Lesson 2 of 12 · 4 min read

Who is who in the law

The roles the law is built around: Data Fiduciary, Data Principal, Data Processor, Consent Manager and the Data Protection Board.

Data Fiduciary: the one who decides

A Data Fiduciary is any person who, alone or with others, decides the purpose and means of processing personal data. 'Person' is wide: an individual, a Hindu undivided family, a company, a firm, an association, the State and other artificial juristic persons. Most duties in the Act fall on the Fiduciary.

Sources: Act s.2(i)Act s.2(s)

Data Principal: the person the data is about

The Data Principal is the individual the personal data relates to. For a child, meaning anyone under 18, the term includes the parents or lawful guardian. For a person with disability, it includes her lawful guardian acting on her behalf. The Act uses 'she' for every individual, whatever their gender.

Sources: Act s.2(j)Act s.2(f)Act s.2(y)

Data Processor: the one who acts for you

A Data Processor processes personal data on behalf of a Data Fiduciary, such as a cloud host, payroll firm or call centre. A Fiduciary may use one only under a valid contract, and it stays responsible for what the Processor does, whatever the contract says.

Sources: Act s.2(k)Act s.8(1)Act s.8(2)

Consent Manager: a registered go-between

A Consent Manager is registered with the Board. It is a single point of contact through which a person can give, manage, review and withdraw consent on an accessible, transparent and interoperable platform. It is accountable to the Data Principal and acts on her behalf.

Sources: Act s.2(g)Act s.6(8)

The Board, SDFs and DPOs

The Data Protection Board of India inquires into breaches and imposes penalties (lesson 11). The Government can notify some Fiduciaries as Significant Data Fiduciaries, with extra duties. A Data Protection Officer is the individual a Significant Data Fiduciary appoints under section 10(2)(a).

Sources: Act s.2(c)Act s.2(z)Act s.2(l)Act s.27(1)

Key points

  • The Data Fiduciary decides why and how data is processed.
  • The Data Principal is the person; for a child, parents too.
  • Processors act under a valid contract; the Fiduciary stays responsible.
  • Consent Managers are registered with the Board and accountable to people.
  • Significant Data Fiduciaries are named by Government notification.

In practice

A checklist for your organisation.

  • For each system, record whether you act as Fiduciary or Processor.
  • Sign a written contract with every vendor that processes personal data.
  • Identify customer groups that include children or lawful guardians.
  • Name one person to answer questions about your processing.

Check what you learned

5 questions. Choose an answer to see why it is right.

0 of 5 answered

  1. Question 1 of 5

    A cloud provider stores customer data only on a bank's instructions. What is the cloud provider?

    Show the answer

    C. Data Processor

    Section 2(k) defines a Data Processor as any person who processes personal data on behalf of a Data Fiduciary.

    Act s.2(k)
  2. Question 2 of 5

    Who counts as a child under the Act?

    Show the answer

    C. Anyone under 18

    Section 2(f) defines a child as an individual who has not completed the age of eighteen years.

    Act s.2(f)
  3. Question 3 of 5

    A bank's contract says its payroll vendor alone is responsible for data protection. Who is responsible under the Act?

    Show the answer

    B. The bank, irrespective of the contract

    Section 8(1) makes the Data Fiduciary responsible, irrespective of any agreement to the contrary, including for processing by its Data Processor.

    Act s.8(1)
  4. Question 4 of 5

    What must a Consent Manager be?

    Show the answer

    D. Registered with the Data Protection Board

    Section 2(g) defines a Consent Manager as a person registered with the Board who acts as a single point of contact for consent.

    Act s.2(g)
  5. Question 5 of 5

    Under the Act's definition, who appoints a Data Protection Officer?

    Show the answer

    D. A Significant Data Fiduciary

    Section 2(l) defines a DPO as an individual appointed by the Significant Data Fiduciary under section 10(2)(a).

    Act s.2(l)

Official sources for this lesson

A plain-English summary of the DPDP Act 2023 and DPDP Rules 2025, checked on 28 September 2026. It is not legal advice. Words in this lesson are explained in the DPDP dictionary.