Knowledge Resources › Data Fiduciary Obligations
Last updated: 20 August 2026
A Data Fiduciary is the person or organisation that decides why and how personal data is processed. Section 8 of the Digital Personal Data Protection Act, 2023 sets out its general obligations. These are the core duties that most directly shape how a business must handle personal data.
Accountability
- Responsibility for compliance. A Data Fiduciary is responsible for complying with the Act — including for processing carried out on its behalf by a Data Processor. This responsibility cannot be contracted away.
- Processors only under contract. A Data Fiduciary may engage a Data Processor to process personal data only under a valid contract.
Data quality
- Accuracy and completeness. Where personal data is likely to be used to make a decision that affects the Data Principal, or is to be disclosed to another Data Fiduciary, it must be complete, accurate and consistent.
Security and breaches
- Technical and organisational measures. The Data Fiduciary must implement appropriate technical and organisational measures to ensure effective observance of the Act.
- Reasonable security safeguards. It must protect the personal data in its possession or control by taking reasonable security safeguards to prevent a personal data breach.
- Breach notification. In the event of a personal data breach, the Data Fiduciary must notify the Data Protection Board and each affected Data Principal, in the form and manner prescribed by the DPDP Rules, 2025.
Retention and erasure
- Erase when no longer needed. The Data Fiduciary must erase personal data when the Data Principal withdraws consent, or once it is reasonable to assume the specified purpose is no longer being served — whichever is earlier — unless retention is required by law. It must also have its Data Processor erase the data.
Transparency and grievances
- Point of contact. The Data Fiduciary must publish the business contact information of a Data Protection Officer (where applicable) or of a person who can answer questions about the processing of personal data.
- Grievance redressal. It must establish an effective mechanism to address the grievances of Data Principals.
Some of these obligations are given further detail in the DPDP Rules, 2025 (for example, the form and manner of breach notification and of retention periods), and they come into force in stages — see the note on the phased implementation timeline. Certain Data Fiduciaries notified as Significant Data Fiduciaries carry further obligations on top of these.
This page is a general overview and is not legal advice; how each obligation applies depends on the specific facts of an organisation’s processing.