DPDP Rules status: compliance window active. Read the update

Skip to content
Data Privacy · DPDP Act 2023

Data Fiduciary obligations — your core duties under the DPDP Act

Section 8 of the DPDP Act sets out the duties a Data Fiduciary cannot contract away: accountability, accuracy, security, breach intimation, erasure, and grievance redressal. Rules 6 and 9 add the security specifics and the contact point.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

In plain English

A Data Fiduciary is the organisation that decides why and how personal data gets used. A Data Processor is a company it hires to do the actual work with that data.

You stay responsible even when your processor does the work. And you can only use a processor if you have a valid contract with them.

It must also:

  • keep data accurate when it is used for decisions or shared with others
  • put reasonable technical and organisational security measures in place
  • notify the Board and the affected people of a breach
  • erase data once the purpose is over or consent is withdrawn, unless another law requires it to be kept

Rule 6 turns the security duty into a checklist: encryption, access controls, logs, monitoring, backups, keeping logs for a year, and security terms in your processor contracts.

Rule 9 covers who people contact. You must name a business contact point — a Data Protection Officer if you need one, or another responsible person. Publish that contact clearly, and include it in every reply you send to someone exercising their rights.

Think of it like

If you hire a courier to deliver confidential documents, you are still accountable to the sender for safe delivery. You must:

  • pick a trustworthy courier
  • seal the documents in an envelope
  • keep a delivery log
  • tell the sender if the package is lost
  • destroy your copies once delivery is complete, unless tax law says to keep a record

Key takeaways

  • You cannot hand off responsibility. You answer for your processor's work.
  • You need a written contract with every processor you use.
  • Data you use to make decisions about someone, or share with another organisation, must be complete, accurate and consistent.
  • Rule 6 sets the security checklist: encryption or something equivalent, access controls, logs, monitoring and backups. Keep logs for a year. Put security terms in your processor contracts.
  • After a breach, you must tell the Board and every affected person, in the form the rules set out.
  • Erase data when someone withdraws consent, or when you no longer need it — unless another law says to keep it.
  • You must publish a contact point, and it must work. People need a real way to complain.

What this means for you

Founders

You are answerable even when a vendor handles the data. Before May 2027, check your processor contracts, your encryption, your access controls and your breach plan.

Freelancers

If you handle personal data for a client, your contract should say plainly who the Data Fiduciary is and what security you have to provide.

Creators

Email lists, membership platforms, and audience analytics must be kept accurate and secure. Publish a clear contact point for data questions and deletion requests.

Status

EnforceableCore obligations enforceable 13 May 2027. The Act has been on the statute book since 13 November 2025. The Data Protection Board is not yet hearing complaints.

Primary sources

Official text

Official text — Section 8, DPDP Act, 2023
SECTION 8 — General obligations of Data Fiduciary (DPDP Act, 2023) 8. (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. (2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract. (3) Where personal data processed by a Data Fiduciary is likely to be— (a) used to make a decision that affects the Data Principal; or (b) disclosed to another Data Fiduciary, the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency. (4) A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder. (5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. Illustrations. (I) X, an individual, registers herself on an online marketplace operated by Y, an e-commerce service provider. X gives her consent to Y for the processing of her personal data for selling her used car. The online marketplace helps conclude the sale. Y shall no longer retain her personal data. (II) X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X's personal data for the said period. (8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not–– (a) approach the Data Fiduciary for the performance of the specified purpose; and (b) exercise any of her rights in relation to such processing, for such time period as may be prescribed, and different time periods may be prescribed for different classes of Data Fiduciaries and for different purposes. (9) A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data. (10) A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals. (11) For the purposes of this section, it is hereby clarified that a Data Principal shall be considered as not having approached the Data Fiduciary for the performance of the specified purpose, in any period during which she has not initiated contact with the Data Fiduciary for such performance, in person or by way of communication in electronic or physical form.
Official text — Rule 6, DPDP Rules, 2025
RULE 6 — Reasonable security safeguards (DPDP Rules, 2025) 6. (1) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach, which shall include, at the minimum, — (a) appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data; (b) appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable; (c) visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence; (d) reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups; (e) for enabling the detection of unauthorised access, its investigation, remediation to prevent recurrence and continued processing in the event of such a compromise, retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise; (f) appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards; and (g) appropriate technical and organisational measures to ensure effective observance of security safeguards. (2) In this rule, the expression "computer resource" shall have the same meaning as is assigned to it in Information Technology Act, 2000 (21 of 2000).
Official text — Rule 9, DPDP Rules, 2025
RULE 9 — Contact information of person to answer questions about processing (DPDP Rules, 2025) 9. Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data.
Quick self-check

Am I a Data Fiduciary?

Run the 3-minute self-check to see whether your product triggers these duties.

Run it now

Citation

Kokate, S. (2026). Data Fiduciary obligations — your core duties under the DPDP Act. India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/data-fiduciary-obligations. Educational content, not legal advice.

The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.