Chapter II · Obligations of Data Fiduciary
Section 8: General obligations of Data Fiduciary
Section 8 is the core duty list: stay accountable for your processors, keep data accurate, secure it with reasonable safeguards, report breaches, erase data when its purpose ends, and publish a contact and grievance route.
- Chapter
- Chapter II · Obligations of Data Fiduciary
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Data Fiduciaries
- Official citation
- DPDP Act, 2023, s.8
- Reading time
- 5 min
- Updated
- August 2026
At a glance
Section 8 sets out the general obligations of a Data Fiduciary. It remains responsible for compliance even where a Data Processor acts on its behalf, and may engage a processor only under a valid contract. It must keep data accurate and complete where it drives decisions, apply reasonable security safeguards, notify the Board and affected individuals of a personal data breach, erase data once consent is withdrawn or the purpose is served, and publish contact details and an effective grievance mechanism.
Key takeaways
- You stay responsible for compliance even when a Data Processor acts for you.
- You may engage a processor only under a valid contract.
- Keep personal data accurate, complete and consistent where it is used for decisions or shared.
- Apply reasonable security safeguards to prevent a personal data breach.
- On a breach, notify the Board and each affected Data Principal in the prescribed manner.
- Erase personal data once consent is withdrawn or the purpose is served, and make processors erase too.
- Publish a contact point and an effective grievance redressal mechanism.
Who should read this
Read this if you are a Data Fiduciary, which is most organisations, because it is the backbone duty list every compliance programme is measured against.
In plain language
If Sections 5 to 7 are about how you start processing, Section 8 is about how you run it responsibly. The first principle is accountability: you remain responsible for compliance even where a Data Processor handles the data for you, and you may only engage one under a valid contract.
Then come the operational duties. Where personal data is used to make a decision about someone or is shared onward, you must keep it accurate, complete and consistent. You must protect it with reasonable security safeguards. And if a personal data breach happens, you must notify the Board and each affected person in the prescribed manner.
Finally, data should not live forever. When consent is withdrawn or the purpose is served, you must erase the data (unless a law requires you to keep it) and make your processors erase it too. And you must publish a business contact point and run an effective grievance mechanism so people can reach you.
The text of the law
Section 8: General obligations (key duties)
Accountability A Data Fiduciary is responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor, and may engage a Data Processor only under a valid contract.
Accuracy Where personal data is likely to be used to make a decision that affects the Data Principal, or is to be disclosed to another Data Fiduciary, the Data Fiduciary shall ensure its completeness, accuracy and consistency.
Security safeguards A Data Fiduciary shall protect personal data in its possession or under its control by taking reasonable security safeguards to prevent a personal data breach.
Breach intimation In the event of a personal data breach, the Data Fiduciary shall give intimation of the breach to the Board and to each affected Data Principal, in the form and manner prescribed.
Erasure The Data Fiduciary shall erase personal data on the Data Principal withdrawing consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is required by law, and shall cause its Data Processors to erase it.
Contact and grievance The Data Fiduciary shall publish the business contact information of a Data Protection Officer (if applicable) or a person able to answer questions about the processing, and establish an effective mechanism to redress grievances of Data Principals.
This groups the key duties of Section 8, which sets them out across several sub-sections. Always confirm against the official Gazette text for authoritative language.
What this means for you
- Put a DPDP-aligned contract in place with every processor and vendor.
- Stand up reasonable security safeguards and log them.
- Write a breach-response plan that can meet the reporting duty.
- Set retention limits and an erasure process, including for processors.
- Publish a named contact and a working grievance route.
Frequently asked questions
What are the main obligations of a Data Fiduciary?
Am I still responsible if a vendor causes a breach?
When must I erase personal data?
Do I have to report data breaches?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.