A leading recruitment firm operating across India held an ISO 27001 certificate and believed its security program already covered the new privacy law. The assessment showed otherwise.
The firm had no central inventory of candidate and employee data, no way to capture explicit consent and no workflow to answer a request for access, correction or erasure. Its public cloud setup also lacked the monitoring that an accountable organization needs. The root cause sat in one legal term that the leadership team had never applied to itself, which is Data Fiduciary.
Under India’s DPDP Act, any organization that decides why and how personal data is processed holds that role, and the role carries the liability. This guide explains what a Data Fiduciary is, who qualifies, what the law requires and how to prepare.
What Is A Data Fiduciary Under The DPDP Act?
A Data Fiduciary is any person who, alone or with others, decides the purpose and means of processing personal data. Section 2(i) of the Digital Personal Data Protection Act, 2023 sets this definition, and the official text of the Act uses the word person broadly. A company, a partnership, a trust, an individual and a government body can all qualify. The role depends on who makes the decisions about data, and company size or sector does not change it. The word fiduciary reflects the idea that an organization holds personal data in trust for the individual it relates to.
Who Qualifies As A Data Fiduciary In Practice?
Any organization that collects personal data and chooses how to use it qualifies. A bank that opens accounts, a hospital that stores patient records, an e-commerce platform that tracks orders and a recruitment firm that holds resumes all act as Data Fiduciaries. Two organizations can share the role when they jointly decide the purpose and means, because the definition covers decisions made in conjunction with others. The Act applies to digital personal data processed in India, and it also reaches processing outside India when the organization offers goods or services to individuals in India.
What Is The Difference Between A Data Fiduciary And A Data Processor?
A Data Fiduciary decides why and how personal data is processed, while a Data Processor handles the data on the Fiduciary’s behalf. A payroll vendor that processes employee data under instructions is a Data Processor. The Data Fiduciary stays responsible for compliance even when a processor performs the work, so a vendor breach becomes the Fiduciary’s legal problem. The Act also requires a valid contract with each processor. The individual the data relates to is the Data Principal, which includes a parent or lawful guardian for a child or a person with a disability.
What Are The Obligations Of A Data Fiduciary?
The Act and the DPDP Rules, 2025 set several core duties:
- Notice and consent: give an itemized, plain-language notice and obtain free, specific and informed consent, with withdrawal as easy as giving it.
- Purpose and accuracy: process data only for a lawful purpose and keep it accurate when it drives decisions about a person.
- Security safeguards: apply controls such as encryption, access restrictions, logging, monitoring and resilient backups.
- Breach notification: inform each affected Data Principal and the Data Protection Board, with a detailed report to the Board within 72 hours.
- Retention and erasure: erase personal data once the purpose is served or consent is withdrawn, unless a law requires retention.
- Rights and grievances: act on access, correction and erasure requests and resolve grievances within 90 days.
- Children’s data: obtain verifiable parental consent for anyone under 18 and avoid tracking or targeted advertising aimed at children.
What Is A Significant Data Fiduciary?
A Significant Data Fiduciary is a Data Fiduciary, or a class of them, that the Central Government notifies after weighing the volume and sensitivity of the data, the risk to individuals and wider factors such as the security of the State. These organizations carry extra duties. They must appoint a Data Protection Officer based in India, appoint an independent data auditor and run periodic Data Protection Impact Assessments. Ampcus Cyber offers DPO as a Service, and its guide to the Data Privacy Impact Assessment explains when the assessment applies. Because the government decides the designation, check the latest notifications instead of assuming a threshold.
Why Does The Data Fiduciary Role Matter For Business Risk?
The role matters because the penalties are large and the accountability sits with the organization. The Act sets fines of up to Rs. 250 crore for failing to maintain reasonable security safeguards and up to Rs. 200 crore for failing to report a breach or meet children’s data duties. A Significant Data Fiduciary that misses its additional duties can face up to Rs. 150 crore. The commercial damage often exceeds the fine, because lost customer trust, stalled enterprise deals and cyber insurance complications follow a public violation. Boards increasingly ask whether leadership funded and monitored the safeguards before an incident.
When Do Data Fiduciary Obligations Take Effect?
The Data Protection Board and the core definitions took effect when MeitY notified the DPDP Rules in November 2025. Consent Manager registration follows at 12 months, around November 2026. Most Data Fiduciary obligations apply at 18 months, on May 13, 2027. MeitY proposed in January 2026 to shorten the window for some provisions, mainly for Significant Data Fiduciaries. As of October 2026, trackers reported no formal notification of that change, so confirm the position before you finalize your plan. Ampcus Cyber’s DPDPA guide walks through the phased timeline.
Which Frameworks And Tools Help Data Fiduciaries Comply?
ISO 27001 gives a strong security base, and ISO 27701 extends it into privacy management. Neither maps one to one with DPDP duties, so a gap analysis against the Act remains necessary. Data discovery tools locate personal data, and consent and rights platforms track requests. A GRC platform keeps controls and evidence in one place, which helps when the Board asks for proof. For vendors, third-party risk management connects processor oversight to the Fiduciary’s own accountability.
How Can A Data Fiduciary Prepare For DPDP Compliance?
Preparation follows six steps:
- Map every personal data set, its purpose, its location and its processors.
- Assign ownership, including a grievance contact and a Data Protection Officer where required.
- Rewrite privacy notices and consent flows in plain language.
- Apply security controls and set retention and deletion schedules.
- Update processor contracts and test that vendors can delete data and report breaches.
- Rehearse a breach drill that meets the 72-hour reporting window.
Organizations that start these steps before May 2027 gain time to test them, and they walk into regulatory scrutiny with evidence instead of promises.
Prepare for DPDP enforcement.
| Talk to Ampcus Cyber’s privacy experts to strengthen consent controls and close compliance gaps. |
People Also Ask
What is a Data Fiduciary in simple terms?
A Data Fiduciary is any organization or person that decides why and how personal data is processed.
What is the difference between a Data Fiduciary and a Data Principal?
The Data Fiduciary processes the data, and the Data Principal is the individual the data belongs to.
Is a Data Processor the same as a Data Fiduciary?
No. A Data Processor acts on the Fiduciary’s instructions, and the Fiduciary stays accountable for compliance.
Who is a Significant Data Fiduciary?
A Data Fiduciary or class that the Central Government notifies based on data volume, sensitivity and risk.
What is the penalty for a Data Fiduciary under the DPDP Act?
Up to Rs. 250 crore for failing to maintain reasonable security safeguards, with other tiers for breach reporting and Significant Data Fiduciary duties.
When must Data Fiduciaries comply with the DPDP Act?
Most obligations apply from May 13, 2027, though MeitY has proposed an earlier date for some provisions.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.









