Home Courses DPDP Act 2023 Compliance Module 2
Module 2 of 6 — DPDP Act 2023 Compliance

Data Fiduciary Obligations and Accountability

Reading module · approx 14 min

The Data Fiduciary sits at the centre of the DPDP Act's compliance architecture. All primary obligations under the Act flow to the Data Fiduciary. Understanding these obligations precisely — what they require, when they apply, and how they interact — is the foundation of any DPDP compliance programme.

Core obligations of Data Fiduciaries

A Data Fiduciary must: collect only personal data that is necessary for the specified purpose (data minimisation); use personal data only for the purpose for which it was collected or for a compatible legitimate purpose; take reasonable security safeguards to prevent personal data breaches; inform Data Principals of any personal data breach that is likely to cause harm; and establish mechanisms for Data Principals to exercise their rights.

The Act also imposes an accuracy obligation: the Data Fiduciary must take reasonable steps to ensure that personal data it processes is accurate, complete, and consistent with the purpose. This obligation is particularly relevant for businesses that make automated decisions or recommendations based on personal data.

Storage limitation

Personal data may not be retained beyond the period necessary for the purpose for which it was collected unless retention is required for compliance with an applicable law. In practice, this means Data Fiduciaries must implement data retention policies that map retention periods to stated purposes and ensure deletion or anonymisation at the end of the retention period.

Rights of Data Principals

Data Principals have the following rights under the DPDP Act:

Data Protection Officer

Significant Data Fiduciaries (a category to be designated by the government by notification) are required to appoint a Data Protection Officer (DPO). The DPO must be a person based in India and is the primary point of contact for the Data Protection Board of India and for Data Principals exercising their rights.

Significant Data Fiduciaries The government may designate certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of personal data processed, the risk to Data Principals, national security, and the impact on sovereignty and integrity of India. Significant Data Fiduciaries face additional obligations: mandatory DPO appointment, periodic Data Protection Impact Assessments, and compliance audits. The criteria and the initial list of Significant Data Fiduciaries will be specified by notification.

Obligations of Data Processors

Data Processors — entities processing data on behalf of a Data Fiduciary — must process data only under a valid Data Processing Agreement with the Data Fiduciary, following the Fiduciary's instructions, and taking security safeguards consistent with the Act. Data Processors have limited direct obligations to Data Principals but must assist the Data Fiduciary in responding to Data Principal rights requests and in notifying breaches.

Module 3 covers consent — the primary legal basis for processing under the DPDP Act, and the most operationally complex obligation to implement correctly.