Definition
Under Section 2(k) of the DPDPA, 2023, a Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The dividing line is decision-making: the fiduciary decides why and how data is used; the processor simply acts on the fiduciary's instructions. Your CRM, cloud host, payroll bureau, laboratory information system, SMS or WhatsApp gateway, tally-hosting provider and email platform are typically processors. Section 8(2) lets you engage one only under a valid contract. Critically, Section 8(1) keeps you responsible for compliance — including for processing your processor carries out on your behalf.
Fiduciary vs processor, in practice
|
Data Fiduciary |
Data Processor |
| Decides purpose |
Yes |
No |
| Acts on instructions |
No |
Yes |
| Answers to the data principal |
Yes |
No — routes to you |
| Board looks to |
You — the fiduciary stays liable |
Does not take your liability with them |
Two things this does not mean. First, engaging a processor does not transfer your liability — you cannot point at your vendor when the Board asks why consent wasn't collected. Second, a processor is not automatically a Significant Data Fiduciary. SDF status under Section 10 applies only where the Central Government notifies an entity, and it brings the Rule 13 annual audit, DPIA and India-resident DPO with it. A large SaaS provider may or may not be notified; that is not something you can assume from its size.
How this matters in practice
Most 15–40 person firms have twelve to twenty processors and a contract with none of them — just a signed-up-online SaaS account and a Terms page. Privigo builds your processor register, flags which vendors touch personal data, and generates DPDPA-aligned contract addenda covering purpose limits, security, breach notification upstream to you, sub-processor disclosure and deletion at contract end.
Frequently asked questions
We use Zoho CRM, a payroll consultant and a WhatsApp Business gateway. Do we need a separate agreement with each?
Yes — Section 8(2) requires a valid contract with every processor, and clicking through standard terms is usually thin. For established SaaS vendors, check whether they publish a data processing addendum you can accept; many now do for India. For your payroll consultant, gateway reseller or local IT partner, you'll likely need to add a written addendum yourself. Cover purpose limits, security, sub-processors, breach notice to you, and deletion on exit.
If our CRM vendor gets breached, are we off the hook?
No. You remain the fiduciary and stay accountable — reporting to the Data Protection Board and informing affected individuals is your obligation, not theirs. Four lanes run together: CERT-In within 6 hours of noticing a reportable cyber incident; Rule 7(1) intimation to affected people without delay; Rule 7(2)(a) initial Board intimation without delay; and Rule 7(2)(b) the detailed Board report within 72 hours. That only works if your contract obliges the vendor to tell you immediately.
Can we be a fiduciary and a processor at the same time?
Regularly. A digital marketing agency is a processor for its clients' customer lists, and a fiduciary for its own employees and leads. A diagnostic lab is a fiduciary for walk-in patients and a processor for samples referred by a hospital. Map it per data set, not per company — the same organisation can hold both roles, with different obligations attaching to each.
List every vendor that touches personal data
Book a 30-minute call. We map your CRM, payroll, cloud and messaging stack to Section 8(2) contracts and flag where click-wrap terms leave you exposed.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.