---
title: "Section 8: General obligations of Data Fiduciary"
url: https://dpdp.myndsolution.com/wiki/act/section-8-general-obligations-of-data-fiduciary/
description: "Section 8 of the Digital Personal Data Protection Act, 2023 (General obligations of Data Fiduciary). Official text verbatim, comes into force on 13 may…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-8-general-obligations-of-data-fiduciary/
---
# Section 8: General obligations of Data Fiduciary

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter II: OBLIGATIONS OF DATA FIDUCIARY. Comes into force on 13 May 2027.*

## Official text

- **(1)** A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.

- **(2)** A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.

- **(3)** Where personal data processed by a Data Fiduciary is likely to be—
  - **(a)** used to make a decision that affects the Data Principal; or
  - **(b)** disclosed to another Data Fiduciary, the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency.

- **(4)** A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder.

- **(5)** A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.

- **(6)** In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.

- **(7)** A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,—
  - **(a)** erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and
  - **(b)** cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor.

> **Illustrations.** (I) X, an individual, registers herself on an online marketplace operated by Y, an e-commerce service provider. X gives her consent to Y for the processing of her personal data for selling her used car. The online marketplace helps conclude the sale. Y shall no longer retain her personal data.

> **Illustrations.** (II) X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X’s personal data for the said period.

- **(8)** The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not––
  - **(a)** approach the Data Fiduciary for the performance of the specified purpose; and
  - **(b)** exercise any of her rights in relation to such processing,
  for such time period as may be prescribed, and different time periods may be prescribed for different classes of Data Fiduciaries and for different purposes.

- **(9)** A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data.

- **(10)** A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.

- **(11)** For the purposes of this section, it is hereby clarified that a Data Principal shall be considered as not having approached the Data Fiduciary for the performance of the specified purpose, in any period during which she has not initiated contact with the Data Fiduciary for such performance, in person or by way of communication in electronic or physical form.


## Rules made under this section

- [Rule 6: Reasonable security safeguards](https://dpdp.myndsolution.com/wiki/rules/rule-6-reasonable-security-safeguards/)
- [Rule 7: Intimation of personal data breach](https://dpdp.myndsolution.com/wiki/rules/rule-7-intimation-of-personal-data-breach/)
- [Rule 8: Time period for specified purpose to be deemed as no longer being served](https://dpdp.myndsolution.com/wiki/rules/rule-8-time-period-for-specified-purpose-to-be-deemed-as-no-longer/)
- [Rule 9: Contact information of person to answer questions about processing](https://dpdp.myndsolution.com/wiki/rules/rule-9-contact-information-of-person-to-answer-questions-about/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

Section 8 sets out the main rules for a Data Fiduciary, which is the person or entity deciding how and why personal data is processed. The Data Fiduciary is always responsible for following the law, even if they use a Data Processor (someone who processes data on their behalf) or if the Data Principal (the individual the data is about) fails to do their duties. If a Data Fiduciary uses a Data Processor to offer goods or services, they must have a valid contract in place. The Data Fiduciary must keep personal data complete, accurate, and consistent if it will be used to make a decision about the Data Principal or shared with another Data Fiduciary. They must also set up technical and organizational measures to follow the law and use reasonable security safeguards to prevent a personal data breach. If a breach happens, the Data Fiduciary must notify both the Board and every affected Data Principal in a manner that will be prescribed by rules. Data must be erased when the Data Principal withdraws their consent or when the original purpose for collecting it is no longer being served, whichever happens first. The Data Fiduciary must also ensure their Data Processors erase this data. However, data can be kept if another law requires it. The law considers a purpose no longer served if the Data Principal does not contact the Data Fiduciary or exercise their rights for a specific time period, which will be prescribed by rules. Finally, the Data Fiduciary must publish contact information for someone who can answer questions and set up a mechanism to handle grievances.

### Key points

- The Data Fiduciary is responsible for compliance for all processing done by it or its Data Processors. (1)
- A valid contract is required to use a Data Processor for activities related to offering goods or services. (2)
- The Data Fiduciary must ensure data is complete, accurate, and consistent if used for decisions or shared with another Data Fiduciary. (3)
- In the event of a personal data breach, the Data Fiduciary must notify the Board and each affected Data Principal. (6)
- Personal data must be erased when consent is withdrawn or the purpose is no longer served, unless another law requires retention. (7)
- The Data Fiduciary must publish contact information for a person to answer questions and establish a grievance redressal mechanism. (9, 10)

### Common misreadings

- A Data Fiduciary cannot avoid responsibility by blaming a Data Processor or by signing an agreement that shifts the blame.
- A Data Fiduciary does not have to erase data if another active law requires them to keep it, even if the Data Principal withdraws consent.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 8. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
