A Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 is a person or organization that, alone or jointly with others, decides the purpose and means of processing personal data. In practical terms, the entity deciding why personal data is needed and how it will be collected, used, stored, shared, or erased is the Data Fiduciary.
Data Fiduciary obligations cover lawful processing, notice, consent, processor oversight, accuracy in specified situations, security safeguards, breach notification, retention and erasure, Data Principal rights, grievance redressal, and children’s data. Significant Data Fiduciaries have additional governance, audit, DPO, and DPIA duties.
Compliance timing matters. As of 3 August 2026, the DPDP definition provisions are in force, while the principal operational obligations in Sections 3 to 17 are scheduled to commence on 13 May 2027. Businesses should use the transition period to implement controls and create audit-ready evidence rather than waiting for the final commencement date.
What Is a Data Fiduciary Under the DPDP Act?
A Data Fiduciary is any person who, alone or together with other persons, determines the purpose and means of processing personal data. The term is defined in Section 2(i) of the Digital Personal Data Protection Act, 2023.
The simplest test is to ask two questions: Why is this personal data being processed? and Who decides how the processing will take place? The entity making those decisions is generally the Data Fiduciary for that processing activity.
Data Fiduciary Meaning in Simple Terms
A Data Fiduciary is the organization responsible for the decisions made about an individual’s digital personal data. It may collect the data directly or use another company to process it, but it remains accountable for processing carried out by it or on its behalf.
Official reference: Digital Personal Data Protection Act, 2023.
What Are Examples of Data Fiduciaries?
An organization’s role depends on the processing activity, not only on its industry or company type. The same organization may be a Data Fiduciary for one activity and a Data Processor for another.
| Processing activity | Likely Data Fiduciary | Why |
|---|---|---|
| Opening a bank account | Bank | The bank decides which KYC data is required and how it will be used for account opening and regulatory compliance. |
| Managing employee records | Employer | The employer determines why payroll, attendance, performance, and benefits data is processed. |
| Providing medical treatment | Hospital or healthcare provider | The provider determines how patient data is collected and used to deliver care. |
| Operating an e-commerce marketplace | Marketplace operator | The operator decides how account, order, payment, and delivery data supports the service. |
| Running an educational platform | School, university, or edtech provider | The entity determines the purposes for processing student and guardian data. |
| Recruiting job applicants | Employer or recruitment company | The organization decides how applicant information is evaluated and retained. |
| Managing a customer loyalty programme | Retailer or brand | The organization determines the purpose and method of profiling purchases and administering rewards. |
For each business process, document the Data Fiduciary, any joint decision-makers, the processors involved, the specified purpose, personal data categories, systems, recipients, retention period, and control owner.
How Do You Know Whether Your Business Is a Data Fiduciary?
Your organization is likely acting as a Data Fiduciary when it makes one or more of the following decisions:
- Which personal data must be collected
- The business or legal purpose for collecting it
- Which individuals are covered by the processing
- How the data will be used, analysed, combined, or disclosed
- Which employees, systems, vendors, or recipients may access it
- How long the data should be retained
- When data should be corrected, restricted, archived, or erased
- Which security and privacy controls should apply
Can Two Organizations Be Data Fiduciaries Together?
Yes. The statutory definition covers a person acting alone or in conjunction with other persons. Where two organizations jointly determine the purpose and means of processing, teams should document their respective decisions, responsibilities, notices, request-handling duties, breach coordination, and contractual allocation of work.
Data Fiduciary vs Data Processor, Data Principal, and Consent Manager
These DPDP roles are connected but are not interchangeable. Correctly mapping them is the foundation of privacy notices, contracts, rights workflows, risk ownership, and audit evidence.
| Role | Core meaning | Decision-making position | Example |
|---|---|---|---|
| Data Fiduciary | Determines the purpose and means of processing personal data | Decides why and how processing occurs | A bank deciding how customer KYC data is processed |
| Data Processor | Processes personal data on behalf of a Data Fiduciary | Acts under the Fiduciary’s instructions and contract | A cloud or payroll provider processing data for a client |
| Data Principal | The individual to whom the personal data relates | Exercises rights and performs duties under the Act | A customer, employee, applicant, patient, or user |
| Consent Manager | A person registered with the Board that enables individuals to give, manage, review, and withdraw consent | Provides an accessible, transparent, and interoperable consent-management interface | A Board-registered consent-management service |
Does Using a Data Processor Transfer the Data Fiduciary’s Liability?
No. Section 8 states that the Data Fiduciary remains responsible for compliance in relation to processing undertaken by it or on its behalf by a Data Processor. Outsourcing the activity does not outsource statutory accountability.
Read also: Vendor Risk Management Under DPDP.
Data Fiduciary vs Data Controller: What Is the Difference?
A Data Fiduciary under India’s DPDP Act and a Data Controller under the EU GDPR perform broadly comparable decision-making roles because both determine the purposes and means of processing. However, the terms arise under different laws, and their detailed obligations should not be treated as identical.
| Area | Data Fiduciary | Data Controller |
|---|---|---|
| Legal framework | India’s DPDP Act | EU GDPR |
| Individual | Data Principal | Data Subject |
| Core role | Determines purpose and means of processing | Determines purposes and means of processing |
| Processing partner | Data Processor | Processor |
| Primary compliance focus | DPDP notice, consent or certain legitimate uses, safeguards, rights, erasure, breach response, and accountability | GDPR lawful bases, transparency, rights, security, accountability, and cross-border requirements |
A multinational organization may be a Data Fiduciary under the DPDP Act and a Data Controller under the GDPR for the same or related processing, depending on territorial scope and applicable law.
When Do Data Fiduciary Obligations Take Effect?
The DPDP framework is being implemented in phases. Businesses should distinguish between provisions already in force and obligations scheduled to commence later.
| Date | Key position | Business implication |
|---|---|---|
| 13 November 2025 | Section 2 definitions and selected institutional and procedural provisions commenced; Rules 1, 2, and 17 to 21 commenced | Organizations can formally map statutory roles and prepare against the notified framework |
| 13 November 2026 | Rule 4 on Consent Manager registration and obligations is scheduled to commence | Relevant Consent Manager applicants should prepare for registration and operating requirements |
| 13 May 2027 | Sections 3 to 17 and most operational Rules, including Rules 3 and 5 to 16, are scheduled to commence | Core Data Fiduciary obligations become operational under the notified timeline |
As of 3 August 2026, organizations are still within the implementation period for most operational Data Fiduciary duties. This is a readiness window, not a reason to delay. Data discovery, notices, consent records, vendor contracts, security safeguards, rights workflows, retention rules, breach procedures, and evidence repositories require cross-functional implementation time.
See the official DPDP Rules and enforcement timeline.
What Are the Main Obligations of a Data Fiduciary?
A Data Fiduciary must convert the DPDP Act and Rules into repeatable legal, operational, security, and governance controls. The following duties form the core compliance programme.
1. Process Personal Data for a Lawful Purpose
Personal data may be processed for a lawful purpose based on the Data Principal’s consent or for certain legitimate uses permitted by Section 7. Teams should record the applicable ground for every processing purpose instead of treating consent as the only possible basis.
2. Give a Clear DPDP Notice
The notice should help the individual understand the personal data involved, the specified purpose, how consent may be withdrawn, how rights may be exercised, and how a complaint may be made. The Rules require the notice to be independently understandable and written in clear and simple language.
Read also: DPDP Consent and Notice Requirements.
3. Obtain and Manage Valid Consent Where Required
Consent must be free, specific, informed, unconditional, and unambiguous, shown through clear affirmative action, and limited to personal data necessary for the specified purpose. The Data Fiduciary must also make consent withdrawal as easy as giving consent and stop processing based on consent within a reasonable time after withdrawal, subject to lawful retention or another applicable ground.
Read also: Managing Consent Withdrawal Under DPDP.
4. Remain Accountable for Processing by Data Processors
A Data Processor may be used only under a valid contract for processing connected with offering goods or services to Data Principals. The Data Fiduciary remains responsible for compliance and should establish instructions, access limits, confidentiality, safeguards, incident escalation, deletion, audit, and return-of-data requirements.
5. Ensure Accuracy, Completeness, and Consistency Where Required
The DPDP Act does not impose an unlimited accuracy obligation for every record. The Data Fiduciary must ensure completeness, accuracy, and consistency where personal data is likely to be used to make a decision affecting the Data Principal or disclosed to another Data Fiduciary.
6. Implement Technical and Organisational Measures
Appropriate technical and organisational measures should make compliance operational across systems and teams. Examples include role-based access, purpose controls, data classification, approval workflows, monitoring, retention rules, request routing, training, control testing, and evidence management.
7. Apply Reasonable Security Safeguards
The Rules specify minimum safeguards such as encryption, obfuscation, masking or tokenisation, access controls, logs and monitoring, investigation and remediation capabilities, backups and continuity measures, processor-contract safeguards, and appropriate technical and organisational measures.
Read also: DPDP Data Security Controls.
8. Notify Personal Data Breaches
The Data Fiduciary must notify affected Data Principals without delay in the prescribed manner and notify the Data Protection Board. The Rules require an initial intimation to the Board without delay and updated detailed information within 72 hours of becoming aware of the breach, unless the Board permits a longer period on written request.
Read also: DPDP Data Breach Notification.
9. Erase Personal Data When It Is No Longer Required
Unless retention is required by law, a Data Fiduciary must erase personal data when consent is withdrawn or when it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier. It must also cause its Data Processor to erase the personal data made available for processing.
Retention and erasure should be governed by purpose, legal requirements, system dependencies, processor copies, backups, litigation holds, and documented exceptions. The Rules also introduce specific retention and log requirements that must be reconciled with erasure obligations.
Read also: Data Retention Policy Guide.
10. Publish Contact Information
Every Data Fiduciary must prominently publish the business contact information of its Data Protection Officer, where applicable, or another person able to answer questions about personal data processing. The contact details should also appear in responses concerning the exercise of Data Principal rights.
11. Establish Rights and Grievance Workflows
Data Fiduciaries must provide accessible means for Data Principals to exercise access, correction, erasure, grievance, and nomination rights under the Act. The Rules require the grievance redressal period published by the organization to be reasonable and not exceed 90 days.
The 90-day period should not be described as one universal deadline for every access, correction, or erasure request. Rule 14(3) specifically addresses the period published under the grievance redressal system.
Read also: Data Principal Rights Under DPDP.
12. Protect Children’s Personal Data
Before processing a child’s personal data, a Data Fiduciary must obtain verifiable parental consent, subject to notified exemptions and conditions. It must not undertake processing likely to cause a detrimental effect on the child’s well-being or tracking, behavioural monitoring, or targeted advertising directed at children, subject to the Act and prescribed exemptions.
13. Govern Cross-Border Personal Data Transfers
A Data Fiduciary should map where personal data and remote access travel outside India. Section 16 permits transfers subject to restrictions notified by the Central Government, while Rule 15 requires compliance with any general or special government requirements concerning availability of personal data to a foreign State or an entity under its control. Significant Data Fiduciaries may also face restrictions for specified personal data and related traffic data.
What Must a Data Fiduciary Do About Processors and Vendors?
Processor governance is a direct Data Fiduciary responsibility because the Fiduciary remains accountable for processing performed on its behalf. A vendor list alone is not sufficient; organizations need a lifecycle covering onboarding, due diligence, contracting, access, monitoring, incidents, changes, renewal, and offboarding.
Processor Contract and Oversight Checklist
- Document the processing purpose, scope, duration, data categories, and Data Principal groups
- Restrict processing to documented instructions
- Define access control, confidentiality, and security safeguards
- Require timely notification of suspected or confirmed incidents
- Define support for Data Principal rights and data discovery
- Specify retention, deletion, return, and backup-handling requirements
- Control sub-processors and material processing changes
- Address audit evidence, assurance reports, testing, and remediation
- Map cross-border access and transfer dependencies
- Terminate credentials and verify data disposition during offboarding
Cloud providers, SaaS applications, payroll vendors, contact centres, analytics services, marketing platforms, payment service providers, managed security providers, and document-storage providers may all process personal data on behalf of a Data Fiduciary.
What Security Safeguards Must Data Fiduciaries Implement?
Reasonable security safeguards should protect confidentiality, integrity, and availability across the complete processing lifecycle, including processing performed by vendors. The notified Rules provide a practical minimum baseline rather than leaving the requirement entirely abstract.
- Encryption, masking, obfuscation, or tokenisation where appropriate
- Identity and access management with least-privilege controls
- Logging, monitoring, review, and unauthorised-access detection
- Investigation, containment, remediation, and recurrence prevention
- Backups, recovery, and continuity measures
- Security clauses in Data Processor contracts
- Documented technical and organisational measures
- Evidence that safeguards are operating, reviewed, and improved
The Rules require specified security logs and personal data to be retained for one year for detection, investigation, remediation, recurrence prevention, and continuity purposes, unless another law requires otherwise. Retention controls should distinguish these prescribed records from data that should otherwise be erased.
What Is a Significant Data Fiduciary?
A Significant Data Fiduciary, or SDF, is a Data Fiduciary or class of Data Fiduciaries notified by the Central Government under Section 10. A business does not become an SDF merely because it considers itself large or processes a high volume of data; designation depends on government notification following an assessment of relevant factors.
Factors Used to Assess Significant Data Fiduciaries
- Volume and sensitivity of personal data processed
- Risk to the rights of Data Principals
- Potential impact on the sovereignty and integrity of India
- Risk to electoral democracy
- Security of the State
- Public order
Additional Obligations of a Significant Data Fiduciary
- Appoint a Data Protection Officer based in India
- Make the DPO responsible to the board of directors or a similar governing body
- Use the DPO as the point of contact for grievance redressal
- Appoint an independent data auditor
- Conduct periodic Data Protection Impact Assessments
- Conduct periodic compliance audits
- Undertake the additional measures prescribed under the Rules
Under Rule 13, an SDF must conduct a DPIA and audit once in every 12-month period from its notification or inclusion in a notified class. It must also perform due diligence regarding technical measures, including algorithmic software, so that their use is not likely to pose a risk to Data Principal rights.
Read also: DPDP DPIA Requirements.
What Are the Penalties for Data Fiduciary Non-Compliance?
The Data Protection Board may impose a monetary penalty after determining that a breach is significant and giving the person an opportunity to be heard. The Schedule sets maximum amounts for different categories of non-compliance.
| Breach category | Maximum monetary penalty |
|---|---|
| Failure to take reasonable security safeguards under Section 8(5) | May extend to ₹250 crore |
| Failure to notify the Board or affected Data Principals of a personal data breach under Section 8(6) | May extend to ₹200 crore |
| Failure to observe obligations relating to children under Section 9 | May extend to ₹200 crore |
| Failure to observe additional Significant Data Fiduciary obligations under Section 10 | May extend to ₹150 crore |
| Breach of any other provision of the Act or Rules | May extend to ₹50 crore |
The maximum amount is not automatic. Section 33 requires consideration of factors such as the nature, gravity, duration, data affected, repetition, gain or avoided loss, mitigation, and proportionality.
Read also: DPDP Penalties in India.
Data Fiduciary Compliance Checklist for Businesses
Use this checklist to convert statutory obligations into an implementation plan. Each completed item should have an owner, due date, evidence, review frequency, and mapped processing activities.
- Map Data Fiduciary, joint Data Fiduciary, Data Processor, and Data Principal roles for each processing activity
- Create and maintain a personal data inventory and data-flow map
- Record the specified purpose and applicable processing ground
- Review notices for clarity, granularity, language access, rights, withdrawal, and complaint information
- Implement purpose-based consent capture, proof, versioning, and withdrawal workflows
- Identify processing that relies on certain legitimate uses and document the applicable conditions
- Assess accuracy, completeness, and consistency controls for decisions and disclosures
- Implement technical and organisational measures across systems and departments
- Test reasonable security safeguards and retain required evidence and logs
- Create a breach-assessment and notification workflow capable of meeting the notified timeline
- Review processor contracts and establish vendor monitoring and offboarding controls
- Implement retention schedules, legal holds, erasure triggers, and processor-deletion verification
- Publish the required privacy contact information
- Create access, correction, erasure, grievance, and nomination workflows
- Implement age assurance and verifiable parental-consent controls where children’s data is processed
- Assess potential Significant Data Fiduciary exposure and prepare DPO, audit, and DPIA capabilities
- Map cross-border data access and transfer dependencies
- Train legal, privacy, IT, security, HR, marketing, procurement, operations, and customer-support teams
- Maintain policies, approvals, logs, reports, test results, and remediation evidence
- Report readiness, incidents, overdue actions, and residual privacy risks to leadership
Read also: DPDP Compliance Steps for 2026 Implementation.
What Evidence Should a Data Fiduciary Maintain?
The DPDP programme should produce evidence that controls are designed and operating. Policies alone cannot prove that notices were delivered, consent was valid, requests were completed, incidents were escalated, vendors were monitored, or data was erased.
- Personal data inventory and data-flow records
- Processing-purpose and role-assessment records
- Approved privacy notices and version history
- Consent receipts, timestamps, purpose records, and withdrawal logs
- Certain legitimate-use assessments
- Processor register, contracts, due diligence, and monitoring evidence
- Access-control reviews and security test results
- Data-quality checks for decisions and disclosures
- Retention schedules, deletion approvals, and erasure evidence
- Data Principal request and grievance case histories
- Breach registers, investigation records, communications, and notification evidence
- Children’s data and parental-consent evidence
- Training attendance and role-specific awareness records
- DPIAs, audits, findings, remediation actions, and closure evidence
- Management reports, risk acceptances, exceptions, and review minutes
Read also: How to Prepare for a DPDP Audit.
What Common Data Fiduciary Mistakes Should Businesses Avoid?
- Assuming that only consumer data is covered while ignoring employee, applicant, vendor-contact, and user data
- Treating every vendor as a processor without analysing who decides the purpose and means
- Believing that processor contracts transfer statutory accountability
- Using vague, bundled, or excessive consent requests
- Collecting data that is not necessary for the specified purpose
- Keeping data indefinitely because no retention owner is assigned
- Failing to locate personal data across email, files, SaaS tools, backups, and unstructured sources
- Applying the accuracy duty as a generic statement without identifying decisions and disclosures
- Treating the 90-day grievance period as a universal deadline for all Data Principal requests
- Waiting for a breach before designing the Board and Data Principal notification process
- Maintaining policies without workflow logs, control evidence, or remediation tracking
- Assuming an organization is automatically an SDF without a Central Government notification
The most effective way to reduce these gaps is to map each legal obligation to a business process, control, system, role, evidence source, and review cycle.
How Can GRC³ Support Data Fiduciary Compliance?
Data Fiduciary compliance crosses privacy, cybersecurity, legal, vendor management, operations, audit, and leadership reporting. A unified platform can connect these activities so that compliance is managed as an operating system rather than a collection of spreadsheets and disconnected documents.
GRC³ Capabilities Relevant to Data Fiduciaries
- Data discovery and data-flow visibility across structured and unstructured sources
- Purpose-based consent capture, withdrawal, and audit-ready consent records
- Data Principal rights workflows for access, correction, erasure, and grievance handling
- Identity verification, routing, SLA tracking, approvals, and evidence logs
- Retention, purpose limitation, and policy-based privacy controls
- Vendor and Data Processor risk assessments and lifecycle oversight
- Incident and breach workflows with investigation and notification evidence
- DPIA, risk, control, remediation, audit, and management-reporting workflows
Explore the GRC³ Data Privacy Solution to connect consent, rights handling, data discovery, privacy controls, incident response, and compliance evidence.
You can also contact GRC³ to discuss a Data Fiduciary readiness assessment, implementation roadmap, or DPDP compliance platform.
Conclusion
A Data Fiduciary is the person or organization that decides the purpose and means of processing personal data. That decision-making control carries responsibility for lawful processing, notice, consent, processor oversight, accuracy in specified situations, technical and organisational measures, security, breach notification, erasure, rights, grievance handling, and children’s data.
The key business lesson is that accountability remains with the Data Fiduciary even when processing is distributed across departments, cloud services, SaaS applications, contractors, and other Data Processors. Compliance therefore requires an enterprise-wide operating model with clear ownership and verifiable evidence.
With most operational obligations scheduled to commence on 13 May 2027, organizations should use 2026 to complete role mapping, data discovery, notice and consent remediation, processor governance, security testing, retention design, rights workflows, breach preparation, and audit-readiness work.
Frequently Asked Questions
A Data Fiduciary is the person or organization that decides why personal data will be processed and how that processing will take place.

