Konfirmity

Data Fiduciary: The role DPDP puts you in, and what it costs (2026)

Author

Konfirmity

2026-10-05

Every duty in India's Digital Personal Data Protection Act keys off which of three roles you occupy, so the role determination is the first piece of DPDP work and the one that invalidates everything downstream if you get it wrong. A Data Fiduciary carries the substantive obligations. A Data Processor carries them contractually. A Significant Data Fiduciary carries both plus four more.

Most teams arriving from GDPR assume Data Fiduciary is simply the Indian word for controller. It is close enough to be useful and different enough to matter, and the difference is deliberate.

What Is a Data Fiduciary?

A Data Fiduciary is the person who determines the purpose and means of processing personal data. That is the whole test. If you decide why personal data is processed and how, you are a Data Fiduciary for that activity, regardless of who owns the infrastructure it runs on or who physically handles the records.

The role is activity-specific rather than organisation-wide. The same company is routinely a Data Fiduciary for its own employee and marketing data and a Data Processor for the customer data it handles under contract. Determining the role once for the whole business is the most common sequencing error in a DPDP programme, because it produces a notice and consent design that fits some processing activities and not others.

Why DPDP Says Fiduciary Rather Than Controller

The word choice is substantive. A fiduciary relationship in Indian law carries an expectation of acting in another party's interest, and the Act's drafters chose it over the GDPR's "controller" to signal that the duty runs toward the Data Principal rather than merely constraining the processor.

In practice the operative duties resemble a controller's. What the terminology changes is the interpretive posture: where a provision is ambiguous, the reading that favours the Data Principal is the safer planning assumption. The Act also gives the Data Principal duties of her own under section 15, which has no GDPR equivalent, so the relationship is not one-directional.

Data Fiduciary vs Data Processor vs Significant Data Fiduciary

The three roles are not tiers of the same obligation. They are different positions with different exposure.

RoleTestWhere the duty comes from
Data FiduciaryDetermines the purpose and means of processingDirectly from the Act and the Rules
Data ProcessorProcesses on a fiduciary's behalfContractually, via section 8(2) and rule 6(f)
Significant Data FiduciaryA Data Fiduciary the Central Government notifies as significant under section 10The Act and Rules, plus rule 13's four additional duties

A Data Processor is not lightly regulated so much as regulated through someone else's contract. Section 8(2) permits a fiduciary to engage a processor "only under a valid contract," and rule 6(f) requires that contract to oblige the processor to take reasonable security safeguards. The practical effect is that processor obligations arrive as procurement terms, which is why processor-side DPDP readiness is now a sales question rather than a legal one.

A Significant Data Fiduciary is a Data Fiduciary the government has notified. You do not self-assess into the category and you cannot opt in.

Not sure which role you are, activity by activity?

Share your work email and we'll walk your processing activities against the three DPDP roles and mark where your existing ISO 27001 or GDPR work already carries the duty.

We check that your email domain is real and can receive mail before sending. If we can't verify it, we won't be able to follow up — so please use a work address rather than a forwarding or temporary one.

We'd like to know who we're talking to. By submitting this form you agree that we may contact you about Konfirmity — no more than six emails a year, and we won't ask again each time. You can unsubscribe from any of them, and we'll stop. See our Privacy Policy.

There Is No Size Threshold

This is the single most misunderstood feature of the role. Unlike the CCPA's revenue and volume thresholds, or the Significant Data Fiduciary category the government notifies on the basis of volume and sensitivity, the baseline Data Fiduciary duties apply regardless of headcount, revenue or user count.

A ten-person startup processing the personal data of Indian users is a Data Fiduciary with the same core obligations as a bank. The Third Schedule retention rules do carry user-count thresholds, but those add a duty for large platforms rather than removing one for small ones.

The reach extends past India's borders too. Section 3 applies the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering goods or services to Data Principals within the territory of India. A US or Singapore SaaS company with Indian customers is a Data Fiduciary under Indian law.

The Duties That Attach to the Role

Seven duties attach to the Data Fiduciary role, and the notified DPDP Rules name each one specifically rather than leaving it to a risk assessment. Almost all of them commence in mid-May 2027, eighteen months after the Rules were published in the Gazette.

  • Notice that itemises. Rule 3 requires a standalone notice giving an itemised description of the personal data, the specific purposes, and the goods, services or uses enabled. A privacy policy saying you collect "contact and usage information" itemises nothing.
  • Withdrawal at parity. Rule 3(c)(i) requires withdrawal to be comparably easy to granting. One-click in, one-click out.
  • Seven security safeguards. Rule 6 names them, including a one-year retention floor on logs and personal data and a safeguards clause in every processor contract. If you already run access controls and a logging pipeline for another framework, most of this is evidence mapping.
  • Two breach clocks. Rule 7 requires intimation to affected Data Principals and a first intimation to the Board without delay, and a detailed submission to the Board within seventy-two hours of awareness.
  • Retention and erasure. Rule 8 sets an inactivity clock for the Third Schedule classes with forty-eight hours' advance notice before erasure, and a one-year minimum retention floor for everyone.
  • A published contact. Rule 9 requires the business contact details of the Data Protection Officer if applicable, or of someone who can answer processing questions, published prominently and repeated in every rights response.
  • Rights and grievances. Rule 14 requires a published grievance-response period that cannot exceed ninety days, and measures that make the system actually meet it.

The full duty-by-duty breakdown, with the rule each one comes from, is in our DPDP compliance checklist.

How to Determine Your Role in Practice

Work activity by activity rather than entity by entity, and write down the answer with the reasoning. The determination is the document an assessor will ask to see first.

  1. List the processing activities, not the systems. "Running payroll" and "sending product marketing" are activities; "the HR database" is not.
  2. For each, ask who decided the purpose. If a customer told you what to do with the data and you executed it, you are likely a processor for that activity. If you decided, you are a fiduciary.
  3. Ask who decided the means. Choosing your own sub-processors, retention periods or enrichment sources pulls you toward fiduciary even where the purpose came from a customer.
  4. Record the mixed cases. A SaaS vendor is almost always a processor for customer-uploaded data and a fiduciary for the account and usage data it decides to collect about its users. Both are true at once.
  5. Re-run it when the product changes. Adding analytics, enrichment or an AI feature that processes customer data for your own purposes can move an activity from processor to fiduciary without anyone filing a ticket about it.

What It Costs to Get the Role Wrong

Getting the role wrong costs you in a specific way: misclassifying yourself as a processor when you are in fact a fiduciary means you have no notice, no consent mechanism and no rights-fulfilment path for data you are directly accountable for. The Schedule to the Act sets ceilings rather than tariffs, and the largest band attaches to the security-safeguards duty in section 8(5) at up to 250 crore rupees. Failure to give the Board or affected Data Principals breach notice sits in a separate band at up to 200 crore rupees, and most other contraventions fall into a residual band at up to 50 crore rupees.

Section 33(2) requires the Board to weigh the nature, gravity and duration of the breach, the type of data affected, whether it was repetitive, gain realised or loss avoided, mitigation taken, proportionality and the likely impact of the penalty. Prompt mitigation is written into the statute as a factor, which means a documented role determination and a visible remediation effort are worth more than an argument about scope after the fact.

Data Fiduciary Questions Teams Ask

Functionally close, deliberately not identical. Both turn on determining the purpose and means of processing, and the operative duties overlap heavily. The word "fiduciary" signals a duty running toward the Data Principal rather than a constraint on the processor, which matters where a provision is ambiguous. There are also substantive divergences: DPDP has no legitimate-interest basis of the GDPR kind, its child threshold is eighteen rather than thirteen to sixteen, and rule 8(3) imposes a one-year minimum log retention that cuts against a delete-on-request reflex.

Yes, and most B2B companies are. The role is determined per processing activity, not per company. A SaaS vendor is typically a Data Processor for the personal data its customers upload and a Data Fiduciary for the account, billing and product-usage data it decides to collect about its own users. Both roles run in parallel and carry different duties, which is why the role determination has to be done activity by activity.

Yes, where the processing relates to offering goods or services to Data Principals in India. Section 3 extends the Act to processing of digital personal data outside India in connection with any activity related to offering goods or services to Data Principals within the territory of India. No Indian entity, office or infrastructure is required. This is why DPDP clauses are appearing in Indian enterprise procurement paperwork aimed at foreign vendors.

Only if you are a notified Significant Data Fiduciary. Section 10(2) requires a notified SDF to appoint a DPO based in India who represents the entity, is responsible to its board or equivalent governing body, and is the contact point for grievance redressal. An ordinary Data Fiduciary has a lighter duty under rule 9: prominently publish the business contact information of the DPO if applicable, or of a person who can answer questions about processing. A named contact is mandatory; a formally appointed DPO is not.

Rule 1 splits commencement into three tranches. Rules 1, 2 and 17 to 21 came into force on 14 November 2025, the day the Rules were published in the Gazette. Rule 4, governing Consent Manager registration, commences one year after that. Rules 3 and 5 to 16, which carry almost every operational duty a Data Fiduciary has to build for, commence eighteen months after publication, in mid-May 2027. That is a single cliff rather than a ramp.

Turn a role determination into a working DPDP programme

Book a demo and we'll spend 30 minutes mapping your processing activities against the three DPDP roles, marking what your existing ISO 27001, SOC 2 or GDPR work already covers.

Book a demo

Why the Role Determination Comes First

The role determination comes first because Data Fiduciary is the default position under DPDP, not a category you qualify into. There is no revenue floor, no user-count threshold and no exemption for being small or foreign. If you decide why and how personal data about people in India is processed, the Act's substantive duties are yours.

The determination is worth doing properly and writing down, because it is activity-specific, it changes when the product changes, and every duty downstream depends on it. Start there, then itemise what you hold — everything in rule 3 through rule 15 keys off knowing exactly that.

//related blogs

Konfirmity

The Privacy Rule: Understanding its role in compliance and s...

Konfirmity

2026-01-19

The Privacy Rule: Understanding its role in compliance and security (2026)

arrow

What is the HIPAA Privacy Rule? We explain what it is, who it applies to, and its (2026) role in compliance and patient data security.

Konfirmity

What is a Data Breach: The basics every business should know...

Konfirmity

2026-01-19

What is a Data Breach: The basics every business should know (2026)

arrow

What really counts as a data breach? We cover the (2026) basics, the different types, and what every business needs to know.

Konfirmity

ISO/IEC 15288: Definition, use cases, and compliance relevan...

Konfirmity

2026-01-19

ISO/IEC 15288: Definition, use cases, and compliance relevance (2026)

arrow

How do you manage a system's life cycle? Get the (2026) definition of ISO/IEC 15288, its use cases, and its relevance for systems engineering.

Konfirmity

What ISO Stands For: How it supports data protection standar...

Konfirmity

2025-12-12

What ISO Stands For: How it supports data protection standards (2026)

arrow

Learn what ISO stands for and how its standards help keep data safe. This guide explains the role of ISO in shaping strong security practices heading into 2026.

Konfirmity

Risk Management Framework (ISO 31000): Meaning, purpose, and...

Konfirmity

2026-01-19

Risk Management Framework (ISO 31000): Meaning, purpose, and real-world importance (2026)

arrow

How do you really manage risk? We explain the ISO 31000 framework, its (2026) purpose, and its real-world importance for any business.

Konfirmity

CAGE Code: Meaning, purpose, and real-world importance (2026...

Konfirmity

2025-12-04

CAGE Code: Meaning, purpose, and real-world importance (2026)

arrow

What's a CAGE Code and why does it matter? Get the (2026) breakdown on its meaning, purpose, and real-world importance for government contractors.

How Real Security Becomes Compliance

Built by the CTO who scaled NIUM to $2 billion. 10 years building security and compliance for regulated fintechs. 4.5 years running Konfirmity profitably.

Book a call