Glossary · Data Fiduciary Duties

What Are Data Fiduciary Duties Under DPDPA?

If you decide why and how personal data is used, Section 8 puts the Act's core duties on you — processor contracts, accuracy, security, erasure, breach reporting, a named contact. A DPO is not one of them unless you are notified as a Significant Data Fiduciary. Get the baseline in place before 13 May 2027.

Last reviewed: 14 August 2026

Definition

A Data Fiduciary is whoever decides why and how personal data gets processed — for most SMBs, that's you, not your software vendor. Section 8 of the DPDP Act, 2023 lists the duties that follow. You stay responsible even when a processor handles the data for you, and no contract shifts that. You must engage processors only under a valid contract (Section 8(2)), keep data accurate where it affects someone, apply reasonable security safeguards including for processing done on your behalf (Section 8(5)), report breaches (Section 8(6)), erase data once consent is withdrawn or the purpose is served (Section 8(7)), publish a contact point for questions (Section 8(9) and Rule 9), and run a working grievance channel (Section 8(10)).

How this matters in practice

The duties SMBs fail first are the unglamorous ones: no published contact person, no processor contracts, no erasure trigger when a customer goes dormant. A DPO is Rule 13 and Significant Data Fiduciaries only — do not confuse that with the Rule 9 contact person every fiduciary owes. Privigo turns each Section 8 duty into a tracked control with an owner and evidence — retention clocks, a processor register, and immutable logs that show the Board what you did, not what you intended.

Frequently asked questions

Am I a Data Fiduciary or a Data Processor?

You're a Data Fiduciary if you decide the purpose and means of processing — a school collecting admission forms, an NBFC running KYC, an HR firm handling payroll. You're a Processor only if you process data purely on someone else's instructions. Most SMBs are Fiduciaries for their own customer and employee data while simultaneously being Processors for a client's data, and the same company can be both in different relationships. It matters because Section 8 duties and the large penalty slabs attach to the Fiduciary. Section 8(2) requires a valid contract before a processor acts on your behalf; Section 8(5) makes you answerable for security of processing done on your behalf as well.

What does reasonable security safeguards actually mean for a 15-person company?

Section 8(5) sets the duty; Rule 6 of the DPDP Rules, 2025 gives the shape — measures such as encryption, obfuscation, masking or virtual tokens; access controls; logs and monitoring to detect unauthorised access; backups to restore data after an incident; one-year retention of certain logs; and contractual security terms with processors under Rule 6(1)(f). There's no certification to buy and no fixed checklist. The test is whether your measures fit your data and risk. This is the highest-penalty duty in the Act at up to ₹250 crore, and it applies regardless of whether you relied on consent or on a Section 7 legitimate use. A Data Protection Officer and annual audit under Rule 13 bind Significant Data Fiduciaries only.

When do I have to delete data, and can I just keep it to be safe?

No — retention beyond need is itself a breach. Section 8(7) requires erasure once the Data Principal withdraws consent or the specified purpose is no longer being served, unless an Indian law requires you to retain it. Rule 6(1)(e) and Rule 8(3) set a one-year floor for certain access logs, traffic data and related personal data — so "delete everything on request" is also wrong. The 2025 Rules add a specific trigger for larger e-commerce, online gaming and social media intermediaries: erase after three years of Data Principal inactivity, with advance notice before deleting. Smaller SMBs aren't in scope for that clock but still need a defensible retention rule per data type. Build backwards from 13 May 2027.

Official sources

Turn Section 8 into a tracked control list

Book a 30-minute call to see which fiduciary duties you already meet, which are missing an owner, and what evidence you would show the Board.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.