Data Fiduciary: the one who decides
A Data Fiduciary is any person who, alone or with others, decides the purpose and means of processing personal data. 'Person' is wide: an individual, a Hindu undivided family, a company, a firm, an association, the State and other artificial juristic persons. Most duties in the Act fall on the Fiduciary.
Sources: Act s.2(i)Act s.2(s)
Data Principal: the person the data is about
The Data Principal is the individual the personal data relates to. For a child, meaning anyone under 18, the term includes the parents or lawful guardian. For a person with disability, it includes her lawful guardian acting on her behalf. The Act uses 'she' for every individual, whatever their gender.
Sources: Act s.2(j)Act s.2(f)Act s.2(y)
Data Processor: the one who acts for you
A Data Processor processes personal data on behalf of a Data Fiduciary, such as a cloud host, payroll firm or call centre. A Fiduciary may use one only under a valid contract, and it stays responsible for what the Processor does, whatever the contract says.
Sources: Act s.2(k)Act s.8(1)Act s.8(2)
Consent Manager: a registered go-between
A Consent Manager is registered with the Board. It is a single point of contact through which a person can give, manage, review and withdraw consent on an accessible, transparent and interoperable platform. It is accountable to the Data Principal and acts on her behalf.
Sources: Act s.2(g)Act s.6(8)
The Board, SDFs and DPOs
The Data Protection Board of India inquires into breaches and imposes penalties (lesson 11). The Government can notify some Fiduciaries as Significant Data Fiduciaries, with extra duties. A Data Protection Officer is the individual a Significant Data Fiduciary appoints under section 10(2)(a).
Sources: Act s.2(c)Act s.2(z)Act s.2(l)Act s.27(1)
Key points
- The Data Fiduciary decides why and how data is processed.
- The Data Principal is the person; for a child, parents too.
- Processors act under a valid contract; the Fiduciary stays responsible.
- Consent Managers are registered with the Board and accountable to people.
- Significant Data Fiduciaries are named by Government notification.
In practice
A checklist for your organisation.
- For each system, record whether you act as Fiduciary or Processor.
- Sign a written contract with every vendor that processes personal data.
- Identify customer groups that include children or lawful guardians.
- Name one person to answer questions about your processing.
Check what you learned
5 questions. Choose an answer to see why it is right.
0 of 5 answered
Question 1 of 5
A cloud provider stores customer data only on a bank's instructions. What is the cloud provider?
Show the answer
C. Data Processor
Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary.
Act s.2(k)Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary.
Act s.2(k)Question 2 of 5
Who counts as a child under the Act?
Show the answer
C. Anyone under 18
Section 2(f) defines a child as an individual who has not completed the age of eighteen years.
Act s.2(f)Section 2(f) defines a child as an individual who has not completed the age of eighteen years.
Act s.2(f)Question 3 of 5
A bank's contract says its payroll vendor alone is responsible for data protection. Who is responsible under the Act?
Show the answer
B. The bank, irrespective of the contract
Section 8(1) makes the Data Fiduciary responsible, irrespective of any agreement to the contrary, including for processing by its Data Processor.
Act s.8(1)Section 8(1) makes the Data Fiduciary responsible, irrespective of any agreement to the contrary, including for processing by its Data Processor.
Act s.8(1)Question 4 of 5
What must a Consent Manager be?
Show the answer
D. Registered with the Data Protection Board
Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact for consent.
Act s.2(g)Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact for consent.
Act s.2(g)Question 5 of 5
Under the Act's definition, who appoints a Data Protection Officer?
Show the answer
D. A Significant Data Fiduciary
Section 2(l) defines a DPO as an individual appointed by the Significant Data Fiduciary under section 10(2)(a).
Act s.2(l)Section 2(l) defines a DPO as an individual appointed by the Significant Data Fiduciary under section 10(2)(a).
Act s.2(l)
Official sources for this lesson
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, Extraordinary, Part II, Section 1, 11 August 2023
- G.S.R. 843(E), 13 November 2025: dates on which provisions of the DPDP Act come into force
A plain-English summary of the DPDP Act 2023 and DPDP Rules 2025, checked on 28 September 2026. It is not legal advice. Words in this lesson are explained in the DPDP dictionary.