Obligations of a Data Fiduciary Under the DPDP Act

Last updated: 20 August 2026

A Data Fiduciary is the person or organisation that decides why and how personal data is processed. Section 8 of the Digital Personal Data Protection Act, 2023 sets out its general obligations. These are the core duties that most directly shape how a business must handle personal data.

Accountability

Data quality

Security and breaches

Retention and erasure

Transparency and grievances

Some of these obligations are given further detail in the DPDP Rules, 2025 (for example, the form and manner of breach notification and of retention periods), and they come into force in stages — see the note on the phased implementation timeline. Certain Data Fiduciaries notified as Significant Data Fiduciaries carry further obligations on top of these.

This page is a general overview and is not legal advice; how each obligation applies depends on the specific facts of an organisation’s processing.