, and to the Data Protection Board of India, the Fiduciary is the responsible party. A processor you hired answers to you under your contract, but it doesn’t absorb your accountability.

What you can be penalised for

Penalties attach to breaches of your duties — with the largest reserved for security failures that cause a data breach. The Act sets tiered financial penalties (up to ₹250 crore for failing to take reasonable security safeguards, with lower ceilings for other breaches), imposed by the Board after an inquiry and scaled to the gravity of what happened. Two features matter for how you think about risk:

  • They’re maximums, weighed case by case — a small, quickly-fixed lapse and a large, ignored failure are treated very differently.
  • They go to the government, not to victims — DPDP penalties are not compensation paid to the affected individuals.

The dedicated penalties guide breaks down the tiers; the point here is that liability is a function of which duty you breached and how bad it was.

Company vs proprietor: where “personal” really bites

Whether liability touches you personally depends on your business structure — and this is the distinction most owners miss.

  • If you operate as a company or LLP, the entity is the Data Fiduciary and bears the penalty. The Act penalises the Fiduciary; it does not impose broad automatic personal liability on directors the way some other laws do. Your corporate structure does real work here.
  • If you’re a sole proprietor or a solo professional, there’s no separate legal entity between you and your business — so you are the Fiduciary. Business liability and personal liability are the same thing; a penalty against “the business” is a penalty against you.

This is a genuine reason for solo operators to be deliberate about compliance: you don’t have an entity absorbing the exposure on your behalf.

Beyond fines: the costs the penalty table doesn’t show

The financial penalty is often not the biggest cost of getting this wrong. A breach or a finding against you can also bring: loss of customer trust (hard to rebuild for a business that handles personal data), lost clients and deals (B2B buyers increasingly vet their vendors’ data practices), the operational cost of cleaning up and responding, and management time pulled into an inquiry. For many small and mid-sized businesses, the reputational hit outlasts the fine.

How to limit your exposure

You reduce liability the same way you meet the duties — by handling less data, more carefully, and being able to prove it. Practically:

  • Minimise. The less personal data you hold, the less there is to breach.
  • Secure and document. Reasonable safeguards, and records that show valid notice and consent — your evidence if you’re ever questioned.
  • Manage vendors. Contract properly and diligence anyone you share data with; their breach is your accountability.
  • Have a breach plan. Knowing how you’ll detect and report a breach limits the damage if one happens.
  • Consider your structure. For a growing solo operation, how you’re incorporated affects whether liability is personal — a question worth raising with your accountant or lawyer.

FAQ

Can I be held personally liable under the DPDP Act?

If you’re a sole proprietor or solo professional, yes — you are the Fiduciary, so business liability is personal. For a company or LLP, the entity bears the penalty, and the Act doesn’t impose broad automatic personal liability on directors.

Can a contract shift my liability to a vendor?

Not your accountability to individuals and the regulator — that holds irrespective of any agreement. A contract lets you recover from a vendor afterwards; it doesn’t move your front-line responsibility.

How large can the penalties be?

Up to ₹250 crore at the top tier (for security failures causing a breach), with lower ceilings for other breaches. They’re maximums, set by the Board case by case, and paid to the government, not to victims.

What’s the most cost-effective way to reduce my risk?

Hold less data, secure and document what you keep, manage your vendors, and have a breach plan. Minimisation is the cheapest liability reduction there is.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →