insightfour
What Are Data Fiduciaries and Data Processors Under Indian Law?

The Digital Personal Data Protection Act, 2023 introduced a new privacy framework for India and established important roles for organisations handling digital personal data. Among the most important concepts are data fiduciaries and data processors. Understanding these roles is essential because the classification determines who decides why and how personal data is processed, who acts on another organisation's instructions and where compliance responsibility sits. A business may be a Data Fiduciary for its own customers while simultaneously acting as a Data Processor for another organisation. The distinction therefore depends on the specific processing activity rather than simply the nature or size of the organisation.

What Are Data Fiduciaries and Data Processors?

The DPDP Act uses two closely connected definitions. A Data Fiduciary is a person who alone or together with another person determines the purpose and means of processing personal data. A Data Processor is a person who processes personal data on behalf of a Data Fiduciary. The distinction is based primarily on decision making and control. An organisation does not become a Data Processor merely because another business owns the information. Likewise, storing information on another company's servers does not by itself determine the legal role. The key question is who determines the purpose of processing and how the processing is carried out.

This distinction is important because many modern business relationships involve several parties. A company may collect customer information for its own products, use a cloud provider to host the information, engage a payroll company for employee records and use a marketing platform to send communications. Each relationship may involve a different role depending on the actual processing arrangement.

Who Is a Data Fiduciary Under Indian Law?

A Data Fiduciary is the organisation or person responsible for deciding the purpose and means of processing personal data. In simple terms, the Data Fiduciary determines why personal data is needed and how it will be processed to achieve the relevant purpose. For example, an online retailer collecting customer names, contact details and delivery addresses to fulfil orders will generally determine the purpose and means of this processing itself. The retailer is therefore acting as a Data Fiduciary for this activity. A hospital deciding how patient information is collected and used for providing healthcare services can similarly act as a Data Fiduciary. An employer determining how employee information is collected and used for employment administration can also fall within this role.

The role is not restricted to large companies. The statutory definition refers to a “person”, which is broad enough to cover companies, firms, associations, individuals and other recognised legal persons. The legal classification therefore depends on the processing activity rather than turnover, employee count or corporate structure.

Who Is a Data Processor?

A Data Processor processes personal data on behalf of a Data Fiduciary. The processor performs processing activities for the fiduciary rather than independently deciding the purpose for which the personal data will be used. Common examples include cloud hosting providers, payroll service providers, outsourced customer support companies, data entry vendors, certain analytics providers and software platforms handling customer information for their business clients. The precise classification depends on the contractual arrangement and, more importantly, the actual conduct of the parties.

For example, suppose an employer appoints an external payroll provider to calculate salaries using employee information supplied by the employer. If the provider processes the information for the employer's defined purpose and under the employer's instructions, it may act as a Data Processor. The employer remains the party determining why the employee information is being processed. A processor can perform sophisticated technical functions without automatically becoming the Data Fiduciary. Technical control over a system should not be confused with determining the legal purpose of processing.

The Purpose and Means Test

The most useful way to classify a relationship is to examine the purpose and means of processing. The first question is why the personal data is being processed. The second is who determines how the processing will take place. If an organisation determines both, it is likely to be the Data Fiduciary for that processing. If it processes personal data on behalf of another organisation and follows the other organisation's decisions, it may be the Data Processor.

Businesses should avoid using superficial tests such as who owns the database, who pays the vendor, where the servers are located or which party physically accesses the information. These facts may help understand the relationship but do not replace the statutory role test. The contract is also important, but a contract should reflect the actual relationship rather than artificially create one. Calling a vendor a “Data Processor” in an agreement does not necessarily make it a processor if the vendor independently determines purposes for some of the processing.

Can One Organisation Be Both a Data Fiduciary and a Data Processor?

Yes. This is one of the most important concepts businesses should understand. A SaaS company may be a Data Processor when it hosts and processes customer information according to its customer's instructions. The same SaaS company may be a Data Fiduciary for information relating to its own employees, website visitors, account holders and business operations.

Similarly, a marketing agency may process a client's customer list on the client's instructions for one campaign. If the agency separately collects information for its own purposes or uses the information independently for another purpose, its role may change for that processing. Role classification should therefore be performed activity by activity. Businesses should not automatically assign one privacy role to an entire organisation or vendor relationship.

Data Fiduciary vs Data Processor: The Main Difference

The fundamental difference is decision making. A Data Fiduciary determines the purpose and means of processing. A Data Processor processes personal data on behalf of the Data Fiduciary. A Data Fiduciary normally determines why information is collected, what processing is required, which services are engaged and how the processing fits within its business purpose. A Data Processor generally carries out defined processing activities for the fiduciary. This distinction affects contracts, accountability, privacy notices, security arrangements, breach response, deletion procedures and vendor management. It can also affect whether an organisation needs to consider Significant Data Fiduciary requirements.

What Responsibilities Does a Data Fiduciary Have?

The DPDP Act places the principal statutory obligations on Data Fiduciaries. Section 8 provides for responsibilities including compliance with the Act and Rules for processing undertaken by the fiduciary or on its behalf by a Data Processor. It also addresses security safeguards, personal data breaches, erasure and grievance mechanisms. A Data Fiduciary therefore cannot assume its responsibilities disappear simply because processing is outsourced. If a company appoints a processor to handle customer information, the outsourcing arrangement does not by itself transfer the fiduciary's statutory responsibility. This is a critical point for procurement and legal teams. Vendor selection should not be treated as a complete transfer of privacy responsibility. The Data Fiduciary needs appropriate contractual and operational controls over the processing relationship.

What Responsibilities Does a Data Processor Have?

The DPDP Act defines the Data Processor by reference to processing on behalf of a Data Fiduciary. Many of the detailed statutory obligations in Chapter II are addressed to the Data Fiduciary. This does not mean a processor can ignore privacy and security requirements. The relationship should be governed by a valid contract where the Act requires one. The contract should establish the permitted processing activities, security requirements, confidentiality expectations, breach escalation, assistance with rights requests, retention and deletion arrangements, subcontracting controls and other relevant obligations. The processor should also ensure its actual operations remain within the agreed scope. If it begins using customer information for its own unrelated purpose, the relationship may need to be reassessed because the processor could be determining the purpose of a new processing activity.

Why Data Processing Agreements Matter

A Data Processing Agreement or appropriate data processing provisions in a broader commercial contract can establish the operational framework between a Data Fiduciary and Data Processor. The agreement should describe the subject matter and purpose of processing, categories of personal data, categories of Data Principals, processing duration, security controls, confidentiality requirements, breach escalation, sub processors, deletion procedures and assistance requirements.

The agreement should also deal with audit and assurance rights where appropriate. A fiduciary needs enough information to demonstrate oversight of its processors, particularly where the vendor handles significant volumes of personal data. Contractual wording should match the technical reality. A clause promising immediate deletion may be ineffective if the processor has immutable backups or data embedded within another system. Legal teams and technology teams should therefore review processor contracts together.

Security Obligations Across the Fiduciary and Processor Relationship

Security is an important area where the responsibilities of both parties need to work together. The 2025 Rules specify reasonable security safeguards for personal data, including measures concerning encryption, masking or tokenisation, access controls, logs, monitoring, backups and technical and organisational safeguards, subject to the applicable commencement provisions. The Rules also refer specifically to appropriate security provisions in contracts between Data Fiduciaries and Data Processors.

A Data Fiduciary should therefore assess whether its processors maintain appropriate security controls. Vendor due diligence may include reviewing security certifications, access management, incident response procedures, encryption practices, vulnerability management and business continuity arrangements. A processor should also understand its contractual obligations. If the processor detects unauthorised access or a suspected breach, the contract should establish how quickly it must inform the fiduciary and what information it must provide.

Who Is Responsible for a Data Breach?

The allocation of responsibility following a breach should not be reduced to a simple statement such as “the processor is liable” or “the fiduciary is always liable”. The statutory framework, contract, facts and applicable commencement provisions must all be considered. Section 8 of the DPDP Act expressly places responsibility on the Data Fiduciary for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. The processor relationship therefore does not allow the fiduciary to contract away its statutory responsibility.

Operationally, the processor may be the first party to discover an incident. The contract should therefore require prompt escalation and cooperation. The fiduciary needs sufficient information to assess regulatory and individual notification requirements. Businesses should also remember that other laws can impose separate cyber incident reporting obligations. CERT In's directions, for example, contain reporting requirements for specified cyber security incidents.

What Is a Significant Data Fiduciary?

A Significant Data Fiduciary is a Data Fiduciary which the Central Government may notify based on specified factors. These include the volume and sensitivity of personal data processed, risks to Data Principals and potential effects on sovereignty, security of the State, electoral democracy and public order.

SDF status brings additional requirements. Section 10 provides for appointment of a Data Protection Officer based in India, appointment of an independent data auditor and periodic Data Protection Impact Assessments and audits. The DPDP Rules provide further requirements for SDFs, including annual DPIA and audit requirements and due diligence concerning algorithmic software. Businesses operating large scale digital services should therefore assess whether their processing could place them within the future SDF framework.

How Do SaaS Companies Fit Into the Framework?

SaaS companies provide one of the clearest examples of why role classification must be activity specific. A SaaS provider may process a customer's employee information, customer records or business contacts as a Data Processor. At the same time, it may determine its own purposes for processing account information, billing information, website visitor data, employee information and security logs.

The company may therefore have both roles within the same platform. Its privacy documentation, contracts and internal data maps should reflect this distinction. This is especially important for AI enabled SaaS products. If a provider uses customer submitted data for its own model training, product development or analytics, the parties should examine whether this use remains within the processor relationship. The answer depends on the actual purposes and means of processing rather than the wording of a standard contract.

What About Cloud Service Providers?

Cloud hosting creates another common classification question. A business may store customer records with a cloud provider while deciding why the records are processed and how the service is used. The cloud provider may act as a processor for the customer's data where it provides infrastructure on the customer's behalf. However, the provider may act as a Data Fiduciary for its own customer account information, billing information, security data and other processing activities.The correct approach is therefore to examine each processing activity separately.

How Should Businesses Determine Their Role?

Businesses should begin with a processing inventory rather than a list of vendors. For every major processing activity, identify the personal data involved, the purpose, the systems used, the people affected and the organisations receiving the information. Next, determine who decided why the information should be processed. Then identify who determines the key means of processing. Review the contract and compare it with actual operations. If the organisation decides the purpose and means, it is likely acting as a Data Fiduciary. If another organisation decides the purpose and the business simply processes information on its behalf, the business may be a Data Processor. The assessment should also consider whether the vendor uses the information for independent purposes. Independent use may change the role for that activity and should trigger a fresh legal review.

Common Mistakes in Classifying Data Roles

One common mistake is assuming the company collecting the data is always the Data Fiduciary. Collection is important, but the statutory test focuses on determining the purpose and means of processing. Another mistake is assuming the party hosting the database is the Data Fiduciary. Hosting infrastructure does not automatically establish control over the purpose of processing. Businesses also sometimes assume a processor has no privacy responsibilities. A processor relationship requires appropriate contractual and technical controls. The processor's conduct can directly affect the fiduciary's compliance position.

A further mistake is applying one role to an entire vendor relationship. A company can perform several different processing activities for the same customer, with different legal roles for each activity. Finally, organisations should avoid treating GDPR terminology as an exact substitute. A Data Fiduciary broadly resembles a GDPR controller and a Data Processor broadly resembles a GDPR processor, but Indian businesses should apply the DPDP Act's own statutory definitions and requirements.

The Role of Legal and Compliance Teams

Correct role classification should be built into procurement, product development and contract review. A legal team should examine whether the proposed relationship reflects the actual decision making structure. data protection lawyers can assist with role mapping, data processing agreements, vendor assessments, privacy notices, cross border processing and broader DPDP compliance planning. Their review becomes particularly important where a vendor uses personal data for several purposes or combines client data with its own datasets. The assessment should not remain solely with the legal department. Technology, security, procurement, product and business teams should understand why a particular vendor is classified as a processor and what contractual controls are required.

DPDP Compliance and the Current Implementation Timeline

The DPDP Act was enacted in August 2023, but its provisions do not commence simultaneously. The Government's commencement notification dated 13 November 2025 brought Section 2 and several institutional provisions into force immediately. It placed Sections 3 to 5, Sections 7 to 17 and other substantive provisions within the eighteen month commencement group.

This phased approach is important when discussing Data Fiduciary and Data Processor obligations in 2026. The statutory definitions are already in force, while several of the operational obligations associated with the distinction are scheduled for later commencement. Businesses should therefore avoid describing the DPDP Act as either completely inactive or fully operational. The correct position depends on the particular provision being discussed. The transition period provides an opportunity to map processing activities, classify vendors, update contracts, establish security controls and prepare privacy governance systems before the substantive obligations become applicable.

Conclusion

Understanding the distinction between Data Fiduciaries and Data Processors is fundamental to building a practical privacy compliance framework under Indian law. The most important question is who determines the purpose and means of processing. The answer should be assessed for each processing activity rather than assigned automatically to an entire organisation. A Data Fiduciary generally determines why personal data is processed and how the processing is structured. A Data Processor handles personal data on behalf of the fiduciary. However, modern businesses often occupy both roles across different activities. SaaS providers, cloud companies, marketing agencies, payroll providers and technology vendors may therefore need a detailed role assessment rather than a simple label.

The distinction also has practical consequences for contracts, security, vendor management, breach response, deletion, audits and accountability. Organisations should maintain accurate processing inventories, review vendor relationships carefully and seek corporate legal advice where contractual or governance arrangements need to reflect the actual allocation of responsibilities. As India's DPDP framework moves through its phased commencement, businesses have an opportunity to resolve role classification issues before the substantive compliance obligations take effect. Clear allocation of roles today can make privacy notices, contracts, security controls and governance processes considerably easier to manage in the future.

Frequently Asked Questions (FAQs)

Q1. What is a Data Fiduciary in India?

A Data Fiduciary is a person who alone or together with another person determines the purpose and means of processing personal data under Section 2 of the DPDP Act, 2023.

Q2. What is a Data Processor under Indian law?

A Data Processor is a person who processes personal data on behalf of a Data Fiduciary. The processor generally performs processing according to the fiduciary's purpose and instructions.

Q3. Can one company be both a Data Fiduciary and a Data Processor?

Yes. An organisation may be a Data Fiduciary for its own customers, employees or business operations while acting as a Data Processor for another organisation's personal data.

Q4. Does outsourcing personal data processing transfer legal responsibility?

No. Outsourcing does not automatically transfer the Data Fiduciary's statutory responsibility. Section 8 places responsibility on the Data Fiduciary for processing undertaken by it or on its behalf by a Data Processor.

Q5. Is a Data Processing Agreement mandatory in India?

Section 8 requires a Data Fiduciary to engage a Data Processor for activities related to offering goods or services to Data Principals only under a valid contract. Businesses should therefore ensure processor relationships are properly documented and reflect the actual processing arrangement.

Q6. Is a cloud provider a Data Processor?

A cloud provider may be a Data Processor when it hosts or processes personal data on behalf of a customer under the customer's purposes and instructions. It may separately be a Data Fiduciary for its own independent processing activities.

Q7. Is a SaaS company a Data Fiduciary or Data Processor?

It can be either or both. A SaaS provider may act as a processor for customer data while acting as a fiduciary for its own employees, account administration, billing, security or other independent processing.

Q8. Who is responsible if a Data Processor causes a breach?

The Data Fiduciary remains responsible for compliance in relation to processing carried out on its behalf. The contract should establish the processor's security and incident escalation obligations. The specific consequences depend on the applicable law, facts and contractual arrangements.

Q9. What is the difference between a Data Fiduciary and a GDPR Data Controller?

The concepts are broadly comparable because both roles focus on determining the purposes and means of processing. However, Indian businesses should rely on the DPDP Act's statutory definitions rather than assuming GDPR terminology automatically determines their position in India.

Q10. Do Data Processors need a Data Protection Officer?

The DPDP Act specifically requires a Data Protection Officer for a Significant Data Fiduciary. It does not establish an equivalent universal DPO requirement for every Data Processor.

Q11. Can a vendor decide how it technically processes data and still remain a Data Processor?

Technical implementation alone does not necessarily change the role. The assessment should focus on who determines the purpose and relevant means of processing. Businesses should examine the actual relationship, technical autonomy and contractual arrangements rather than relying on a label.

This update was released on 09 Oct 2026.

The views expressed in this update are personal and should not be construed as any legal advice. Please contact us directly on +91 22 40565252 or contact@mhcolaw.com for any assistance.

Legal Update Team
MANSUKHLAL HIRALAL & COMPANY
Advocates, Solicitors and Notaries
T: +91 22 40565252
Mumbai Office: Surya Mahal, 2nd Floor, 5, Burjorji Bharucha Marg, Fort, Mumbai-400 023, India
Delhi Office: Block C-9, Lower Ground Floor, Jangpura Extension, New Delhi - 110 014, India
www.mhcolaw.com

"Noted lawyer in the Real Estate practitioner from India" - Chambers & Partners

Please consider the environment before printing this email

The information contained in this communication is intended solely for the use of the individual or entity to whom it is addressed and others authorized to receive it. This communication may contain confidential or legally privileged information. If you are not the intended recipient, any disclosure, copying, distribution or action taken relying on the contents is prohibited and may be unlawful. If you have received this communication in error, or if you or your employer does not consent to email messages of this kind, please notify the sender immediately by responding to this email and then delete it from your system. No liability is accepted for any harm that may be caused to your systems or data by this message.
Need Help? Chat with us