With businesses increasingly relying on digital platforms and data-driven operations, the responsibility to protect personal data has become a critical legal and compliance obligation. The Digital Personal Data Protection Act, 2023 (DPDP Act) establishes a framework for regulating the processing of digital personal data in India. At the centre of this framework is the concept of a Data Fiduciary—an entity that determines the purpose and means of processing personal data.
The DPDP Act places significant responsibility on Data Fiduciaries to ensure that personal data is processed lawfully, securely and responsibly. The Digital Personal Data Protection Rules, 2025, notified on 14 November 2025, provide further operational details for implementing these obligations.
Who is a Data Fiduciary?
A Data Fiduciary may broadly be understood as an individual, company, organisation or other person that determines why and how personal data will be processed. For example, an e-commerce company collecting customers’ names, contact details and delivery addresses to fulfil orders would generally determine the purpose and means of such processing and therefore act as a Data Fiduciary.
Importantly, a Data Fiduciary remains responsible for compliance even when it engages a Data Processor to process personal data on its behalf. The Act requires such processing to be carried out under a valid contract.
Key Obligations of Data Fiduciaries
1. Lawful and Purpose-Limited Processing
Data Fiduciaries must ensure that personal data is processed for a lawful purpose and in accordance with the DPDP Act. Data collection should be connected to the purpose for which the data is being processed rather than undertaken indiscriminately.
The DPDP Rules further emphasise clear and understandable notices so that individuals are informed about what personal data is being collected and the purpose for which it will be used.
2. Accuracy of Personal Data
Where personal data is likely to be used to make a decision affecting the Data Principal or disclosed to another Data Fiduciary, the Data Fiduciary must ensure that the data is complete, accurate and consistent.
3. Security Safeguards
Data Fiduciaries are required to implement appropriate technical and organisational measures to protect personal data. This includes reasonable security safeguards designed to prevent personal data breaches.
The Rules provide greater detail regarding such safeguards, including measures such as encryption, access controls, monitoring for unauthorised access, backups and breach detection mechanisms.
4. Data Breach Notification
In the event of a personal data breach, the Data Fiduciary must notify the Data Protection Board and affected Data Principals in the prescribed manner. This makes breach response an important component of privacy compliance.
5. Erasure and Retention
A Data Fiduciary cannot retain personal data indefinitely. Subject to applicable legal requirements, personal data must be erased when it is no longer necessary for the specified purpose or when the prescribed conditions for erasure are met.
6. Grievance Redressal
Data Fiduciaries must establish an effective mechanism through which Data Principals can raise grievances relating to the processing of their personal data. They must also publish relevant contact information for addressing questions concerning such processing.
Additional Obligations for Significant Data Fiduciaries
Certain organisations may be notified as Significant Data Fiduciaries based on factors such as the volume and sensitivity of personal data processed and the potential impact on individuals. Such entities are subject to additional compliance requirements, including periodic Data Protection Impact Assessments and audits.
Conclusion
The DPDP framework shifts data privacy from being merely an internal IT concern to a broader legal responsibility for organisations. Data Fiduciaries must understand what personal data they collect, why they collect it, how it is processed, who has access to it and when it should be deleted.
For businesses, preparing for DPDP compliance therefore requires more than updating a privacy policy. It requires a comprehensive review of data practices, contracts, security safeguards, consent mechanisms, retention policies and grievance procedures. As the DPDP Act and Rules move through their phased implementation, organisations should treat privacy compliance as an ongoing governance responsibility rather than a one-time exercise.
