DPDP Act 2023 Series · #09 · Module 2 · Core DPDP Concepts

Who is a Data Processor?

Understanding the role of a Data Processor under the Digital Personal Data Protection Act, 2023 — in plain, practical English.

Data Processor illustration

Not Every Organization Decides How Data is Used

The Key Insight

When you think about personal data, it is easy to assume that every organization handling your data is making decisions about it. But that is not always the case.

Some organizations process personal data purely on behalf of someone else — following instructions, not setting the rules.

Two Very Different Roles

Data Fiduciary

Decides why and how personal data is processed. Sets the purpose and the rules.

Data Processor

Follows instructions. Processes data on behalf of the Fiduciary. Does not set the purpose.

The Legal Definition

“Any person who processes personal data on behalf of a Data Fiduciary.”
— Digital Personal Data Protection Act, 2023

A Data Processor is any person or organization that processes personal data — but only under the authority and instructions of a Data Fiduciary. The Processor does not have an independent relationship with the individual whose data is being processed.

Illustration accompanying the legal definition

What a Data Processor Does NOT Decide

This is the critical distinction. A Data Processor generally has no say in the following decisions — those belong entirely to the Data Fiduciary.

Why Data is Collected

The purpose behind collecting personal data is set by the Fiduciary, not the Processor.

What Data is Collected

The type and scope of personal data collected is determined by the Fiduciary.

Purpose of Processing

The Fiduciary defines the legal and business purpose for which data is processed.

Data Retention Period

How long personal data is kept is a decision made by the Data Fiduciary, not the Processor.

The Data Flow: Who Connects to Whom?

Understanding the three-party relationship at the heart of the DPDP Act is essential. Here is how personal data flows from the individual all the way to the entity that processes it.

Data Principal → Data Fiduciary → Data Processor

The Data Principal shares their data with the Data Fiduciary, who may then engage a Data Processor to perform specific processing tasks. The Processor acts solely on the Fiduciary's instructions and has no direct accountability to the Data Principal under the Act.

Real-Life Examples of Data Processors

Data Processors are everywhere — from the cloud platform storing your medical records to the payroll software that calculates your salary. Here are five common examples.

🏥 Hospital & Cloud Provider

🏥 Hospital & Cloud Provider

Hospital = Data Fiduciary. The cloud service provider storing patient records = Data Processor. The hospital decides what records to store; the cloud provider simply stores them.

💼 Employer & Payroll Software

💼 Employer & Payroll Software

Employer = Data Fiduciary. The payroll software company = Data Processor. Employee salary data is processed by the software under the employer's contract and instructions.

📧 Company & Email Platform

📧 Company & Email Platform

Company = Data Fiduciary. The email marketing platform = Data Processor. Customer contact data is uploaded by the company; the platform sends emails on its behalf.

More Real-Life Examples

☁️ Business & Cloud Hosting

☁️ Business & Cloud Hosting

Business = Data Fiduciary. The cloud hosting provider (e.g., AWS, Azure, Google Cloud) = Data Processor. The business controls what data is stored; the provider manages the infrastructure.

🏢 Organization & HRMS Vendor

🏢 Organization & HRMS Vendor

Organization = Data Fiduciary. The HRMS (HR management software) vendor = Data Processor. Employee personal data — attendance, leave, performance — is processed within the vendor's platform under the organization's configuration.

In every example, the Fiduciary sets the rules and the Processor executes. The Processor never independently decides what to do with the data.

Fiduciary vs. Processor: Side-by-Side Comparison

This table captures the four most important dimensions that separate a Data Fiduciary from a Data Processor under the DPDP Act, 2023.

DimensionData FiduciaryData Processor
Who decides purpose?The Fiduciary — independently decides why and how data is processedDoes not decide — acts only on Fiduciary's instructions
Who processes the data?May process data directly or outsource to a ProcessorProcesses personal data on behalf of the Fiduciary
Who interacts with the individual?The Fiduciary — collects consent and responds to rights requestsTypically has no direct contact with the Data Principal
ExamplesHospital, Employer, Company, Business, OrganizationCloud provider, Payroll software, Email platform, HRMS vendor

Accountability Does Not Transfer

A Critical Legal Point

Many organizations assume that once data processing is outsourced to a third-party vendor, the responsibility for compliance shifts to that vendor. Under the DPDP Act, 2023, this is not correct.

The Data Fiduciary remains primarily accountable to the Data Principal and to the Data Protection Board of India — even when a Data Processor is handling the actual processing.

This means the Fiduciary must ensure the Processor also complies with the Act's requirements — typically through a contractual agreement.

Fiduciary's Responsibility

Ensure the Processor is contractually bound to handle data in compliance with the Act.

Processor's Obligation

Process data only as per the Fiduciary's instructions and maintain appropriate security standards.

The Bottom Line

Outsourcing is permitted — but it is not an escape from accountability.

Common Misconceptions — Busted

There are several widespread misunderstandings about what it means to be a Data Processor. Let us address the most important ones directly.

❌ Myth: Every software company is a Data Processor

Not automatically. A software company becomes a Data Processor only when it processes personal data on behalf of a specific Data Fiduciary as part of a service agreement. A general SaaS product used internally may not qualify.

❌ Myth: A Processor owns the personal data it processes

Absolutely not. The Data Processor has no ownership rights over the personal data it handles. Ownership and control remain entirely with the Data Fiduciary and, ultimately, the Data Principal.

❌ Myth: Outsourcing transfers all responsibility

Engaging a Data Processor does not absolve the Fiduciary of its obligations. The Fiduciary must exercise oversight and ensure the Processor complies with the law through clear contractual terms.

Why Organizations Use Data Processors

Using third-party Data Processors is not just common — it is a fundamental part of how modern businesses operate efficiently. Here is why organizations regularly outsource data processing.

Operational Efficiency

Specialized vendors deliver faster, more reliable processing than most organizations can build in-house — from payroll calculations to cloud storage at scale.

Cost Reduction

Building and maintaining proprietary infrastructure for every processing function is expensive. Using Processors reduces capital expenditure and operational overhead.

Access to Expertise

Processors are specialists in their domain — whether it is email delivery, HR software, or cloud infrastructure — bringing deep technical expertise to the Fiduciary.

Scalability

Third-party Processors allow organizations to scale data operations quickly without needing to proportionally grow their internal teams or infrastructure.

Key Takeaways: The Data Processor in a Nutshell

A Data Processor processes personal data on behalf of a Data Fiduciary

It acts under the Fiduciary's instructions and does not set its own purpose for processing.

The Processor does not decide purpose, scope, or retention

All key decisions — why, what, and how long — belong to the Data Fiduciary.

The relationship is governed by a contract

The Fiduciary must bind the Processor through a written agreement that ensures compliance with the DPDP Act.

Accountability stays with the Fiduciary

Outsourcing data processing does not transfer legal accountability. The Fiduciary remains responsible to the Data Principal and the law.

Not every vendor is automatically a Data Processor

A vendor becomes a Data Processor only when it processes personal data on behalf of a Fiduciary under a specific contractual arrangement.

Coming Up Next

Significant Data Fiduciary?

Now that you understand who a Data Processor is

In the next module, we will explore the definition of significant data fiduciary.

DPDP Act 2023 Series · Module 2 → DPDP #10 - Significant Data Fiduciary (SDF)

Illustration for the upcoming Significant Data Fiduciary module

Disclaimer

⚠️ Important Notice

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.

Disclaimer artwork