Skip to main content
Data Fiduciary vs Data Processor: DPDP Act Explained — page loaded
Explainer

Data Fiduciary vs Data Processor Under the DPDP Act: Roles, Duties and Liability

Definitions, obligations, liability and a practical role-classification test.

Section 01

What is the difference between a Data Fiduciary and a Data Processor?

Quick answer
Under the DPDP Act 2023, a Data Fiduciary is the person or entity that alone or with others decides the purpose and means of processing personal data. A Data Processor is any entity that processes personal data on behalf of a Data Fiduciary. The Fiduciary carries the legal obligations and liability; the Processor acts under contract and instruction.

Why the distinction matters

The DPDP Act places almost every obligation and every penalty on the Data Fiduciary. A Data Processor has no direct statutory duties to the Data Principal or the Data Protection Board. That makes role classification the first control in any DPDP programme: misclassify yourself as a Processor when you are actually a Fiduciary, and you have no consent, notice, breach or rights architecture when the Board comes calling. Classify a vendor as a Processor without a valid contract, and you carry their failures as your own.

New to the Act itself? Start with our plain-English guide to the DPDP Act. If you also run an EU programme, see DPDP vs GDPR: key differences, where these roles map to Controller and Processor.

Section 02

What is a Data Fiduciary under the DPDP Act?

A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data (Section 2(i)). It is the accountable party under the Act: it must obtain consent or rely on a legitimate use, issue notices, secure the data, report breaches, honour Data Principal rights and answer to the Data Protection Board. The GDPR equivalent is the Controller.

A Fiduciary the Central Government notifies under Section 10 becomes a Significant Data Fiduciary, with an India-based DPO, annual audits and algorithmic due diligence on top.

Section 03

What is a Data Processor under the DPDP Act?

A Data Processor is any person who processes personal data on behalf of a Data Fiduciary (Section 2(k)). It acts under a contract and on instruction, has no direct obligations to Data Principals or the Board, and its exposure is contractual rather than statutory. The GDPR uses the same term.

Key terms

Where consent is routed through an intermediary rather than collected directly, a third role appears — see what is a Consent Manager under the DPDP Act.

Data Fiduciary
Section 2(i): any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. GDPR equivalent: Controller.
Data Processor
Section 2(k): any person who processes personal data on behalf of a Data Fiduciary. GDPR equivalent: Processor.
Data Principal
Section 2(j): the individual to whom the personal data relates, including a parent or lawful guardian for a child, and a lawful guardian for a person with disability.
Processing
Section 2(x): a wholly or partly automated operation or set of operations on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, dissemination, restriction, erasure or destruction.
Significant Data Fiduciary
A Data Fiduciary or class of Data Fiduciaries notified under Section 10 and subject to enhanced obligations.
Joint determination
Where two or more entities together decide purpose and means, each is a Data Fiduciary for that processing. The Act does not create a separate "joint fiduciary" regime, so contracts must allocate responsibility.
Section 04

Data Fiduciary vs Data Processor: Comparison Table

Data Fiduciary and Data Processor obligations under the DPDP Act, aspect by aspect
AspectData FiduciaryData Processor
Core testDecides why (purpose) and how (means) personal data is processed.Processes only on the Fiduciary's behalf and instructions.
Legal basis for processingMust obtain valid consent or rely on a Section 7 legitimate use.None required in its own right; relies on the Fiduciary's basis.
Notice to Data PrincipalsMust issue a compliant notice before or at the time of seeking consent.No notice obligation.
Accuracy and completenessMust ensure data is accurate and complete where it is used to make decisions or shared with another Fiduciary.Supports as instructed.
Security safeguardsMust implement reasonable security safeguards, including for processing done by its Processors.Contractually bound; the Fiduciary remains liable for the Processor's failure.
Breach notificationMust notify the Board and affected Data Principals for every breach.Must inform the Fiduciary under contract; no direct duty to the Board under the Act.
Erasure and retentionMust erase data when purpose is served or consent withdrawn, and cause its Processors to erase.Must erase on Fiduciary instruction.
Data Principal rightsMust handle access, correction, erasure, grievance and nomination requests.No direct obligation; assists the Fiduciary.
Grievance officer / DPOMust publish a contact for grievances; SDFs must appoint an India-based DPO.Not required by the Act.
Engaging sub-processorsMay engage Processors only under a valid contract.May onboard sub-processors only if the Fiduciary contract allows.
Penalty exposureDirect: up to INR 250 crore per instance.No direct penalty under the DPDP Act; exposure is contractual (indemnity, termination, damages).
Accountability principleSection 8(1): responsible for compliance regardless of any agreement to the contrary or the Processor's conduct.Not accountable to the Board; accountable to the Fiduciary.
Section 05

How to Decide If You Are a Data Fiduciary or a Data Processor

  • Who decided to collect this data and for what business outcome? If you did, you are a Fiduciary.
  • Could you continue processing if the other party terminated the contract? If yes, you are a Fiduciary.
  • Do you use the data for your own analytics, product improvement, model training or marketing? If yes, you are a Fiduciary for that use, even if a Processor for the rest.
  • Do you decide retention periods, security architecture or the categories of data collected? Deciding "means" at a strategic level points to Fiduciary; technical implementation choices alone do not.
  • Are you a professional adviser (auditor, lawyer, CA, bank) with independent professional obligations over the data? You are almost always a Fiduciary.

Common role classifications in Indian businesses

Typical Data Fiduciary and Data Processor classifications in Indian businesses
ScenarioTypical roleWhy
Bank or NBFC processing customer KYCData FiduciaryDecides purpose (onboarding, credit) and means.
Cloud hosting provider (IaaS)Data ProcessorStores and computes on instruction; no purpose determination.
Payroll outsourcing vendorData ProcessorProcesses employee data to the employer's specification.
Payment aggregator settling merchant transactionsData Fiduciary (own regulatory purposes) and Processor (for merchant)Independent RBI obligations create own purposes.
SaaS CRM vendorData Processor for customer data; Fiduciary for its own account-holder dataDual role is common; contracts must split them.
Marketing agency running campaigns on its own data poolsData FiduciaryDetermines audience and purpose.
Chit fund or MFI branch network collecting subscriber dataData FiduciaryThe registered entity decides purpose; agents are internal, not Processors.
Statutory auditor or tax adviserData FiduciaryIndependent professional duties govern how data is used.
BPO handling customer calls for a foreign clientData Processor (DPDP) and typically Processor under GDPRActs on client instruction; contract must flow down DPDP terms.
Section 06

What a DPDP Data Processor Contract Must Include

The Act requires only that a Processor be engaged under a valid contract, but Section 8(1) accountability means the Fiduciary should insist on the following clauses:

  • Scope and instructions: purposes, data categories, permitted operations, and prohibition on any processing outside instructions.
  • Security safeguards: minimum controls mapped to Rule 6 of the DPDP Rules (encryption, access control, logging, monitoring, backups) and the right to audit.
  • Breach reporting: notification to the Fiduciary without delay, with the facts needed for the Fiduciary to meet its 72-hour detailed report to the Board.
  • Sub-processing: prior written approval, flow-down of identical terms, and a maintained sub-processor list.
  • Retention and erasure: erasure on completion of purpose, on withdrawal of consent, or on instruction, with certification.
  • Assistance with rights: timelines for supporting access, correction and erasure requests.
  • Cross-border transfers: restriction to permitted jurisdictions and any SDF-specific localisation conditions.
  • Liability and indemnity: indemnity for penalties and losses caused by Processor default, with insurance where proportionate.
  • Log and record retention: the DPDP Rules require logs and personal data to be retained for at least one year after erasure to support Board inquiries; contracts should mirror this.

The regime this replaced put no such clauses in statute at all — DPDP Act vs IT Act SPDI Rules sets out what changed.

Frequently Asked Questions: Data Fiduciary and Data Processor

Not directly. The Act imposes obligations and penalties on the Data Fiduciary, which remains responsible for compliance regardless of the Processor's conduct. Processor liability arises from the contract.

Yes. Most SaaS, payment and outsourcing companies are Processors for client data and Fiduciaries for their own customer, employee and vendor data. The compliance programme must cover both roles.

The definition ("alone or in conjunction with other persons") covers joint determination, but the Act does not prescribe a joint-controller arrangement as GDPR Article 26 does. Allocate responsibilities contractually.

An SDF is a Data Fiduciary notified by the Central Government based on volume, sensitivity and risk factors, and it carries additional duties: an India-based DPO, an independent auditor, annual DPIAs, algorithmic due diligence and possible localisation restrictions.

No. There is no registration requirement for Fiduciaries or Processors. Only Consent Managers register with the Board.

No. Processors can be anywhere, subject to any Central Government restriction on transfers to specified countries and any conditions imposed on SDFs.

Key takeaways

  • The Fiduciary decides purpose and means; the Processor acts on instruction.
  • All statutory obligations and penalties sit with the Fiduciary, even for Processor failures.
  • Dual roles are the norm for technology and outsourcing companies; map each processing activity separately.
  • A valid written contract with security, breach, sub-processing, erasure and indemnity clauses is the Fiduciary's main control over Processor risk.