What is a Data Fiduciary under DPDP — definition and responsibilities

What is a Data Fiduciary under DPDP — definition and responsibilities
Concepts

What is a Data Fiduciary under DPDP — definition and responsibilities

The Data Fiduciary sits at the centre of every DPDP obligation. Here is exactly what the term means and what responsibilities it carries.

Quick Answer: Under the DPDP Act 2023, a Data Fiduciary is any person, company, or state entity that alone or jointly with others determines the purpose and means of processing personal data. If you decide what personal data to collect and why, you are a Data Fiduciary — regardless of whether you physically process the data yourself or hire someone else to do it. As a Data Fiduciary you must: issue a privacy notice before collecting data; obtain and manage consent where required; honour data principal rights; implement security safeguards; notify the Board of breaches; enter into Data Processing Agreements with any Data Processor you engage; and delete data after the purpose is served. Almost every company in India that deals with customers, employees, or users is a Data Fiduciary.

Who qualifies as a Data Fiduciary under the DPDP Act?

Any entity — a company, LLP, partnership, individual, or government body — that determines the purpose and means of processing personal data is a Data Fiduciary. The test is control over the 'why' and 'how'. If you are a startup that decides to build a customer database, you are the Fiduciary for that database. If you are an employer who decides to collect employee attendance using biometrics, you are the Fiduciary for that biometric data. If you are a hospital that decides what patient data to collect in its EHR, you are the Fiduciary for that patient data.

What is the difference between a Data Fiduciary and a Data Processor?

A Data Processor processes personal data on behalf of and under the instructions of a Data Fiduciary. The Processor does not decide why the data is collected or what it is used for — it simply carries out the Fiduciary's instructions. Examples: a payroll outsourcing company that processes employee salary data on your instructions is a Processor; a cloud hosting company that stores your customer database is a Processor. If you use a CRM platform, you are the Fiduciary; the CRM vendor is the Processor. The Fiduciary-Processor distinction determines who holds the compliance obligations.

Can an organisation be both a Data Fiduciary and a Data Processor?

Yes. An IT services company may be a Data Processor when processing client data under a contract, and a Data Fiduciary for its own employee data and internal operations. A bank may be a Data Fiduciary for its customers' financial data, and a Data Processor for insurance data it processes on behalf of a bancassurance partner. Maintain clear internal records of which role you occupy for each data flow — your compliance obligations differ significantly between the two roles.

What are the core obligations of a Data Fiduciary?

A Data Fiduciary must: (1) Provide a Notice to data principals before or at the time of collecting personal data; (2) Obtain Consent where required; (3) Ensure personal data is used only for the stated purpose; (4) Implement security safeguards proportionate to the risk; (5) Notify the Board and affected data principals of breaches; (6) Honour data principal rights (access, correction, erasure, nomination, grievance); (7) Enter into DPAs with any Data Processor; (8) Delete personal data once the purpose is served; and (9) Comply with cross-border transfer restrictions.

Are there any exemptions from Data Fiduciary obligations under DPDP?

The Act provides limited exemptions: the government may exempt certain state instrumentalities from specific obligations for reasons of national security or public order. Certain processing for research, archiving, or statistical purposes may also be subject to modified rules under government notification. There is no exemption based on company size, revenue, or number of employees — a sole proprietor running an e-commerce store is a Data Fiduciary with the same core obligations as a multinational corporation, calibrated to the scale of their processing.

What happens if you do not comply with Data Fiduciary obligations?

The Data Protection Board can: investigate on its own motion or on complaint; impose financial penalties of up to ₹250 crore for the most serious failures; direct remediation of processing practices; and require notification to affected data principals. Board orders are publicly available — reputational consequences of enforcement orders are significant for consumer-facing businesses. Directors and senior officers may face personal accountability for wilful or deliberate non-compliance under provisions the government may prescribe.

Frequently asked questions

Is an individual freelancer a Data Fiduciary?

If a freelancer collects and processes personal data to deliver their services — for example, a freelance HR consultant who maintains a database of candidates, or a freelance accountant who holds client tax records — they are a Data Fiduciary for that data. The DPDP Act does not exempt individuals from its application. However, the scale and risk of a freelancer's processing is very different from a large corporation, and the Board's enforcement priorities are expected to focus on higher-risk processing first.

Does joint Data Fiduciary status exist under DPDP?

The Act uses the phrase 'alone or jointly with others determines the purpose and means' — acknowledging that two or more entities can jointly determine purpose and means, creating joint Fiduciary status. For example, a co-branded loyalty programme where two companies jointly decide what customer data to collect and how to use it would create joint Fiduciary obligations on both companies. Joint Fiduciaries should define between themselves who handles each compliance obligation — consent management, breach notification, rights responses — and document this in their agreement.

Are government bodies Data Fiduciaries under DPDP?

Yes. The DPDP Act applies to both private and government data processing. Government bodies that collect and process personal data — for welfare programmes, tax collection, land records — are Data Fiduciaries. However, the government has broad power to exempt its own instrumentalities from specific obligations for reasons of national security, law enforcement, or public order. The extent of these exemptions will become clearer when the Rules and any exemption notifications are published.

Understand your DPDP obligations as a Data Fiduciary

Niti Bharat's DPDP Readiness Assessment maps your organisation's Data Fiduciary obligations across all data flows — consent, notice, security, vendor DPAs, and rights mechanisms.

Start Fiduciary Assessment
Previous Post Next Post

Get Free DPDP Checklist