Who is a Data Processor?
Understanding the role of a Data Processor under the Digital Personal Data Protection Act, 2023 — in plain, practical English.

Not Every Organization Decides How Data is Used
The Key Insight
When you think about personal data, it is easy to assume that every organization handling your data is making decisions about it. But that is not always the case.
Some organizations process personal data purely on behalf of someone else — following instructions, not setting the rules.
Two Very Different Roles
Data Fiduciary
Decides why and how personal data is processed. Sets the purpose and the rules.
Data Processor
Follows instructions. Processes data on behalf of the Fiduciary. Does not set the purpose.
The Legal Definition
“Any person who processes personal data on behalf of a Data Fiduciary.”
— Digital Personal Data Protection Act, 2023
A Data Processor is any person or organization that processes personal data — but only under the authority and instructions of a Data Fiduciary. The Processor does not have an independent relationship with the individual whose data is being processed.

What a Data Processor Does NOT Decide
This is the critical distinction. A Data Processor generally has no say in the following decisions — those belong entirely to the Data Fiduciary.
Why Data is Collected
The purpose behind collecting personal data is set by the Fiduciary, not the Processor.
What Data is Collected
The type and scope of personal data collected is determined by the Fiduciary.
Purpose of Processing
The Fiduciary defines the legal and business purpose for which data is processed.
Data Retention Period
How long personal data is kept is a decision made by the Data Fiduciary, not the Processor.
The Data Flow: Who Connects to Whom?
Understanding the three-party relationship at the heart of the DPDP Act is essential. Here is how personal data flows from the individual all the way to the entity that processes it.
The Data Principal shares their data with the Data Fiduciary, who may then engage a Data Processor to perform specific processing tasks. The Processor acts solely on the Fiduciary's instructions and has no direct accountability to the Data Principal under the Act.
Real-Life Examples of Data Processors
Data Processors are everywhere — from the cloud platform storing your medical records to the payroll software that calculates your salary. Here are five common examples.

🏥 Hospital & Cloud Provider
Hospital = Data Fiduciary. The cloud service provider storing patient records = Data Processor. The hospital decides what records to store; the cloud provider simply stores them.

💼 Employer & Payroll Software
Employer = Data Fiduciary. The payroll software company = Data Processor. Employee salary data is processed by the software under the employer's contract and instructions.

📧 Company & Email Platform
Company = Data Fiduciary. The email marketing platform = Data Processor. Customer contact data is uploaded by the company; the platform sends emails on its behalf.
More Real-Life Examples

☁️ Business & Cloud Hosting
Business = Data Fiduciary. The cloud hosting provider (e.g., AWS, Azure, Google Cloud) = Data Processor. The business controls what data is stored; the provider manages the infrastructure.

🏢 Organization & HRMS Vendor
Organization = Data Fiduciary. The HRMS (HR management software) vendor = Data Processor. Employee personal data — attendance, leave, performance — is processed within the vendor's platform under the organization's configuration.
Fiduciary vs. Processor: Side-by-Side Comparison
This table captures the four most important dimensions that separate a Data Fiduciary from a Data Processor under the DPDP Act, 2023.
| Dimension | Data Fiduciary | Data Processor |
|---|---|---|
| Who decides purpose? | The Fiduciary — independently decides why and how data is processed | Does not decide — acts only on Fiduciary's instructions |
| Who processes the data? | May process data directly or outsource to a Processor | Processes personal data on behalf of the Fiduciary |
| Who interacts with the individual? | The Fiduciary — collects consent and responds to rights requests | Typically has no direct contact with the Data Principal |
| Examples | Hospital, Employer, Company, Business, Organization | Cloud provider, Payroll software, Email platform, HRMS vendor |
Accountability Does Not Transfer
A Critical Legal Point
Many organizations assume that once data processing is outsourced to a third-party vendor, the responsibility for compliance shifts to that vendor. Under the DPDP Act, 2023, this is not correct.
The Data Fiduciary remains primarily accountable to the Data Principal and to the Data Protection Board of India — even when a Data Processor is handling the actual processing.
This means the Fiduciary must ensure the Processor also complies with the Act's requirements — typically through a contractual agreement.
Fiduciary's Responsibility
Ensure the Processor is contractually bound to handle data in compliance with the Act.
Processor's Obligation
Process data only as per the Fiduciary's instructions and maintain appropriate security standards.
The Bottom Line
Outsourcing is permitted — but it is not an escape from accountability.
Common Misconceptions — Busted
There are several widespread misunderstandings about what it means to be a Data Processor. Let us address the most important ones directly.
❌ Myth: Every software company is a Data Processor
Not automatically. A software company becomes a Data Processor only when it processes personal data on behalf of a specific Data Fiduciary as part of a service agreement. A general SaaS product used internally may not qualify.
❌ Myth: A Processor owns the personal data it processes
Absolutely not. The Data Processor has no ownership rights over the personal data it handles. Ownership and control remain entirely with the Data Fiduciary and, ultimately, the Data Principal.
❌ Myth: Outsourcing transfers all responsibility
Engaging a Data Processor does not absolve the Fiduciary of its obligations. The Fiduciary must exercise oversight and ensure the Processor complies with the law through clear contractual terms.
Why Organizations Use Data Processors
Using third-party Data Processors is not just common — it is a fundamental part of how modern businesses operate efficiently. Here is why organizations regularly outsource data processing.
Operational Efficiency
Specialized vendors deliver faster, more reliable processing than most organizations can build in-house — from payroll calculations to cloud storage at scale.
Cost Reduction
Building and maintaining proprietary infrastructure for every processing function is expensive. Using Processors reduces capital expenditure and operational overhead.
Access to Expertise
Processors are specialists in their domain — whether it is email delivery, HR software, or cloud infrastructure — bringing deep technical expertise to the Fiduciary.
Scalability
Third-party Processors allow organizations to scale data operations quickly without needing to proportionally grow their internal teams or infrastructure.
Key Takeaways: The Data Processor in a Nutshell
A Data Processor processes personal data on behalf of a Data Fiduciary
It acts under the Fiduciary's instructions and does not set its own purpose for processing.
The Processor does not decide purpose, scope, or retention
All key decisions — why, what, and how long — belong to the Data Fiduciary.
The relationship is governed by a contract
The Fiduciary must bind the Processor through a written agreement that ensures compliance with the DPDP Act.
Accountability stays with the Fiduciary
Outsourcing data processing does not transfer legal accountability. The Fiduciary remains responsible to the Data Principal and the law.
Not every vendor is automatically a Data Processor
A vendor becomes a Data Processor only when it processes personal data on behalf of a Fiduciary under a specific contractual arrangement.
Coming Up Next
Significant Data Fiduciary?
Now that you understand who a Data Processor is
In the next module, we will explore the definition of significant data fiduciary.
DPDP Act 2023 Series · Module 2 → DPDP #10 - Significant Data Fiduciary (SDF)

Disclaimer
⚠️ Important NoticeThis presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.
