Readiness assessment
Share this section

Chapter II · Obligations of Data Fiduciary

Section 8: General obligations of Data Fiduciary

Section 8 is the core duty list: stay accountable for your processors, keep data accurate, secure it with reasonable safeguards, report breaches, erase data when its purpose ends, and publish a contact and grievance route.

Official text
Section 8General obligations of Data Fiduciary
Chapter
Chapter II · Obligations of Data Fiduciary
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Data Fiduciaries
Official citation
DPDP Act, 2023, s.8
Reading time
5 min
Updated
August 2026

At a glance

Section 8 sets out the general obligations of a Data Fiduciary. It remains responsible for compliance even where a Data Processor acts on its behalf, and may engage a processor only under a valid contract. It must keep data accurate and complete where it drives decisions, apply reasonable security safeguards, notify the Board and affected individuals of a personal data breach, erase data once consent is withdrawn or the purpose is served, and publish contact details and an effective grievance mechanism.

Applies to Data FiduciariesChapter Chapter IIEffective 13 May 2027Read time 6 min

Key takeaways

  • You stay responsible for compliance even when a Data Processor acts for you.
  • You may engage a processor only under a valid contract.
  • Keep personal data accurate, complete and consistent where it is used for decisions or shared.
  • Apply reasonable security safeguards to prevent a personal data breach.
  • On a breach, notify the Board and each affected Data Principal in the prescribed manner.
  • Erase personal data once consent is withdrawn or the purpose is served, and make processors erase too.
  • Publish a contact point and an effective grievance redressal mechanism.

Who should read this

Read this if you are a Data Fiduciary, which is most organisations, because it is the backbone duty list every compliance programme is measured against.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

If Sections 5 to 7 are about how you start processing, Section 8 is about how you run it responsibly. The first principle is accountability: you remain responsible for compliance even where a Data Processor handles the data for you, and you may only engage one under a valid contract.

Then come the operational duties. Where personal data is used to make a decision about someone or is shared onward, you must keep it accurate, complete and consistent. You must protect it with reasonable security safeguards. And if a personal data breach happens, you must notify the Board and each affected person in the prescribed manner.

Finally, data should not live forever. When consent is withdrawn or the purpose is served, you must erase the data (unless a law requires you to keep it) and make your processors erase it too. And you must publish a business contact point and run an effective grievance mechanism so people can reach you.

The text of the law

Section 8: General obligations (key duties)

Accountability A Data Fiduciary is responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor, and may engage a Data Processor only under a valid contract.

Accuracy Where personal data is likely to be used to make a decision that affects the Data Principal, or is to be disclosed to another Data Fiduciary, the Data Fiduciary shall ensure its completeness, accuracy and consistency.

Security safeguards A Data Fiduciary shall protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach.

Breach intimation In the event of a personal data breach, the Data Fiduciary shall give intimation of the breach to the Board and to each affected Data Principal, in the form and manner prescribed.

Erasure The Data Fiduciary shall erase personal data on the Data Principal withdrawing consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is required by law, and shall cause its Data Processors to erase it.

Contact and grievance The Data Fiduciary shall publish the business contact information of a Data Protection Officer (if applicable) or a person able to answer questions about the processing, and establish an effective mechanism to redress grievances of Data Principals.

This groups the key duties of Section 8, which sets them out across several sub-sections. Always confirm against the official Gazette text for authoritative language.

What this means for you

Frequently asked questions

What are the main obligations of a Data Fiduciary?
Accountability for processors, data accuracy where it drives decisions, reasonable security safeguards, breach notification to the Board and affected people, erasure when consent is withdrawn or the purpose ends, and a published contact and grievance mechanism.
Am I still responsible if a vendor causes a breach?
Yes. A Data Fiduciary remains responsible for compliance even where a Data Processor acts on its behalf, and must engage processors under a valid contract.
When must I erase personal data?
When consent is withdrawn or the specified purpose is no longer served, whichever is earlier, unless a law requires retention. Processors must erase too.
Do I have to report data breaches?
Yes. You must notify the Data Protection Board and each affected Data Principal in the prescribed manner.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment