Data Fiduciary obligations — your core duties under the DPDP Act
Section 8 of the DPDP Act sets out the duties a Data Fiduciary cannot contract away: accountability, accuracy, security, breach intimation, erasure, and grievance redressal. Rules 6 and 9 add the security specifics and the contact point.
In plain English
A Data Fiduciary is the organisation that decides why and how personal data gets used. A Data Processor is a company it hires to do the actual work with that data.
You stay responsible even when your processor does the work. And you can only use a processor if you have a valid contract with them.
It must also:
- keep data accurate when it is used for decisions or shared with others
- put reasonable technical and organisational security measures in place
- notify the Board and the affected people of a breach
- erase data once the purpose is over or consent is withdrawn, unless another law requires it to be kept
Rule 6 turns the security duty into a checklist: encryption, access controls, logs, monitoring, backups, keeping logs for a year, and security terms in your processor contracts.
Rule 9 covers who people contact. You must name a business contact point — a Data Protection Officer if you need one, or another responsible person. Publish that contact clearly, and include it in every reply you send to someone exercising their rights.
Think of it like
If you hire a courier to deliver confidential documents, you are still accountable to the sender for safe delivery. You must:
- pick a trustworthy courier
- seal the documents in an envelope
- keep a delivery log
- tell the sender if the package is lost
- destroy your copies once delivery is complete, unless tax law says to keep a record
Key takeaways
- You cannot hand off responsibility. You answer for your processor's work.
- You need a written contract with every processor you use.
- Data you use to make decisions about someone, or share with another organisation, must be complete, accurate and consistent.
- Rule 6 sets the security checklist: encryption or something equivalent, access controls, logs, monitoring and backups. Keep logs for a year. Put security terms in your processor contracts.
- After a breach, you must tell the Board and every affected person, in the form the rules set out.
- Erase data when someone withdraws consent, or when you no longer need it — unless another law says to keep it.
- You must publish a contact point, and it must work. People need a real way to complain.
What this means for you
You are answerable even when a vendor handles the data. Before May 2027, check your processor contracts, your encryption, your access controls and your breach plan.
If you handle personal data for a client, your contract should say plainly who the Data Fiduciary is and what security you have to provide.
Email lists, membership platforms, and audience analytics must be kept accurate and secure. Publish a clear contact point for data questions and deletion requests.
Status
Primary sources
Official text
Official text — Section 8, DPDP Act, 2023
Official text — Rule 6, DPDP Rules, 2025
Official text — Rule 9, DPDP Rules, 2025
Am I a Data Fiduciary?
Run the 3-minute self-check to see whether your product triggers these duties.
Run it nowCitation
Kokate, S. (2026). Data Fiduciary obligations — your core duties under the DPDP Act. India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/data-fiduciary-obligations. Educational content, not legal advice.
The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.