Data Fiduciary vs Data Processor — which one am I?
If you decide why and how personal data is used, you are a Data Fiduciary. If you only process it on someone else's instructions, you are a Data Processor. The same company can wear both hats for different data.
Short answer
The Data Fiduciary is the decision-maker. It decides the purpose and means of processing. The Data Processor is the doer. It processes personal data on the Fiduciary's instructions, under a valid contract. You cannot outsource accountability.
The detail
The DPDP Act draws a clear line based on control, not ownership or incorporation. Do you decide, alone or with others, why personal data is collected and how it is used? If so, you are a Data Fiduciary. That makes you accountable for compliance, even if another company does the actual processing.
A Data Processor, by contrast, does not decide purpose or means. It acts on the Fiduciary's written instructions. Examples include:
- A cloud host.
- A payroll provider.
- A customer-support platform.
- An analytics vendor.
The Act requires this relationship to run under a valid contract.
The same legal entity can be both. A SaaS startup is typically a Data Fiduciary for the personal data of its own end-users. That is because it decides what data to collect and why. But say that same startup also processes data for one of its enterprise customers under a strict service agreement. For that customer's data, it is a Data Processor.
This differs from a Significant Data Fiduciary. That is a special tier the Central Government can notify based on volume, sensitivity, or risk. It comes with extra duties, such as:
- A Data Protection Officer.
- Periodic audits.
- A DPIA.
But it is still a Data Fiduciary.
At a glance
| Question | Data Fiduciary | Data Processor |
|---|---|---|
| Decides purpose and means? | Yes | No |
| Accountable for compliance | Yes, always | No — but must follow the contract |
| Contract required | Must have one with any Processor | Works under the Fiduciary's contract |
| Typical example | A startup running its own app | The cloud host or email service it uses |
What this means for you
If your product decides what user data to collect and why, you are a Data Fiduciary. You remain responsible even when you use AWS, Stripe, or a third-party CRM. So put processor contracts in place. Keep an inventory of who processes what.
Building a product for a client? You are likely a Data Processor for that client's user data. Make sure your contract covers:
- Instructions.
- Security duties.
- What happens to data when the engagement ends.
Running your own newsletter, course, or community? You are the Data Fiduciary for your audience data. The email platform you use is your Processor. You are still the one the law holds accountable.
Status
Related pages
Am I a Data Fiduciary?
Run the 3-minute self-check to see which hat your product wears under the DPDP Act.
Run it nowPrimary sources
Gazette of India, Extraordinary, Part II, Section 1, 11 August 2023 (Act 22 of 2023). See Section 2 definitions and Section 8(1)–(2).
Status unverified — no status check recorded
G.S.R. 846(E), 13 November 2025. Operational rules on consent, breach response, and complaints.
Status unverified — no status check recorded
Official text — Sections 2(f), 2(i), 2(k) and 8(1)–(2), DPDP Act, 2023
Citation
Kokate, S. (2026). Data Fiduciary vs Data Processor — which one am I? India AI Rulebook. Retrieved from https://indiaairulebook.com/learn/data-privacy/data-fiduciary-vs-data-processor. Educational content, not legal advice.
The Rules are dated 13 November 2025 and were published in the Gazette on 14 November 2025. Some sources therefore give 14 May 2027. We use 13 May 2027; see Methodology.