← Back to Blog
•Infiverix Compliance Team

Data Fiduciary vs Data Processor: Your Role Under DPDP Act

Data FiduciaryData ProcessorDPDP Act

Before you can comply with India's Digital Personal Data Protection (DPDP) Act 2023, you must accurately identify your legal role. The Act assigns specific responsibilities based on whether you dictate how data is used or if you are simply handling it on someone else's behalf.

Misidentifying your role can lead to severe compliance gaps, exposing you to penalties of up to ₹250 Crores. The core distinction lies between being a Data Fiduciary and a Data Processor.

This guide will clarify these definitions, provide real-world examples, and outline the distinct obligations tied to each role.

Defining the Roles

What is a Data Fiduciary?

Under the DPDP Act, a Data Fiduciary is defined as any person (which includes companies, firms, and the state) who determines the purpose and means of processing personal data, either alone or in conjunction with others.

Put simply, if you answer the questions “Why are we collecting this data?” and “How will we use it?”, you are the Data Fiduciary. You are the entity that the user (the Data Principal) trusts with their information.

What is a Data Processor?

A Data Processor is any person who processes personal data on behalf of a Data Fiduciary.

Processors do not decide the purpose of the data collection. They merely act on the instructions of the Fiduciary. They provide a service, such as cloud storage, analytics, or payroll processing, using the data provided to them.

For a broader overview of the Act's terminology and scope, read our foundational post: What is the DPDP Act 2023?.

Real-World Examples

It is highly common for a business to act as a Data Fiduciary in one context and a Data Processor in another.

Example 1: A B2B SaaS Company (e.g., HR Management Software)

  • As a Data Processor: When the SaaS company processes the employee data of its corporate clients (calculating payroll, managing leave requests), it acts as a Data Processor. The corporate client is the Data Fiduciary because they decided to collect that employee data.
  • As a Data Fiduciary: When the same SaaS company collects data from its own website visitors for marketing, or processes the data of its own direct employees, it acts as a Data Fiduciary.

Example 2: An E-commerce Store and a Payment Gateway

  • The e-commerce store is the Data Fiduciary. They decide to sell products and require customer data to fulfill orders.
  • The payment gateway is the Data Processor. They process the financial data purely on behalf of the e-commerce store to complete the transaction.

If you are dealing with user consent on your own platforms, you must build a compliant system. See our guide on How to Build a DPDP-Compliant Consent System in India.

Obligations of a Data Fiduciary

The bulk of the legal burden under the DPDP Act falls on the Data Fiduciary. Your primary obligations include:

  1. Ensuring Lawful Processing: Obtaining valid consent or relying on legitimate uses.
  2. Providing Notice: Giving clear, multilingual notices before collecting data.
  3. Data Minimization and Accuracy: Collecting only what is necessary and keeping it updated.
  4. Implementing Security Safeguards: Protecting data against breaches.
  5. Fulfilling Data Principal Rights: Responding to requests for access, correction, and erasure. If you need help with this, consult our Right to Erasure Guide.
  6. Grievance Redressal: Providing a mechanism for users to lodge complaints.
  7. Managing Processors: Ensuring that any Data Processors you hire are bound by a valid contract that enforces DPDP compliance. You remain ultimately responsible for the actions of your processors.

To verify you are meeting all Fiduciary requirements, use our DPDP Compliance Checklist.

What is a Significant Data Fiduciary (SDF)?

The DPDP Act introduces a sub-category: the Significant Data Fiduciary (SDF). The Central Government will designate certain Fiduciaries as SDFs based on criteria like the volume of data processed, the sensitivity of the data, and potential risks to national security or public order.

SDFs face stricter obligations, including:

  • Appointing a Data Protection Officer (DPO) based in India.
  • Appointing an independent Data Auditor to evaluate compliance.
  • Conducting periodic Data Protection Impact Assessments (DPIAs).

To see how this compares to international frameworks, check our DPDP Act vs GDPR comparison.

Obligations of a Data Processor

While the DPDP Act places the primary liability on the Fiduciary, Processors are not off the hook.

  1. Contractual Compliance: Processors must strictly adhere to the data processing agreement signed with the Fiduciary.
  2. Security Measures: Processors must implement robust security safeguards to protect the data they handle, as a breach on their end will directly implicate the Fiduciary.
  3. Assisting the Fiduciary: Processors must build their systems in a way that allows the Fiduciary to fulfill user requests (like data deletion or retrieval).

How to Determine Your Role

Ask yourself these questions regarding any dataset you handle:

  1. Who decides why the data is collected?
  2. Who decides what specific data elements to collect?
  3. Who has the direct relationship with the user?

If the answer is "We do," you are likely the Data Fiduciary. If the answer is "Our client does," you are likely a Data Processor.

Regardless of your role, Infiverix provides the tools to manage your DPDP obligations efficiently, from mapping data flows to managing processor agreements.

Go to Dashboard to Start Complying


Ready to automate your DPDP compliance?

Join Indian startups using Infiverix to manage consent and data rights effortlessly.

Start Free Pilot