Every business handling personal data in India eventually runs into these two terms, and confusing them is one of the most common mistakes we see in compliance documents. The Digital Personal Data Protection Act, 2023 (DPDP Act) treats a Data Fiduciary and a Data Processor very differently, and getting the classification wrong can leave your business exposed to obligations it never planned for, or worse, unaware of obligations it actually has.
What Is a Data Fiduciary
A Data Fiduciary is any person, company, or government entity that determines the purpose and means of processing personal data. In plain terms, if your organisation decides why data is being collected and how it will be used, you are the Data Fiduciary. An e-commerce platform collecting customer addresses for delivery, a hospital maintaining patient records, or a fintech app onboarding users through KYC are all Data Fiduciaries because they control the purpose of processing.
The DPDP Act places the primary compliance burden on the Data Fiduciary. This includes obtaining valid consent, maintaining reasonable security safeguards, notifying the Data Protection Board and affected individuals in case of a breach, and honouring data principal rights such as access and erasure requests. See our plain-language guide to the DPDP Act for the underlying framework.
What Is a Data Processor
A Data Processor is any person or entity that processes personal data on behalf of a Data Fiduciary, under a contract. A cloud hosting company storing customer data for an app, a payroll vendor processing employee salaries for a company, or a call centre handling customer queries for a bank are typically acting as Data Processors. They do not decide why the data is being processed, they only execute the processing as instructed.
The key distinction lies in liability. A Data Processor is generally liable to the extent of its contractual obligations with the Data Fiduciary, not directly to the Data Protection Board in most circumstances. The primary regulatory responsibility and penalty exposure sits with the Data Fiduciary, which is why fiduciaries are expected to enter into strict data processing agreements with every vendor that touches personal data on their behalf.
Why Many Businesses Are Actually Both
A single company can wear both hats depending on the relationship. A SaaS company that collects data directly from its own users is a Data Fiduciary for that data. If the same company also processes data for a client under a service agreement, such as a marketing automation tool acting on a retailer's customer list, it is a Data Processor for that specific engagement. We advise clients to map every data flow separately rather than assuming one label applies across the entire business.
Significant Data Fiduciary: A Higher Bar
The DPDP Act also creates a category called Significant Data Fiduciary (SDF), notified by the government based on factors like volume and sensitivity of data processed, risk to electoral democracy, security of the state, and public order. SDFs face additional obligations, including appointing a Data Protection Officer based in India and conducting periodic Data Protection Impact Assessments and audits.
Timeline: What Is Actually in Force Right Now
The Data Protection Board of India became operational when the DPDP Rules 2025 were notified in November 2025, which set the enforcement machinery in motion. However, the substantive compliance obligations for businesses, including detailed consent requirements, breach reporting timelines, and data principal rights mechanisms, are being phased in and businesses should track the government's official notifications for exact commencement dates rather than assuming everything is already enforceable. Waiting until the deadline is close is a mistake we see often, since building consent flows, vendor contracts, and breach response processes properly takes real time. For the financial exposure involved, see our breakdown of DPDP Act penalties.
What This Means for Your Contracts
If you are a Data Fiduciary engaging vendors, your contracts need clear data processing clauses defining scope, security obligations, sub-processing restrictions, and breach notification timelines from the processor back to you. If you are a Data Processor, you need to ensure you are not silently taking on fiduciary-level obligations through vague contractual language. Our Data Fiduciary obligations guide covers what your compliance checklist should include.
Clawrity's DPDP Act Compliance Audit typically takes 10 to 14 working days, covering data flow mapping, contract review, and a gap analysis against the Act. If your business is unsure which role it plays in a given data flow, or you need vendor agreements reviewed before the compliance deadlines tighten, get in touch with our team.