DPDP Wiki Talk to us

/Guides · Businesses

Data Fiduciary obligations: a plain-English checklist

Every obligation section 8 places on a Data Fiduciary, with the rules on security, breach reporting, erasure, contacts and grievances.

Interpretation · not legal adviceUpdated 9 September 20268 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

A Data Fiduciary is any person who alone or with others determines the purpose and means of processing personal data (section 2(i)). Section 8 collects most of what such a person has to do, and five of the Rules put detail and numbers on it. This guide takes each sub-section in turn.

The checklist#

#ObligationWhere
1Stay responsible for compliance, whatever any agreement says and whatever the Data Principal doess. 8(1)
2Engage a Data Processor only under a valid contracts. 8(2)
3Ensure completeness, accuracy and consistency where the data drives a decision about the Data Principal or goes to another Data Fiduciarys. 8(3)
4Put appropriate technical and organisational measures in places. 8(4)
5Take reasonable security safeguards, meeting seven minimum requirementss. 8(5), r. 6
6Tell affected people and the Board about a breach, in the prescribed form and times. 8(6), r. 7
7Erase data, and make processors erase it, once consent is withdrawn or the purpose is overs. 8(7)
8Apply the prescribed inactivity periods, with 48 hours' warning before erasures. 8(8), r. 8, Third Schedule
9Publish business contact information for questions about processings. 8(9), r. 9
10Run an effective grievance redressal mechanism and publish its response periods. 8(10), r. 14(3)

Responsibility you cannot contract away#

The Data Fiduciary is responsible for complying with the Act and Rules for any processing it does or a Data Processor does on its behalf, "irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act" (section 8(1)).

Where a processor is used for anything related to offering goods or services, the arrangement must rest on "a valid contract" (section 8(2)). The Rules add one required term: appropriate provision for taking reasonable security safeguards (rule 6(1)). Otherwise the Rules do not prescribe the contract's contents.

Accuracy where it matters#

Where personal data is likely to be used for a decision affecting the Data Principal, or disclosed to another Data Fiduciary, its completeness, accuracy and consistency must be ensured (section 8(3)). Separately, appropriate technical and organisational measures must ensure effective observance of the Act and Rules (section 8(4)).

Reasonable security safeguards#

Personal data in the Data Fiduciary's possession or control, including data handled by a processor for it, must be protected "by taking reasonable security safeguards to prevent personal data breach" (section 8(5)). Rule 6 sets the minimum:

  • data security measures such as encryption, obfuscation, masking or virtual tokens mapped to the personal data;
  • measures to control access to the computer resources used, where applicable;
  • visibility on access through logs, monitoring and review, so unauthorised access can be detected, investigated and remedied;
  • reasonable measures for continued processing if confidentiality, integrity or availability is compromised, such as backups;
  • retention of those logs and personal data for one year, unless another law requires otherwise;
  • an appropriate clause in the processor contract for taking reasonable security safeguards; and
  • appropriate technical and organisational measures so the safeguards are actually observed.

Telling people about a breach#

A personal data breach is any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of personal data (section 2(u)). On a breach, both the Board and each affected Data Principal must be given intimation in the prescribed form and manner (section 8(6)). Rule 7 prescribes three separate duties, all triggered "on becoming aware".

To whomWhat must be saidBy when
Each affected Data Principal, through her user account or any mode of communication she registeredA description of the breach including its nature, extent and timing; the consequences likely to arise for her; the mitigation measures implemented and being implemented, if any; the safety measures she may take; and business contact information of a person who can respond to her queries"Without delay", to the best of the Data Fiduciary's knowledge, and in a "concise, clear and plain manner"
The Board, first intimationA description of the breach including its nature, extent, timing and location of occurrence, and the likely impact"Without delay"
The Board, follow-upUpdated and detailed information on that description; the broad facts of the events, circumstances and reasons leading to the breach; measures implemented or proposed to mitigate risk; any findings on who caused it; remedial measures to prevent recurrence; and a report on the intimations given to affected Data Principals"Within seventy-two hours of becoming aware of the breach", or a longer period the Board allows on a written request

Erasure and retention#

Unless retention is necessary for compliance with a law in force, personal data must be erased when the Data Principal withdraws consent or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, and the processor must be made to erase what it was given (section 8(7)). The Act's illustration draws the line: a marketplace that has helped sell a used car keeps nothing, while a bank required by law to keep client identity records for ten years after account closure keeps them.

The purpose is deemed no longer served if the Data Principal neither approaches the Data Fiduciary for its performance nor exercises her rights for a prescribed period (section 8(8)); she counts as not having approached during any period in which she has not initiated contact, in person or electronically or on paper (section 8(11)). Rule 8 prescribes those periods only for the three classes in the Third Schedule.

Class of Data FiduciaryPurposesTime period
E-commerce entity with not less than two crore registered users in IndiaAll purposes, except enabling her to access her user account, and enabling her to access a virtual token issued by or for the Data Fiduciary, stored on its platform and usable to get money, goods or servicesThree years from the date she last approached the Data Fiduciary for performance of the specified purpose or exercise of her rights, or the commencement of the DPDP Rules, 2025, whichever is latest
Online gaming intermediary with not less than fifty lakh registered users in IndiaAs aboveAs above
Social media intermediary with not less than two crore registered users in IndiaAs aboveAs above

At least forty-eight hours before that period runs out, she must be told the data will be erased unless she logs in, otherwise makes contact for the specified purpose, or exercises her rights (rule 8(2)).

Pulling the other way, rule 8(3) requires every Data Fiduciary to keep personal data, associated traffic data and other processing logs for at least one year from the date of processing, for the purposes in the Seventh Schedule, then erase them unless another law or a Government notification requires longer. In the Rules' illustration an e-book platform keeps order, payment and delivery records for a year even if the customer deletes her account, and a company using a cloud provider must make that provider do the same.

A published contact, and a grievance mechanism#

The business contact information of a Data Protection Officer, if applicable, or of a person able to answer questions about processing, must be published in the prescribed manner (section 8(9)). Rule 9 requires it to be published prominently on the website or app and repeated in every response to a communication exercising a Data Principal's rights.

An effective grievance redressal mechanism must also be established (section 8(10)). No rule is made under that sub-section. The nearest requirement sits in the rule on rights: every Data Fiduciary and Consent Manager must prominently publish on its website or app "within a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals", and implement appropriate measures to meet that period (rule 14(3)). The sentence is printed that way in the Gazette and reads as though a word is missing, but the ninety-day outer limit is clear.

What it costs to get wrong#

BreachMaximum penalty
Failure to take reasonable security safeguards under section 8(5)Two hundred and fifty crore rupees
Failure to give the Board or an affected Data Principal notice of a breach under section 8(6)Two hundred crore rupees
Breach of any other provision of the Act or RulesFifty crore rupees

Those maximums are set by the Schedule. The Board imposes a penalty only if it determines on conclusion of an inquiry that the breach is significant, after a hearing (section 33(1)).

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.