Skip to content
Back to Blog
·9 min read·compliance

Data Fiduciary Obligations Under DPDP Act: India Checklist

Every Indian business processing personal data is a Data Fiduciary under DPDP Act 2023. This checklist covers all six obligation categories to stay compliant.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

A Data Fiduciary under India's Digital Personal Data Protection Act 2023 is any entity — company, startup, partnership, or individual — that determines the purpose and means of processing personal data. If your business collects names, phone numbers, email addresses, financial details, location data, or any information that identifies a living person, you are a Data Fiduciary. That classification immediately triggers six categories of enforceable obligation: consent management, data security, breach notification, fulfilment of data principal rights, retention and purpose limitation, and oversight of third-party processors. The Data Protection Board of India (DPBI) has investigation and adjudication powers, and penalties for non-compliance can reach significant amounts.

This checklist breaks down every obligation in detail, maps them to actionable controls, and flags the additional duties that apply to Significant Data Fiduciaries.

What Is a Data Fiduciary Under the DPDP Act?

The Digital Personal Data Protection Act 2023, which received Presidential assent on 11 August 2023, creates a tiered framework of data accountability. A Data Fiduciary decides why and how personal data is processed and bears the primary compliance burden. A Data Processor handles data on the Fiduciary's behalf under contract with fewer direct obligations. The Data Principal is the individual whose data is at stake. A Consent Manager — once rules are finalised — will enable Principals to manage and withdraw consent across platforms at scale.

The Act's reach is broad by design. An Indian startup processing EU visitor data, or a foreign company processing data of Indian residents, both fall within scope. Geography of processing is not the deciding factor — the nationality of the Data Principal is.

The DPDP Compliance Journey

DPDP compliance is not a one-time exercise. It is a repeating cycle of assessment, implementation, and review. Skipping early steps compounds risk at every later stage.

graph TD A[Assessment and Data Inventory]:::normal --> B[Draft Itemised Privacy Notice]:::normal B --> C[Obtain Purpose-Specific Consent]:::normal C --> D[Apply Data Minimisation]:::normal D --> E[Implement Security Safeguards]:::normal E --> F{Breach Detected}:::danger F -- Yes --> G[Notify DPBI and Data Principals]:::danger F -- No --> H[Fulfil Data Principal Rights]:::success G --> H H --> I[Periodic Compliance Review]:::success I --> A classDef normal fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 classDef danger fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 classDef success fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

DPDP Obligations by Category

The six obligation categories are not equal in implementation effort or regulatory exposure. Consent management and data security together account for roughly half the total compliance workload because they require both process design and technical implementation.

pie title DPDP Obligations by Category "Consent Management" : 28 "Data Security" : 22 "Data Principal Rights" : 18 "Breach Notification" : 12 "Retention and Purpose" : 12 "Third-Party Oversight" : 8
₹250 croreMaximum penalty for failure to implement reasonable security safeguards (MeitY DPDP Act 2023 Schedule)
₹200 croreMaximum penalty for failure to notify a personal data breach (MeitY DPDP Act 2023 Schedule)
6 hoursMandatory breach reporting window for critical-sector incidents (CERT-In Cyber Security Directions 2022)

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The DPDP Act sets a high bar for valid consent. It must be free, specific, informed, unconditional, and unambiguous — indicated by a clear affirmative act. Pre-ticked checkboxes, omnibus consent buried in terms of service, and implied consent by continued use of a product are explicitly insufficient.

Practical requirements your team must address:

    1. Itemised notice before collection: State precisely what data you collect, why, who it will be shared with, and how the Principal can withdraw consent.
    2. Plain language: The notice must be comprehensible to the intended recipient. The Act gives individuals the right to receive the notice in any scheduled language of India.
    3. Withdrawal as easy as giving: You cannot make opt-out harder than opt-in. A buried email-to-withdraw flow does not meet the standard.
    4. Legitimate uses: The Act permits processing without consent in limited cases — state-sanctioned purposes, medical emergencies, employment obligations — but the burden of establishing each exception sits with the Fiduciary.
⚠️
WARNING
Blanket consent clauses are no longer defensible. Each processing purpose requires a distinct, separately confirmable consent item. Audit every onboarding form, data-collection modal, and cookie banner before the DPBI begins active enforcement.

Obligation 2 — Data Security

Section 8(5) of the DPDP Act requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches. The Act deliberately avoids prescribing a single technical standard; sector-specific requirements will emerge through rules. However, the security expectation is substantive — "reasonable" will be judged against what a prudent organisation in your sector would do.

Controls that align with the Act's intent include: encryption of personal data at rest and in transit; role-based access controls and least-privilege policies; multi-factor authentication on all systems storing personal data; regular vulnerability assessments and penetration testing to surface exploitable weaknesses before attackers do; patch management with defined response SLAs; and security reviews before onboarding any Data Processor.

🛡️
SECURITY
Vulnerability assessment and penetration testing (VAPT) directly supports your Section 8(5) defence. A documented, dated test report provides evidence that reasonable security measures were in place at the time of any breach — a critical factor during a DPBI investigation. Absence of such documentation shifts presumption toward negligence.

Obligation 3 — Breach Notification

A personal data breach must trigger two parallel notification obligations: one to the Data Protection Board of India and one to each affected Data Principal. The DPDP Act does not specify a notification window in its text, but draft rules and sector-specific directions (including the CERT-In Cyber Security Directions 2022) provide the clearest current benchmark for expected urgency.

Your breach notification must include:

    1. The nature and cause of the breach
    2. Categories and approximate volume of personal data affected
    3. Likely consequences for Data Principals
    4. Measures already taken and planned to contain and mitigate harm
🚨
DANGER
Delaying notification while waiting for a complete forensic investigation is a standalone penalty trigger. Notify the DPBI promptly with the facts available, then provide a supplementary report as more information is confirmed. Silence is worse than partial disclosure.

Obligation 4 — Data Principal Rights

The DPDP Act codifies five enforceable rights that every Data Principal can exercise against any Data Fiduciary. These are not aspirational; each right creates a corresponding duty on your organisation to build a response workflow.

RightWhat You Must DoNotes
Right to AccessProvide a summary of personal data processed and all entities it was shared withMust be on request, in prescribed form
Right to Correction and CompletionCorrect inaccurate data; complete incomplete dataCannot refuse without documented justification
Right to ErasureErase personal data when consent is withdrawn or purpose is servedRetention for legal obligation overrides this
Right to Grievance RedressalAcknowledge complaints via a named Grievance Officer; resolve within prescribed timeframesOfficer details must be published on your platform
Right to NominateAllow Principals to nominate someone to exercise rights on death or incapacityMust be offered at point of consent
You are required to publish the name and contact details of your Grievance Officer on your platform. Unresolved grievances can be escalated directly to the DPBI, which has the authority to impose penalties after adjudication.
💡
TIP
Build your rights-request workflow into your product from the start rather than bolting it on later. A dedicated data-subject request (DSR) portal — even a simple form routed to a named inbox — satisfies the structural requirement and creates an audit trail for every request and response.

Obligation 5 — Retention and Purpose Limitation

Purpose Limitation: Personal data may only be used for the specific purpose under which consent was obtained. Using a customer's email — collected during checkout — to send unrelated marketing without fresh consent is a violation, even if the address is already in your CRM.

Storage Limitation and Deemed Erasure: Once the stated purpose is served, or consent is withdrawn, the Data Fiduciary must erase the data. The Act introduces a concept of deemed erasure via Consent Managers in certain scenarios; rules will clarify timelines. The direction is unambiguous: data must not outlive its purpose. Map every collection point to a purpose and a maximum retention period, and automate erasure wherever possible.

Obligation 6 — Third-Party and Data Processor Oversight

When you engage a vendor — a CRM, cloud provider, analytics platform, or payroll processor — to process personal data, you remain accountable as the Data Fiduciary. Minimum contractual requirements: a written agreement specifying nature, purpose, and duration; a prohibition on sub-contracting without written consent; a right to audit the Processor's security controls; and an obligation on the Processor to assist with breach notification and rights fulfilment. Any Processor breach of data you hold becomes your breach for DPBI notification purposes.

Significant Data Fiduciaries — Heightened Obligations

The Central Government may designate specific organisations as Significant Data Fiduciaries (SDFs) based on volume and sensitivity of data processed, risk to Data Principals, potential national-security implications, and scale of child data processing. SDFs face a materially heavier compliance layer:

Additional SDF ObligationRequirement
Data Protection OfficerAppoint a named DPO resident in India, accountable to the board
Independent Data AuditAnnual audit of data processing practices by an independent auditor
Data Protection Impact AssessmentMandatory DPIA before initiating any high-risk processing activity
Algorithmic AccountabilityPeriodic assessment of algorithms used for targeting, profiling, or automated decision-making
The initial SDF list has not yet been published, but designation can take effect quickly once notified. If your organisation operates at significant scale — particularly involving children, financial data, or health records — start building these processes now.

Your DPDP Compliance Action Checklist

Control AreaSpecific ActionPriority
Data InventoryMap all personal data collected, stored, processed, and sharedP0
Privacy NoticeDraft itemised, purpose-specific notices for each collection pointP0
Consent MechanismReplace blanket consent with per-purpose checkboxes and confirmationsP0
Grievance OfficerAppoint, name, and publish officer contact on your platformP0
Security AssessmentConduct VAPT on all systems handling personal dataP0
Breach Response PlanDocument detection, containment, and DPBI notification proceduresP1
Data Processor ContractsReview all vendor agreements for DPDP-required clauses and audit rightsP1
Erasure WorkflowAutomate deletion when purpose is served or consent is withdrawnP1
Consent Withdrawal UIBuild an accessible opt-out flow for every collected purposeP1
Retention ScheduleDefine and enforce maximum retention periods per data categoryP2
SDF Readiness AssessmentEvaluate whether SDF designation criteria could apply to your organisationP2
Bachao.AI, built by Dhisattva AI Pvt Ltd (a DPIIT Recognized Startup), runs automated VAPT scans to surface the vulnerabilities that create personal data breach risk under Section 8(5). See how the DPDP Shield offering maps findings to your compliance posture.
🎯Key Takeaway
The DPDP Act 2023 makes security a legal mandate, not a best-practice suggestion. Data Fiduciaries who cannot demonstrate reasonable security safeguards — backed by documented assessments and repeatable processes — face both maximum penalty exposure and reputational damage that far exceeds the cost of compliance. The sequence that matters: inventory your data, harden your consent mechanisms, run a VAPT, and build your breach notification runbook before the DPBI's enforcement posture becomes active.

Frequently Asked Questions

Who qualifies as a Data Fiduciary under the DPDP Act 2023?
Any entity — company, startup, or individual — that determines the purpose and means of processing personal data of Indian residents qualifies as a Data Fiduciary. This covers both India-based businesses and foreign organisations processing Indian residents' data, regardless of where processing takes place.
What is the difference between a Data Fiduciary and a Data Processor under DPDP?
A Data Fiduciary decides why and how personal data is processed and carries the primary compliance burden. A Data Processor acts on the Fiduciary's instructions and does not hold independent obligations — but must contractually assist with breach notification and rights fulfilment.
When must a Data Fiduciary notify a personal data breach under DPDP?
The DPDP Act requires prompt notification to the Data Protection Board of India and affected Data Principals. CERT-In's 2022 directions set a 6-hour benchmark for critical sectors. Do not wait for a full forensic investigation — notify with available facts immediately and supplement as the picture becomes clearer.
What rights do Data Principals have under the DPDP Act?
Data Principals hold five enforceable rights: access to data processed about them; correction and completion of inaccurate or incomplete data; erasure when purpose is served or consent withdrawn; grievance redressal via a named Grievance Officer; and the right to nominate someone to exercise these rights on their behalf.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See where your business stands against the DPDP Act 2023

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →