The most consequential classification under the DPDPA is whether your organisation is a Data Fiduciary or a Data Processor. The Data Fiduciary bears virtually all compliance obligations — consent, notice, security, breach notification, rights fulfilment. The Data Processor\'s obligations are narrower but not negligible.
The test is functional, not contractual. What you call yourself in a contract does not determine your classification. If you determine the purpose and means of processing, you are the Data Fiduciary regardless of the contract language. Getting this wrong means either under-building compliance (Data Fiduciary calling itself a Processor) or over-building (Data Processor assuming Fiduciary obligations unnecessarily).
The Five-Question Decision Test
| Question | → Data Fiduciary | → Data Processor |
|---|---|---|
| Who decides WHY personal data is collected? | You determine the purpose — you are likely the Data Fiduciary | You process data for a purpose determined by someone else — you are likely a Data Processor |
| Who decides HOW personal data is processed? | You determine the means, tools, and methods | You follow instructions on means provided by the engaging entity |
| Who interacts with the Data Principal for consent? | You collect consent and serve notices directly | You do not interact with Data Principals — the engaging entity does |
| Who decides how long data is retained? | You set the retention period based on your business needs | You retain data as long as instructed and delete on instruction |
| Who would be liable if data is misused? | You bear primary regulatory liability under the DPDPA | The Data Fiduciary bears regulatory liability; your liability is contractual |
Statutory Definitions
Section 2(i) — Data Fiduciary
"Data Fiduciary" means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
Section 2(k) — Data Processor
"Data Processor" means any person who processes personal data on behalf of a Data Fiduciary.
Compliance Obligations: Who Bears What
The DPDPA assigns obligations primarily to the Data Fiduciary:
- ▸Consent and notice: Data Fiduciary\'s obligation — must serve notice, collect consent, and manage withdrawal
- ▸Security safeguards: Both — Data Fiduciary must ensure, Data Processor must implement
- ▸Breach notification: Data Fiduciary\'s obligation — must notify Board and Data Principals
- ▸Rights fulfilment: Data Fiduciary\'s obligation — must respond to access, correction, erasure requests
- ▸Data retention and deletion: Data Fiduciary determines; Data Processor deletes on instruction
- ▸Penalty exposure: Data Fiduciary bears regulatory penalties; Data Processor\'s exposure is contractual
Related Reading
Frequently Asked Questions
What is a Data Fiduciary under DPDPA?
Under Section 2(i), a Data Fiduciary is any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. The Data Fiduciary bears primary compliance obligations including consent management, notice, security safeguards, breach notification, and responding to Data Principal rights.
What is a Data Processor under DPDPA?
Under Section 2(k), a Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The Data Processor acts only under the instructions of the Data Fiduciary and does not independently determine the purpose of processing. Under the DPDPA, the Data Fiduciary remains responsible for the Data Processor's compliance.
Can an entity be both a Data Fiduciary and a Data Processor?
Yes. An entity may be a Data Fiduciary for its own employees' and customers' data (where it determines the purpose and means) and simultaneously a Data Processor when processing data on behalf of another entity. The classification is determined per processing activity, not per entity.
Who bears the penalty exposure under DPDPA — the Fiduciary or the Processor?
The DPDPA places primary compliance obligations and penalty exposure on the Data Fiduciary. The Data Fiduciary is responsible even for processing carried out by the Data Processor on its behalf. However, the Data Processor must maintain security safeguards and cooperate with breach notification. Contractual indemnities between Fiduciary and Processor are a commercial matter.
Classification Advisory
We assess your processing activities and classify each one correctly. The classification determines the compliance programme you need to build.
Schedule a Consultation