Who is a Data Fiduciary?
Understanding your role and responsibilities under the Digital Personal Data Protection Act, 2023.

Why This Matters
The Digital Personal Data Protection Act, 2023 is India's landmark legislation governing how personal data is collected, stored, used, and protected. Before we discuss consent, compliance, or accountability — we must first identify who is responsible for personal data.
That responsible party is called the Data Fiduciary — and understanding this concept is the foundation of the entire Act.
Identify the Data Fiduciary
Know who holds responsibility.
Understand Obligations
Lawful, fair, transparent processing.
Ensure Compliance
Rights, consent & accountability.
What is a Data Fiduciary?
Under Section 2(i) of the DPDP Act, 2023, a Data Fiduciary is any person — individual, company, government body, or any other entity — who alone or in conjunction with others determines the purpose and means of processing personal data.
Why collected?
The purpose behind collecting personal data — treatment, employment, service delivery.
What is collected?
The type of personal data — name, health records, financial details, location.
How processed?
The methods, tools, and systems used to store, analyse, or share the data.
Who accesses it?
Deciding which staff, vendors, or systems can view or use the data.
How long retained?
Setting retention periods and deletion schedules once the purpose is fulfilled.
Data Fiduciaries Across India’s Economy
Any organization — large or small, private or public — that decides how and why personal data is processed becomes a Data Fiduciary.
Hospitals & Clinics
Collect patient health records, diagnoses, and treatment history.
Banks & NBFCs
Process KYC documents, account details, and financial transactions.
Schools & Colleges
Maintain student records, academic data, and personal information.
Employers
Hold employee records, salary details, and performance data.
Mobile Apps
Collect name, email, location, contacts, and device identifiers.
E-Commerce Platforms
Store purchase history, delivery addresses, and payment data.
Insurance Companies
Process policy data, health disclosures, and claim information.
Government Departments
Handle citizen records, tax data, welfare scheme information.
Who Decides Why and How?
In each case, ask: Who decides why and how personal data is processed? That entity is the Data Fiduciary.
🏥 Hospital
Data Principal: Patient
Data Fiduciary: Hospital
Data Processed: Name, age, diagnosis, treatment history, lab reports, prescriptions — the hospital decides what is collected, how it is stored, and who can access it.
🏦 Bank
Data Principal: Account Holder
Data Fiduciary: Bank
Data Processed: PAN, Aadhaar, address proof, income details, transaction history — the bank determines the purpose and means of processing.
🏢 Employer
Data Principal: Employee
Data Fiduciary: Organisation
Data Processed: Employment contracts, salary records, PF details, performance reviews, biometric attendance.
📱 Mobile Application
Data Principal: App User
Data Fiduciary: App Operating Company
Data Processed: Name, email, phone number, GPS location, device ID.
The Data Ecosystem Under the DPDP Act
The Act defines three distinct roles in the data ecosystem. Understanding how they relate to each other is essential for any compliance programme.
| Role | Who They Are | Key Function | Example |
|---|---|---|---|
| Data Principal | The individual whose data is collected | Provides data; holds rights under the Act | Patient, employee, customer, student |
| Data Fiduciary | Entity deciding purpose & means | Bears primary legal obligations & accountability | Hospital, bank, employer, app company |
| Data Processor | Entity processing on fiduciary's behalf | Follows fiduciary's instructions; no independent authority | Cloud provider, payroll vendor, analytics firm |
Key Responsibilities of a Data Fiduciary
Being a Data Fiduciary carries significant legal and ethical obligations under the DPDP Act.
Lawful Processing Only
Personal data must be processed only for a specific, clear, and lawful purpose — with valid consent or another recognized legal basis under the Act.
Transparency & Notice
Inform the Data Principal about what data is collected, why, and how it will be used — in clear, plain language.
Data Security
Implement reasonable technical and organisational safeguards to prevent breaches, unauthorised access, or misuse.
Respect Data Principal Rights
Establish mechanisms to honour access, correction, and erasure requests in a timely manner.
Data Minimisation
Collect only data necessary for the stated purpose. Excessive or irrelevant collection is not permitted.
Significant Data Fiduciaries
The Central Government has the power under Section 10 of the DPDP Act to designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to national security, and potential impact on public order.
SDFs face heightened obligations beyond standard requirements — including appointing a Data Protection Officer, conducting Data Protection Impact Assessments, and periodic audits.
Data Protection Officer (DPO)
A dedicated officer accountable to the Board for data protection compliance.
Consent Manager
Must register with the Data Protection Board to manage consent on behalf of users.
Impact Assessments
Periodic Data Protection Impact Assessments (DPIAs) are mandatory.
Regular Audits
Independent audits of data practices by registered independent data auditors.
Myths About Data Fiduciaries
❌ “We own the data, so we’re responsible.”
Reality: Ownership is a commercial concept. The DPDP Act is about control and decision-making. If you decide why and how data is processed, you are the Data Fiduciary.
❌ “Only large corporations are Data Fiduciaries.”
Reality: A small clinic, a local school, a freelance HR consultant, or a neighbourhood pharmacy can all be Data Fiduciaries. Size is irrelevant.
❌ “The software or app itself is the Data Fiduciary.”
Reality: Technology cannot bear legal obligations. The company or person operating the software, app, or platform is the Data Fiduciary — not the code itself.
Why Identifying the Right Data Fiduciary Matters
Before consent frameworks, data audits, or breach response plans are designed, the organisation must first correctly identify itself as a Data Fiduciary.
Without Correct Identification
- Accountability gaps — no one owns the obligation
- Invalid consent mechanisms — wrong party seeking consent
- Liability exposure — regulatory action against wrong entity
- Data breach response failures — unclear chain of responsibility
With Correct Identification
- Clear accountability and ownership of obligations
- Valid, purpose-specific consent structures
- Robust vendor contracts with Data Processors
- Confident response to Data Principal rights requests
Data Fiduciary at a Glance
1. The Decision-Maker is the Fiduciary
Any entity that determines the purpose and means of processing personal data — regardless of size or sector — is a Data Fiduciary.
2. It’s a Role, Not a Title
A hospital, bank, school, employer, app company, or government department can all become Data Fiduciaries. It depends on their decisions about personal data.
3. Three Roles, One Ecosystem
The Data Principal provides data and holds rights. The Data Fiduciary decides and bears obligations. The Data Processor executes instructions.
4. Identification Comes First
Compliance begins with correctly identifying who the Data Fiduciary is. Without this, consent, security, and accountability cannot be built on solid legal ground.
Up Next: Who is a Data Processor?
Now that we understand the Data Fiduciary — the decision-maker — we turn to the entity that carries out the actual processing work: the Data Processor.
What will we cover?
- Definition of a Data Processor under the DPDP Act
- How the Data Processor differs from the Data Fiduciary
- Contractual obligations and liability boundaries
- Real-world examples: cloud providers, payroll vendors, analytics firms
Why it matters
Most organisations use third-party service providers to process personal data on their behalf. Understanding the Data Processor relationship is critical for drafting vendor agreements, managing liability, and ensuring end-to-end DPDP compliance.
DPDP Act 2023 Series · Module 2 → DPDP #09 - Who is a Data Processor?
Disclaimer

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.