DPDP Basics · July 2026 · 7 min read
Every DPDP conversation eventually arrives at one question: "Are we a Significant Data Fiduciary?" The answer determines whether you face the Act's baseline obligations or its heaviest tier — DPO, independent audits and impact assessments. Here is how the classification works and what each status demands.
Every processor of personal data is a Data Fiduciary
A Data Fiduciary is any person or organisation that, alone or with others, determines the purpose and means of processing personal data. If you decide why customer, employee, student or citizen data is collected and how it is used — you are a fiduciary. Size is irrelevant: a proprietorship with a customer list in Excel and a listed bank carry the same baseline duties.
Distinguish this from a Data Processor, who processes data on a fiduciary's behalf (a payroll provider, a cloud host, an SMS gateway). Processors act under contract — but the Act keeps liability with the fiduciary, which is why your vendor agreements matter so much.
Baseline obligations — every fiduciary
- Process only with valid consent or a listed legitimate use, accompanied by a compliant notice.
- Maintain data accuracy where data feeds decisions about the principal or is shared onward.
- Implement reasonable security safeguards (the ₹250-crore obligation).
- Notify the Board and affected individuals of personal data breaches.
- Erase data once its purpose is served, unless law requires retention.
- Fulfil data principal rights — access, correction, erasure — and operate a grievance channel.
- Obtain verifiable parental consent for under-18s; no tracking or targeted advertising at children.
What makes a fiduciary "Significant"
The government may notify a fiduciary (or a class of fiduciaries) as a Significant Data Fiduciary based on factors in the Act:
- the volume and sensitivity of personal data processed;
- risk to the rights of data principals;
- potential impact on the sovereignty and integrity of India;
- risk to electoral democracy;
- security of the State and public order.
Expect large banks, insurers, telecoms, hospital chains, major e-commerce and social platforms, and large employers to be early candidates. But notification is the government's call — you don't self-declare; you prepare.
The additional SDF obligations
| Obligation | What it means in practice |
| Data Protection Officer | An individual based in India, responsible for compliance, reporting to the board of directors — and named as the contact point for grievances. |
| Independent data auditor | Periodic data audits by an independent auditor evaluating compliance with the Act. |
| Periodic DPIA | Regular Data Protection Impact Assessments — a structured analysis of processing risks and mitigations. |
| Additional measures | The Rules can prescribe more — including algorithmic due-diligence and restrictions on transferring certain data outside India. |
Breaching SDF obligations attracts penalties up to ₹150 crore — on top of the general penalty schedule.
Preparing under uncertainty
Many organisations sit in the grey zone: not obviously an SDF, not obviously exempt. The pragmatic strategy is to build to the baseline rigorously and keep SDF machinery ready:
- Complete a data inventory now — every SDF duty (audit, DPIA, DPO reporting) presupposes you know what data you hold. Automated data discovery makes this continuous rather than a one-off project.
- Run a voluntary DPIA on your riskiest processing — cheaper than retrofitting one under notification pressure.
- Designate a privacy owner today, even if not formally a DPO — someone must own rights requests and breach response regardless.
- Document everything — the fiduciary that can evidence its decisions is in a different negotiating position before the Board than one that cannot.
Where the fiduciary/processor line gets blurry
Classification errors here create real liability, because the two roles carry different duties. Three recurring situations:
- Your SaaS vendor decides how to use the data. A tool that processes your customer data strictly on your instructions is a processor. The moment it uses that data for its own purposes — model training, benchmarking, its own marketing — it becomes a fiduciary in its own right for that processing, and your contract should either permit it explicitly or forbid it.
- Group companies sharing data. Sharing between a parent and subsidiary is a transfer between two separate fiduciaries unless one is genuinely processing on the other's instructions. Intra-group data flows need a documented basis, not an assumption of unity.
- Joint arrangements. Where two organisations jointly determine purposes — a co-branded programme, a school and its transport partner — both are fiduciaries for that processing, and each owes the full baseline duties. "The other party handles compliance" is not a defence.
The vendor governance duty
Because liability stays with you, processor management is a first-order compliance activity rather than a procurement formality. A workable minimum:
- A register of processors — who they are, what personal data they touch, for which purpose, in which country.
- Contractual terms covering purpose limitation, security safeguards, breach notification to you within a window that lets you meet your own 72-hour duty, sub-processor disclosure and approval, audit rights, and deletion or return of data on exit.
- Onboarding diligence proportionate to risk — security certifications, breach history, data location.
- Exit discipline. Confirmed deletion, revoked access, and a record of both. Dormant vendor accounts holding old exports are a recurring breach source.
Self-assessment: how close are you to SDF territory?
| Indicator | Why it raises your profile |
| Millions of individuals' records | Volume is the first statutory factor |
| Health, financial or biometric data at scale | Sensitivity magnifies risk to principals |
| Large under-18 user base | Children's-data risk plus the ₹200-crore tier |
| Profiling or automated decisions affecting people | Direct risk to rights of data principals |
| Critical infrastructure or public-facing platform | Public order and State-security considerations |
Two or more of these suggests you should build to SDF standard voluntarily. The obligations — a named accountable owner, periodic impact assessments, independent review — are defensible governance regardless of whether a notification ever names you, and they are dramatically cheaper to build calmly than to retrofit on a deadline.
Frequently asked questions
Who decides whether an organisation is a Significant Data Fiduciary?
The central government, by notification, based on factors listed in the Act — volume and sensitivity of data, risk to data principals, sovereignty, electoral democracy and public order. Organisations do not self-classify.
Do small businesses count as Data Fiduciaries under the DPDP Act?
Yes. Any entity that determines the purpose and means of processing digital personal data is a Data Fiduciary, regardless of size or turnover. Baseline obligations — consent, security, breach notification, rights — apply to all.
Is a Data Processor liable under the DPDP Act?
The Act places obligations and liability primarily on the Data Fiduciary, who must engage processors under valid contract and remains answerable for processing done on its behalf — which makes processor contracts and vendor governance critical.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →