Home/Legal Resources/Legal Glossary/Data Fiduciary

LEGAL GLOSSARY · CONSUMER & CYBER

What Is a Data Fiduciary?

The accountable entity at the centre of India's new privacy law — its duties, the individual's rights against it, and the penalties for failure.

Gyanendra Singh·Advocate·High Court of Madhya Pradesh, Jabalpur

What Does Data Fiduciary Mean?

Under the Digital Personal Data Protection Act, 2023, a data fiduciary is any person or company that determines the purpose and means of processing personal data — in plain terms, whoever decides why and how your information gets used. Apps, e-commerce stores, hospitals, employers and banks are all fiduciaries for the customer data they control.

Accountability sits with the fiduciary even where others touch the data — that allocation is the Act's central design choice.

ROLES

The Three Actors Under the DPDP Act

  • Data Principal: the individual whose data it is — the rights-holder.
  • Data Fiduciary: the decision-maker over processing — the duty-bearer.
  • Data Processor: who handles data on the fiduciary's instructions — vendors, hosting providers, payment gateways — bound by contract but not independently accountable to individuals.
  • Classification follows function per activity: the same company can be fiduciary for one dataset and processor for another.
DUTIES

Core Duties a Fiduciary Owes

  • Process only for disclosed purposes under valid consent or defined legitimate uses, keeping collection minimal and relevant.
  • Give itemised notice — what is collected, why, how to withdraw consent and complain.
  • Maintain reasonable security safeguards against breaches.
  • Notify affected individuals and the Data Protection Board on personal-data breaches.
  • Erase data once purpose is served and consent lapses; facilitate grievance redressal.
  • Children's data carries stricter treatment — verifiable parental consent and bans on tracking or targeted advertising directed at children.
  • Fiduciaries notified as Significant Data Fiduciaries add heavier obligations: resident officers, independent audits and impact assessments.

What Individuals Can Ask For

  • A summary of what personal data is held, the processing done, and who it was shared with.
  • Correction, completion and updating of inaccurate data, plus erasure once retention justifications end.
  • Nomination of another person to exercise these rights on incapacity or death.
  • Grievance resolution from the fiduciary first, then complaint to the Data Protection Board — with substantial penalties attaching to fiduciary failures under the scheduled framework.
Business note: the Act operationalises through rules and phased commencement — map your data inventory, consent flows and vendor contracts now so readiness precedes enforcement rather than chasing it.
FAQ

Data Fiduciaries: Common Questions

1. Is my small business a data fiduciary?

If you decide why and how customer or employee personal data is processed, yes — scale changes obligations' intensity, not the baseline label. Even basic CRM usage brings the notice, consent and security duties into play.

2. Does consent have to be written separately for every purpose?

Consent must be free, specific, informed and unambiguous — bundled blanket acceptances covering unrelated purposes fail that standard. Itemised notices let individuals agree to some uses while refusing others.

3. What happens after a data breach under this regime?

The fiduciary notifies both affected individuals and the Data Protection Board without delay, then faces consequences scaled to negligence and harm — penalties reaching the prescribed ceilings make security budgeting cheaper than breach math.

4. Are government agencies exempt?

The Act carves notification-based exemptions for certain state activities and research purposes — narrower than blanket immunity, and litigated boundaries should be watched as implementation matures.

5. I withdrew consent — must they delete everything immediately?

Erasure follows once consent withdrawal leaves no other lawful basis and no legal retention requirement applies — statutory record-keeping duties can legitimately outlast consent itself.

6. Do existing privacy policies satisfy the notice duty?

Only if they meet the Act's specificity standards — standalone itemised notices describing exact purposes, recipients and withdrawal mechanics typically require policy rewrites rather than cosmetic edits.

Source: Digital Personal Data Protection Act, 2023 (indiacode.nic.in)

Collecting Customer Data Online?

Fiduciary duties arrived whether or not your policies did. Get compliance-mapped before the Board maps you.

Contact Gyanendra Singh →

Disclaimer: This explanation covers the DPDP Act in general terms and is not legal advice. Rules and commencement phases evolve; consult a qualified advocate about your situation.