/Glossary · Defined term
Data Fiduciary
Defined in section 2(i) of the Act.
Act, section 2(i)
(i) “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data;
The Digital Personal Data Protection Act, 2023 defines a "Data Fiduciary" as any person who decides why and how personal data is processed. If an individual, company, or other entity determines the purpose (the reason for processing) and the means (the methods used for processing) of handling personal data, the law classifies them as a Data Fiduciary.
The definition specifically notes that a person can make these decisions "alone or in conjunction with other persons." This means an entity does not have to be the sole decision-maker to be considered a Data Fiduciary. If multiple entities work together to decide the purpose and means of processing personal data, they all fit the definition and carry the responsibilities attached to this role under the Act.
Key points
- A Data Fiduciary is any person who determines the purpose and means of processing personal data (2(i)).
- A person can act as a Data Fiduciary entirely on their own (2(i)).
- A person can also be a Data Fiduciary when acting together with other persons to make data processing decisions (2(i)).
Common misreadings
- A person might assume they are only a Data Fiduciary if they make data decisions entirely on their own, but the text explicitly includes those who make decisions in conjunction with others.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.