Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsCompare terms
The difference comes down to control. A Data Fiduciary decides why and how personal data is processed. A Data Processor only acts on the fiduciary's instructions. The fiduciary carries the responsibility either way.
Responsibility follows control. The Data Fiduciary is the party the Data Protection Board and Data Principals deal with, and it carries the statutory duties — including breach notification under Section 8(6). A Data Processor acts on the fiduciary's instructions under a valid contract (Section 8(2)). Misclassifying either role mis-allocates liability, the breach-reporting duty and contract obligations.
You are a Data Fiduciary for data whose purpose and means you decide — your own customers and employees. You are a Data Processor when you handle another organisation's data strictly on its instructions, such as a SaaS platform, a payroll bureau or a KYC-verification vendor. The same company is frequently both: a fiduciary for its own users and a processor for its clients' data.
“Outsourcing shifts the responsibility.” It doesn't. Under Section 8(1) the fiduciary's responsibility is non-delegable, even when a processor does the work.
Assuming the processor answers to the Board. The Rule 7 breach-notification duty sits with the fiduciary; the processor's job is to escalate and assist under contract.
Thinking a processor has no duties. It must be engaged under a valid contract and meet the security safeguards required in that contract under Rule 6.
Can one company be both?
Yes. It is a fiduciary for its own purposes and a processor when handling another fiduciary's data under instruction.
Who is liable if a processor mishandles data?
The fiduciary carries primary responsibility and stays accountable for the processor's compliance.
Consultant-led and partner-backed.