Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+
Glossary

Someone else's data, on someone else's instructions

Last updated

7 October 2026

Sec. 2(k) defines a Data Processor as anyone who processes personal data on behalf of a Data Fiduciary. The test that separates the two, and who answers.

The Data Processor is the shortest definition in the Digital Personal Data Protection Act, 2023 and the one that causes the most argument in a vendor negotiation. It is also the role with the fewest duties, which is why both sides want it.

The definition, in the Act's words

"Data Processor" means any person who processes personal data on behalf of a Data Fiduciary.

That is Sec. 2(k). Twelve words, and the whole of the meaning sits in "on behalf of". The operations covered are the Sec. 2(x) list — collection, storage, retrieval, use, sharing, disclosure, erasure, destruction — so a vendor that merely stores data is processing it.

The same thing, in one sentence

A Data Processor handles personal data for someone else, on that someone else's instructions, without deciding why it is being handled.

A worked example

A Chennai e-commerce seller runs its own storefront. Its payroll goes to an outside accountant, its order database sits with an Indian cloud provider, its support tickets go through a helpdesk tool, and its deliveries are handed to a courier.

The accountant, the cloud provider and the helpdesk tool are Data Processors. The seller decided what employee and customer data exists and why, and each of the three acts on its instructions.

The courier is the interesting one. Told the address and asked to deliver, it is a processor for that. If it also keeps the address to build its own serviceability map and sell route analytics, it has started deciding a purpose of its own — and for that processing it is a Data Fiduciary, with its own Sec. 5 and Sec. 6 problem. The label in the contract does not change that.

What a Data Processor is not

It is not a Data Fiduciary, and the test is not who holds the data. Sec. 2(i) asks who determines the purpose and means; Sec. 2(k) asks who acts on behalf of that person. A hosting provider holding a hundred million records and making no decision about them is a processor. A two-person agency that decides what to collect and stores nothing itself is a Data Fiduciary.

It is not a label that reduces the Data Fiduciary's exposure. Sec. 8(1) makes the Data Fiduciary responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor, "irrespective of any agreement to the contrary".

It is not a role you can occupy by default. Sec. 8(2) lets a Data Fiduciary involve a Data Processor in any activity related to offering goods or services to Data Principals only under a valid contract. No contract, no lawful engagement.

It is not a role with its own penalty exposure under the Act. The Schedule to Sec. 33(1) attaches its four largest entries to Sec. 8(5), Sec. 8(6), Sec. 9 and Sec. 10 — all duties of a Data Fiduciary or a Significant Data Fiduciary. A processor's downside is contractual rather than statutory, which is what a Sec. 8(2) contract exists to correct.

And it is not the Act's term for the registered intermediary role. That is the Consent Manager, defined separately at Sec. 2(g), which acts on behalf of the Data Principal rather than the Data Fiduciary.

What follows from engaging one

The duties land on the Data Fiduciary, in five places.

A contract first, Sec. 8(2). The engagement itself is conditional on it.

Security that reaches the processor, Sec. 8(5) with Rule 6. Sec. 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control, including processing undertaken on its behalf by a Data Processor. Rule 6(1) of the DPDP Rules, 2025 names the minimum, and two of its clauses point straight at the vendor: (b) measures to control access to the computer resources used by the Data Fiduciary or such a Data Processor, and (f) a provision in the contract between them for taking reasonable security safeguards.

Withdrawal that reaches the processor, Sec. 6(6). On withdrawal the Data Fiduciary must, within a reasonable time, cease processing and cause its Data Processors to cease too. The Act's own illustration is a telecom operator that contracted a processor to email bills: when the customer opts for the app instead, the operator must stop and must make the processor stop.

Erasure that reaches the processor, Sec. 8(7)(b). The same shape — erase, and cause the processor to erase what was made available to it.

Disclosure of the processor to her, Sec. 11(1)(b). On an access request the Data Principal is entitled to the identities of all other Data Fiduciaries and Data Processors the data was shared with. You cannot answer that from memory, which is why the vendor list has to be a record rather than a procurement folder.

One retention point runs the other way. Rule 8(3) requires a Data Fiduciary to retain personal data, traffic data and logs for at least one year, including for processing carried out on its behalf by a Data Processor — and the rule's second illustration is a company that must ensure its cloud provider retains them too.

Where to go next

The Act, from the beginning puts the two roles in sequence with everything else, and the provision map ties Sec. 8(2) and Sec. 8(5) to the controls that discharge them. The processing register is where the answer to Sec. 11(1)(b) comes from: one row per activity, the processors that touch it, and the contract permitting each.