Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Compare terms

Data Fiduciary vs Data Processor

The difference comes down to control. A Data Fiduciary decides why and how personal data is processed. A Data Processor only acts on the fiduciary's instructions. The fiduciary carries the responsibility either way.

Data Fiduciary
Data Processor
Plain definition
Decides why and how personal data is processed.
Processes personal data on behalf of a Data Fiduciary.
Decides purpose and means?
Yes. This is what defines the role.
No. It follows the fiduciary's instructions.
Statutory reference
Section 2(i)
Section 2(k)
Acts for
Itself, and its own stated purposes.
The Data Fiduciary that engaged it.
Primary responsibility
Non-delegable under Section 8(1).
Acts under contract; fiduciary stays accountable.
Needs a contract?
Engages processors under a valid contract (Section 8(2)).
Must be engaged under a valid contract.
Everyday example
A bank collecting KYC to open accounts.
A vendor the bank hires to verify the KYC.

Why the distinction matters

Responsibility follows control. The Data Fiduciary is the party the Data Protection Board and Data Principals deal with, and it carries the statutory duties — including breach notification under Section 8(6). A Data Processor acts on the fiduciary's instructions under a valid contract (Section 8(2)). Misclassifying either role mis-allocates liability, the breach-reporting duty and contract obligations.

When each applies

You are a Data Fiduciary for data whose purpose and means you decide — your own customers and employees. You are a Data Processor when you handle another organisation's data strictly on its instructions, such as a SaaS platform, a payroll bureau or a KYC-verification vendor. The same company is frequently both: a fiduciary for its own users and a processor for its clients' data.

Common confusions to avoid

“Outsourcing shifts the responsibility.” It doesn't. Under Section 8(1) the fiduciary's responsibility is non-delegable, even when a processor does the work.

Assuming the processor answers to the Board. The Rule 7 breach-notification duty sits with the fiduciary; the processor's job is to escalate and assist under contract.

Thinking a processor has no duties. It must be engaged under a valid contract and meet the security safeguards required in that contract under Rule 6.

Related glossary terms

Frequently asked questions

Can one company be both?

Yes. It is a fiduciary for its own purposes and a processor when handling another fiduciary's data under instruction.

Who is liable if a processor mishandles data?

The fiduciary carries primary responsibility and stays accountable for the processor's compliance.