DPDP Wiki Talk to us

/Glossary · Defined term

Data Fiduciary

Defined in section 2(i) of the Act.

Official definition

Official definition

Verbatim

Act, section 2(i)

(i) “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data;

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Data Fiduciary

The Digital Personal Data Protection Act, 2023 defines a "Data Fiduciary" as any person who decides why and how personal data is processed. If an individual, company, or other entity determines the purpose (the reason for processing) and the means (the methods used for processing) of handling personal data, the law classifies them as a Data Fiduciary.

The definition specifically notes that a person can make these decisions "alone or in conjunction with other persons." This means an entity does not have to be the sole decision-maker to be considered a Data Fiduciary. If multiple entities work together to decide the purpose and means of processing personal data, they all fit the definition and carry the responsibilities attached to this role under the Act.

Key points

  • A Data Fiduciary is any person who determines the purpose and means of processing personal data (2(i)).
  • A person can act as a Data Fiduciary entirely on their own (2(i)).
  • A person can also be a Data Fiduciary when acting together with other persons to make data processing decisions (2(i)).

Common misreadings

  • A person might assume they are only a Data Fiduciary if they make data decisions entirely on their own, but the text explicitly includes those who make decisions in conjunction with others.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.