DPDP Learning Series · #08 · Module 2

Who is a Data Fiduciary?

Understanding your role and responsibilities under the Digital Personal Data Protection Act, 2023.

Data protection and responsible processing illustration
Setting the Stage

Why This Matters

The Digital Personal Data Protection Act, 2023 is India's landmark legislation governing how personal data is collected, stored, used, and protected. Before we discuss consent, compliance, or accountability — we must first identify who is responsible for personal data.

That responsible party is called the Data Fiduciary — and understanding this concept is the foundation of the entire Act.

Identify the Data Fiduciary

Know who holds responsibility.

Understand Obligations

Lawful, fair, transparent processing.

Ensure Compliance

Rights, consent & accountability.

Legal Definition

What is a Data Fiduciary?

Under Section 2(i) of the DPDP Act, 2023, a Data Fiduciary is any person — individual, company, government body, or any other entity — who alone or in conjunction with others determines the purpose and means of processing personal data.

Why collected?

The purpose behind collecting personal data — treatment, employment, service delivery.

What is collected?

The type of personal data — name, health records, financial details, location.

How processed?

The methods, tools, and systems used to store, analyse, or share the data.

Who accesses it?

Deciding which staff, vendors, or systems can view or use the data.

How long retained?

Setting retention periods and deletion schedules once the purpose is fulfilled.

Think of the Data Fiduciary as the decision-maker — the entity that decides the “why” and “how” of personal data processing.
Who Can Become One?

Data Fiduciaries Across India’s Economy

Any organization — large or small, private or public — that decides how and why personal data is processed becomes a Data Fiduciary.

Hospitals & Clinics

Collect patient health records, diagnoses, and treatment history.

Banks & NBFCs

Process KYC documents, account details, and financial transactions.

Schools & Colleges

Maintain student records, academic data, and personal information.

Employers

Hold employee records, salary details, and performance data.

Mobile Apps

Collect name, email, location, contacts, and device identifiers.

E-Commerce Platforms

Store purchase history, delivery addresses, and payment data.

Insurance Companies

Process policy data, health disclosures, and claim information.

Government Departments

Handle citizen records, tax data, welfare scheme information.

Real-World Examples

Who Decides Why and How?

In each case, ask: Who decides why and how personal data is processed? That entity is the Data Fiduciary.

🏥 Hospital

Data Principal: Patient
Data Fiduciary: Hospital
Data Processed: Name, age, diagnosis, treatment history, lab reports, prescriptions — the hospital decides what is collected, how it is stored, and who can access it.

🏦 Bank

Data Principal: Account Holder
Data Fiduciary: Bank
Data Processed: PAN, Aadhaar, address proof, income details, transaction history — the bank determines the purpose and means of processing.

🏢 Employer

Data Principal: Employee
Data Fiduciary: Organisation
Data Processed: Employment contracts, salary records, PF details, performance reviews, biometric attendance.

📱 Mobile Application

Data Principal: App User
Data Fiduciary: App Operating Company
Data Processed: Name, email, phone number, GPS location, device ID.

Three Key Roles

The Data Ecosystem Under the DPDP Act

The Act defines three distinct roles in the data ecosystem. Understanding how they relate to each other is essential for any compliance programme.

RoleWho They AreKey FunctionExample
Data PrincipalThe individual whose data is collectedProvides data; holds rights under the ActPatient, employee, customer, student
Data FiduciaryEntity deciding purpose & meansBears primary legal obligations & accountabilityHospital, bank, employer, app company
Data ProcessorEntity processing on fiduciary's behalfFollows fiduciary's instructions; no independent authorityCloud provider, payroll vendor, analytics firm
Core Obligations

Key Responsibilities of a Data Fiduciary

Being a Data Fiduciary carries significant legal and ethical obligations under the DPDP Act.

Lawful Processing Only

Personal data must be processed only for a specific, clear, and lawful purpose — with valid consent or another recognized legal basis under the Act.

Transparency & Notice

Inform the Data Principal about what data is collected, why, and how it will be used — in clear, plain language.

Data Security

Implement reasonable technical and organisational safeguards to prevent breaches, unauthorised access, or misuse.

Respect Data Principal Rights

Establish mechanisms to honour access, correction, and erasure requests in a timely manner.

Data Minimisation

Collect only data necessary for the stated purpose. Excessive or irrelevant collection is not permitted.

Special Category

Significant Data Fiduciaries

The Central Government has the power under Section 10 of the DPDP Act to designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to national security, and potential impact on public order.

SDFs face heightened obligations beyond standard requirements — including appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and periodic audits.

Data Protection Officer (DPO)

A dedicated officer accountable to the Board for data protection compliance.

Consent Manager

Must register with the Data Protection Board to manage consent on behalf of users.

Impact Assessments

Periodic Data Protection Impact Assessments (DPIAs) are mandatory.

Regular Audits

Independent audits of data practices by registered independent data auditors.

Common Misconceptions — Busted

Myths About Data Fiduciaries

❌ “We own the data, so we’re responsible.”

Reality: Ownership is a commercial concept. The DPDP Act is about control and decision-making. If you decide why and how data is processed, you are the Data Fiduciary.

❌ “Only large corporations are Data Fiduciaries.”

Reality: A small clinic, a local school, a freelance HR consultant, or a neighbourhood pharmacy can all be Data Fiduciaries. Size is irrelevant.

❌ “The software or app itself is the Data Fiduciary.”

Reality: Technology cannot bear legal obligations. The company or person operating the software, app, or platform is the Data Fiduciary — not the code itself.

When a vendor or cloud provider processes data strictly on your instructions, they are the Data Processor — and you remain the Data Fiduciary responsible for that processing.
Compliance Foundation

Why Identifying the Right Data Fiduciary Matters

Before consent frameworks, data audits, or breach response plans are designed, the organisation must first correctly identify itself as a Data Fiduciary.

Without Correct Identification

  • Accountability gaps — no one owns the obligation
  • Invalid consent mechanisms — wrong party seeking consent
  • Liability exposure — regulatory action against wrong entity
  • Data breach response failures — unclear chain of responsibility

With Correct Identification

  • Clear accountability and ownership of obligations
  • Valid, purpose-specific consent structures
  • Robust vendor contracts with Data Processors
  • Confident response to Data Principal rights requests
Key Takeaways

Data Fiduciary at a Glance

1. The Decision-Maker is the Fiduciary

Any entity that determines the purpose and means of processing personal data — regardless of size or sector — is a Data Fiduciary.

2. It’s a Role, Not a Title

A hospital, bank, school, employer, app company, or government department can all become Data Fiduciaries. It depends on their decisions about personal data.

3. Three Roles, One Ecosystem

The Data Principal provides data and holds rights. The Data Fiduciary decides and bears obligations. The Data Processor executes instructions.

4. Identification Comes First

Compliance begins with correctly identifying who the Data Fiduciary is. Without this, consent, security, and accountability cannot be built on solid legal ground.

Coming Next

Up Next: Who is a Data Processor?

Now that we understand the Data Fiduciary — the decision-maker — we turn to the entity that carries out the actual processing work: the Data Processor.

What will we cover?

  • Definition of a Data Processor under the DPDP Act
  • How the Data Processor differs from the Data Fiduciary
  • Contractual obligations and liability boundaries
  • Real-world examples: cloud providers, payroll vendors, analytics firms

Why it matters

Most organisations use third-party service providers to process personal data on their behalf. Understanding the Data Processor relationship is critical for drafting vendor agreements, managing liability, and ensuring end-to-end DPDP compliance.

DPDP Act 2023 Series · Module 2 → DPDP #09 - Who is a Data Processor?

⚠️ Important Notice

Disclaimer

Legal disclaimer illustration with documents and scales

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.