Data Fiduciary Obligations and Accountability
Reading module · approx 14 min
The Data Fiduciary sits at the centre of the DPDP Act's compliance architecture. All primary obligations under the Act flow to the Data Fiduciary. Understanding these obligations precisely — what they require, when they apply, and how they interact — is the foundation of any DPDP compliance programme.
Core obligations of Data Fiduciaries
A Data Fiduciary must: collect only personal data that is necessary for the specified purpose (data minimisation); use personal data only for the purpose for which it was collected or for a compatible legitimate purpose; take reasonable security safeguards to prevent personal data breaches; inform Data Principals of any personal data breach that is likely to cause harm; and establish mechanisms for Data Principals to exercise their rights.
The Act also imposes an accuracy obligation: the Data Fiduciary must take reasonable steps to ensure that personal data it processes is accurate, complete, and consistent with the purpose. This obligation is particularly relevant for businesses that make automated decisions or recommendations based on personal data.
Storage limitation
Personal data may not be retained beyond the period necessary for the purpose for which it was collected unless retention is required for compliance with an applicable law. In practice, this means Data Fiduciaries must implement data retention policies that map retention periods to stated purposes and ensure deletion or anonymisation at the end of the retention period.
Rights of Data Principals
Data Principals have the following rights under the DPDP Act:
- Right to information: the right to obtain a summary of the personal data processed and the processing activities undertaken
- Right to correction and erasure: the right to have inaccurate or incomplete data corrected, and the right to have data erased where the purpose has been fulfilled or consent has been withdrawn
- Right to grievance redressal: the right to raise a grievance with the Data Fiduciary and receive a response
- Right to nominate: the right to nominate another individual to exercise data rights in the event of the Data Principal's death or incapacity
Data Protection Officer
Significant Data Fiduciaries (a category to be designated by the government by notification) are required to appoint a Data Protection Officer (DPO). The DPO must be a person based in India and is the primary point of contact for the Data Protection Board of India and for Data Principals exercising their rights.
Obligations of Data Processors
Data Processors — entities processing data on behalf of a Data Fiduciary — must process data only under a valid Data Processing Agreement with the Data Fiduciary, following the Fiduciary's instructions, and taking security safeguards consistent with the Act. Data Processors have limited direct obligations to Data Principals but must assist the Data Fiduciary in responding to Data Principal rights requests and in notifying breaches.
Module 3 covers consent — the primary legal basis for processing under the DPDP Act, and the most operationally complex obligation to implement correctly.