If you decide why the data is collected, this is you
7 October 2026
Sec. 2(i) defines a Data Fiduciary as anyone who determines the purpose and means of processing personal data. What that covers, and the duties that follow.
Almost every obligation in the Digital Personal Data Protection Act, 2023 is written as a duty of the Data Fiduciary, so settling whether you are one comes first. The Act answers it in a single clause that says nothing about your size, your sector or where your servers are.
The definition, in the Act's words
"Data Fiduciary" means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
That is Sec. 2(i). Two words in it are themselves defined. "Person" under Sec. 2(s) reaches an individual, a Hindu undivided family, a company, a firm, the State and every other artificial juristic person, so a proprietorship and a municipal body both qualify. "Processing" under Sec. 2(x) runs from collection and storage through sharing and disclosure to erasure.
The same thing, in one sentence
You are a Data Fiduciary if you decide why personal data is collected and how it is handled — whoever actually does the handling.
The phrase "in conjunction with other persons" matters. Two companies that jointly settle the purpose are each a Data Fiduciary for that processing, and the Act gives neither a reduced duty for sharing the decision.
A worked example
A diagnostic lab chain in Pune runs its own booking site. It decides what it asks a patient for — name, mobile number, age, the test ordered — and why: to run the test, to send the report, and to remind her when an annual panel is due. It is the Data Fiduciary for all three purposes.
It also uses a cloud provider to host the records, an SMS gateway to send the report link, and an external pathologist to read one specialist assay. None of the three decided what to collect or why. Each is a Data Processor acting on the lab's instructions, and the lab stays answerable for what they do.
Now change one fact. The SMS gateway starts mining the appointment data for its own marketing segments. It is deciding that purpose itself, so for that processing it is a Data Fiduciary in its own right — whatever the contract calls it.
What a Data Fiduciary is not
It is not whoever holds the data. Possession is not the test; deciding purpose and means is. A company whose entire estate sits in someone else's data centre is still the Data Fiduciary for it.
It is not a role you can contract out of. Sec. 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a Data Processor, and says so "irrespective of any agreement to the contrary". A clause assigning liability to a vendor only decides who pays whom afterwards.
It is not a status that turns on turnover, headcount or sector — the Act sets no floor. What decides whether the Act reaches you at all is Sec. 3, and whether the DPDP Act applies to your organisation works through that test. Nor is it the same thing as a Significant Data Fiduciary, which is a Data Fiduciary the Central Government has notified under Sec. 10 for extra duties.
What follows from being one
Sec. 4(1) lets you process personal data only for a lawful purpose and only on one of two grounds: her consent, or one of the certain legitimate uses in Sec. 7.
If you rely on consent, Sec. 5(1) requires a notice to accompany or precede every request for it, and Sec. 5(3) gives her the option of reading that notice in English or any language in the Eighth Schedule to the Constitution. Sec. 6(1) requires the consent itself to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. What a consent notice must contain takes Sec. 5 clause by clause.
Withdrawal is the part most often under-built. Sec. 6(4) lets her withdraw at any time with ease comparable to the ease of giving, and Sec. 6(6) then requires you, within a reasonable time, to cease processing and to cause your Data Processors to cease. Sec. 6(10) puts the burden of proof on you: where consent is the basis and a question arises in a proceeding, you must prove that a notice was given and that consent was given.
Sec. 8 carries the rest whichever ground you relied on — a valid contract before you engage a Data Processor at Sec. 8(2), reasonable security safeguards at Sec. 8(5), breach intimation to the Board and to each affected person at Sec. 8(6), erasure at Sec. 8(7), and a grievance mechanism at Sec. 8(10). Rule 6 of the DPDP Rules, 2025 sets the minimum content of those safeguards, down to encryption, access control and a year of logs.
The ceilings sit in the Schedule to Sec. 33(1), and the largest — up to 250 crore rupees — attaches to Sec. 8(5), the security duty, rather than to anything about consent screens.
Where to go next
The Act, from the beginning puts these duties in order and against their dates; the provision map lists each against the control that discharges it. On our side, the processing register is where a Data Fiduciary writes down what it has decided to process and why, one row per activity, because nothing else can be built before that exists.