Every data fiduciary obligation, mapped to the provision
6
duties, each mapped to a named control
Across 8 sections and 5 rules, read against the bare text
The provisions that govern consent, and the thing in the platform that discharges each one. Mapping is not certification — the evidence is yours to check, and this page exists so you can.
The matrix
Left: what the provision requires, in its own terms. Right: what the platform does about it.
Notice to the Data Principal
What it requires
An itemised notice, in English or any of the 22 Eighth Schedule languages, given before or at the point consent is requested.
The control
Versioned notice templates per purpose, with the exact text and language snapshotted into the consent record.
Consent Standard and Data Minimisation
What it requires
Free, specific, informed, unconditional and unambiguous, by clear affirmative action, and limited to the data necessary for the stated purpose.
The control
Purpose-scoped toggles with nothing pre-ticked, one record per purpose, and a diff trail whenever a purpose changes.
Withdrawal of Consent
What it requires
Withdrawal at any time, as easy as granting was, after which the fiduciary and its processors must cease processing within a reasonable time.
The control
One-action withdrawal, downstream propagation over webhooks, and a cessation timestamp per system that acknowledged it.
Security Safeguards and Breach Reporting
What it requires
Reasonable safeguards to prevent a breach; affected principals intimated without delay and a detailed report to the Board within 72 hours.
The control
Encryption at rest and in transit, role-based access, logs retained for a year, and a breach workflow that runs the 72-hour clock.
Rights of the Data Principal
What it requires
Access to information about processing, correction and erasure, grievance redressal, and the right to nominate.
The control
A rights portal with identity verification, an SLA clock per request type, and the nomination held with the consent artefact.
Cross-Border Transfer
What it requires
Transfer is permitted except to countries the Central Government restricts, and sectoral conditions still apply.
The control
Geo-fenced storage with a transfer register, enforced at the point of write rather than in a policy document.
Ask yourself
Ten questions a Data Fiduciary has to be able to answer
These are not claims about us. They are what the Act puts to you, with the provision each one comes from. If any answer is “we would have to go and look”, that is the finding.
- 01Every purpose is itemised, with nothing bundledSec. 6(1)
- 02Notice carries every required particular, in a language the person readsSec. 5, Rule 3
- 03Consent is a clear affirmative action, with nothing pre-tickedSec. 6(1)
- 04Withdrawal is as easy as granting was, and processing stopsSec. 6(4), 6(6)
- 05Consent records can be reproduced with the notice the person actually saw
- 06Rights requests have an owner and a published response windowSec. 11–14, Rule 14
- 07A named grievance officer is reachable, and the route is publishedSec. 13
- 08A breach can be reported to the Board within 72 hoursSec. 8(6), Rule 7
- 09Retention has a clock per purpose, and erasure actually runsSec. 8(7), Rule 8
- 10Cross-border destinations are checked against the restricted listSec. 16, Rule 15
Sec. 13 · Rule 14
The duty most platforms answer with a mailbox
A grievance is a statutory obligation with a named officer, a published route and a response window. Every request in the queue has an owner and a clock, and the clock is visible before it runs out rather than after.
Grievance console
Every request has an owner and a clock. Sec. 13 · Rule 14
What changes
Seven areas, before and after
| Area | Today | With myconsent+ |
|---|---|---|
| Consent Capture | Manual, error-prone | Automated, contextual, granular |
| Data Mapping | Spreadsheet-based | AI-driven, real-time discovery |
| Audit Trails | Disconnected logs | Append-only, hash-chained and verifiable |
| DSR Response | Days/weeks | Real-time automated fulfillment |
| Breach Detection | Manual monitoring | Automated, instant notification |
| Cross-Border | No controls | Geo-fenced, localized enforcement |
| Reporting | Quarterly manual | On-demand, one-click regulatory |
Bring a purpose you actually collect consent for
We will build it live — the notice, the capture, the withdrawal, and the evidence you would hand the Board. Thirty minutes, no slides.
Questions people ask
- What is a Data Fiduciary under the DPDP Act?
- Any person who, alone or with others, determines the purpose and means of processing personal data. It is the DPDP equivalent of a controller, and the duties on notice, consent, safeguards, rights and breach reporting attach to it rather than to a processor.
- What is a Significant Data Fiduciary?
- A Data Fiduciary the Central Government notifies as significant, judged on volume and sensitivity of data, risk to Data Principals, and effect on sovereignty, electoral democracy and public order. It carries extra duties: a Data Protection Officer in India, an independent auditor, and periodic impact assessment.
- What are the main obligations of a Data Fiduciary?
- Give notice under Sec. 5. Take valid consent under Sec. 6(1) and honour withdrawal under Sec. 6(4). Keep reasonable security safeguards under Sec. 8(5) and report breaches under Sec. 8(6). Answer rights requests under Sec. 11 to 14. Observe Sec. 16 on cross-border transfer.
- What are the penalties for a Data Fiduciary?
- The Schedule sets ceilings imposed by the Board under Sec. 33. The largest, ₹250 crore, attaches to failing to take reasonable security safeguards. Failure to notify a breach reaches ₹200 crore, as does breach of the obligations on children's data.
- Is a Data Fiduciary the same as a data controller under the GDPR?
- Functionally close, but not identical. Both determine purpose and means. The DPDP Act has no separate category for sensitive data, a narrower set of lawful bases, and its own Significant Data Fiduciary tier with duties the GDPR places on controllers generally.