Data Fiduciary
A Data Fiduciary is the person or entity that alone or with others determines the purpose and means of processing personal data under India’s Digital Personal Data Protection Act, 2023.
In plain English
The Data Fiduciary is the accountable party under the DPDP Act — broadly analogous to the "controller" concept in other regimes. It bears the obligations of giving notice, establishing a lawful basis, maintaining security safeguards, notifying breaches, and responding to Data Principal rights requests. A Data Processor processes data on the Fiduciary’s behalf, under contract.
Why it matters
Identifying who is Fiduciary and who is Processor in a commercial arrangement determines who carries statutory liability. Getting this wrong in a services contract means the data protection clauses allocate obligations to the wrong party.
Example
A retailer using a third-party analytics platform is typically the Data Fiduciary for its customer data; the analytics vendor is a Data Processor acting on its instructions under a processing agreement.
Under Indian law
The DPDP Act uses "Data Fiduciary" and "Data Principal" rather than the controller/data-subject terminology used elsewhere. The choice of "fiduciary" signals a trust-based framing of the relationship.
How LexVio handles it
LexVio flags data protection clauses during contract review, including where roles and processing obligations are undefined.
LegalTech & Compliance AICommon questions
What is the difference between a Data Fiduciary and a Data Processor?
The Data Fiduciary determines the purpose and means of processing and carries the statutory obligations. A Data Processor processes personal data on the Fiduciary’s behalf under a contract and does not determine the purpose.
Is a Data Fiduciary the same as a GDPR controller?
The concepts are closely analogous, but the statutes differ in obligations and enforcement, so the roles should be mapped against the DPDP Act text rather than assumed identical.
