Readiness assessment

DPDP by role

DPDP Act for Data Fiduciaries

You decide why and how personal data is processed, which makes you the primary obligated party under the DPDP Act.

At a glance

A Data Fiduciary is any person or organisation that, alone or with others, decides the purpose and means of processing personal data. It carries the core DPDP duties: give notice, obtain valid consent or rely on a specified legitimate use, secure the data, honour Data Principal rights, notify breaches, limit retention, and engage processors only under contract.

What the DPDP Act means for you

The Data Fiduciary is the central actor in the DPDP Act, the organisation that decides what happens to personal data and therefore carries the obligations. Whether you are a company, a nonprofit or a government body, if you determine the purpose and means of processing, these core duties apply to you.

Your priorities

Notice and lawful basis

Give a clear Section 5 notice and rely on valid consent or a specified legitimate use.

Security and breach

Apply reasonable safeguards and be ready to notify breaches on the required timeline.

Rights and retention

Honour access, correction, erasure and grievance rights, and keep data only as long as needed.

Processor contracts

Only engage processors under a contract, and stay responsible for their processing.

Where to start

Build the record

Map your processing into a record of processing.

Notice and consent

Publish a compliant notice and fix your consent basis.

Stand up controls

Security, breach response, rights handling and retention.

Bind processors

Add DPDP clauses to every processor contract.

Tools and help

Move fast with ready-made resources, or get expert help where it matters:

Frequently asked questions

What is a Data Fiduciary?
Any person or organisation that, alone or with others, decides the purpose and means of processing personal data. It is the primary obligated party under the DPDP Act.
What is the difference between a Fiduciary and a Processor?
The Fiduciary decides why and how data is processed; the Processor only acts on the Fiduciary's instructions. The Fiduciary remains responsible for compliance.
What are the core obligations?
Notice, valid consent or legitimate use, security, breach notification, retention limits, honouring Data Principal rights, and proper processor contracts.

See where you stand

Take the free readiness assessment for a picture tailored to your organisation, then choose a tool or a partner.

Start free readiness assessmentSee the Compliance Toolkit

This page is educational and not legal advice. Confirm against the enacted Act and the DPDP Rules, or take professional advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.