Foundation

Data Fiduciary, Data Principal, Data Processor: DPDP Act Definitions

A Data Fiduciary is any person or organisation that determines why and how personal data is processed under India's DPDP Act 2023 (also called the DPDPA). In simple terms, it is the entity that decides the purpose of using your personal data. The Data Principal is the individual the data is about, and a Data Processor handles data on a Data Fiduciary's instructions. This chapter explains all 28 definitions in the Act.

~4 min readLast updated: June 2026

DPDP Act roles

Which one are you?

The single question that decides your obligations and your liability

Who decides why and how the personal data is processed?

You do →

Data Fiduciary

You set the purpose and the means. You carry the full DPDP obligations — consent, notice, security, breach reporting — and the liability that comes with them.

Someone else does →

Data Processor

You only act on a Data Fiduciary's instructions, under a contract. Your duties flow from that contract — but the Fiduciary stays accountable to the Board.

Most companies guess “processor” and are wrong. If you decide what data to collect and why, you are a Data Fiduciary — even if a vendor does the actual processing for you.

The three roles, with a worked example

One customer order shows all three roles at once.

Data Principal

The individual the personal data is about.

Example: A customer buying from your online store.

Data Fiduciary

Decides why and how the data is processed. Holds the obligations.

Example: The D2C brand that collects the customer's address.

Data Processor

Processes data only on the Fiduciary's instructions, by contract.

Example: The courier or cloud vendor handling that address.

Key Definitions in Plain English

Section 2 of the DPDP Act 2023

The Act defines 28 key terms in Section 2. Understanding these definitions is essential because every obligation and right in the Act depends on them. Here they are, grouped by theme and explained in plain English.

THE PEOPLE: six definitions describe the key roles in the Act.

A Data Principal is the individual whose personal data is being processed: in everyday terms, the person the data is about. For children (anyone under 18) and persons with disability, the Data Principal includes their parent or lawful guardian. A Data Fiduciary is any person or organisation that, alone or in conjunction with other Data Fiduciaries, determines why and how personal data is processed. If your company decides to collect customer email addresses for marketing, your company is the Data Fiduciary. A Data Processor is any person or organisation that processes personal data on behalf of a Data Fiduciary, such as a cloud hosting provider or a payroll outsourcing firm acting on your instructions.

A Significant Data Fiduciary is a Data Fiduciary (or a class of them) that the Central Government specifically notifies under Section 10, based on factors like data volume or sensitivity. Think of it as a "high-impact" designation that triggers additional obligations. A Data Protection Officer (DPO) is an individual that every Significant Data Fiduciary must appoint under Section 10(2)(a) to oversee compliance. A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact for individuals to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform: essentially a consent intermediary that makes it easier for people to control their data permissions across multiple services.

THE DATA: five definitions describe what counts as data and what can go wrong with it.

"Data" in the broadest sense means any representation of information, facts, concepts, opinions, or instructions that is suitable for communication, interpretation, or processing by humans or by automated means. Personal data is any data about an individual who is identifiable by or in relation to that data: a name linked to a purchase history is personal data, but a fully anonymised statistic is not. Digital personal data simply means personal data in digital form. This is the specific category the Act regulates.

Processing covers any wholly or partly automated operation performed on digital personal data, and the Act lists a comprehensive range: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, dissemination, restriction, erasure, or destruction. If you do anything with digital personal data, it is likely processing. A personal data breach is any unauthorised processing of personal data, or any accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the data's confidentiality, integrity, or availability. In short: any incident where personal data is exposed, tampered with, or made inaccessible without authorisation.

THE INSTITUTIONS: four definitions cover the regulatory and governmental bodies.

The Board refers to the Data Protection Board of India, established under Section 18 of the Act. This is the regulator that hears complaints, conducts inquiries, and imposes penalties. The Appellate Tribunal is the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under the TRAI Act 1997, which hears appeals against Board decisions. "State" carries the same meaning as in Article 12 of the Constitution of India: it includes the Government of India, state governments, Parliament, state legislatures, and all local and other authorities within or under the control of the Government of India. A "digital office" is an office that adopts an online mechanism for handling proceedings from start to finish. The Board is intended to function as a digital office, conducting its work electronically rather than through physical paperwork.

THE CONCEPTS: thirteen definitions cover the operational and procedural terms that run through the Act.

"Consent" itself is not separately defined in Section 2, but certain legitimate uses refers to the lawful bases for processing personal data described in Section 7: the situations where an organisation can process data without obtaining consent (for example, for a State function, compliance with a court order, or a medical emergency). Specified purpose means the purpose stated in the notice given under Section 5 for which consent was obtained, or in the case of legitimate uses, the purpose described in Section 7. Organisations can only process data for the specific purpose they declared, not for anything else.

"Automated" means any digital process capable of operating automatically in response to instructions for processing data. "Prescribed" means as specified in the rules made under this Act: whenever the Act says something will be "as prescribed," the detailed requirements appear in the DPDP Rules. "Notification" means a notification published in the Official Gazette, which is how the government formally announces new rules, dates, and designations. A "proceeding" means any action taken by the Board.

The terms "gain" and "loss" have matching definitions: "gain" means gain in property (whether movable or immovable), services, remuneration, or financial advantage, and "loss" means loss in the same categories. These terms are relevant to penalty calculations. "Person" is defined broadly to include not just individuals but also Hindu Undivided Families (HUFs), companies, firms, associations of persons or bodies of individuals, the State, and any artificial juristic person, meaning the Act's obligations apply to virtually any type of entity. "Chairperson" means the Chairperson of the Data Protection Board. "Member" means a Member of the Board and includes the Chairperson. "She" is used as a gender-neutral reference to the Data Principal throughout the Act.

Key Points

  • 28 definitions in total: every right and obligation in the Act depends on these terms
  • Data Principal = the person whose data it is; Data Fiduciary = the organisation that decides why and how to process it; Data Processor = the entity doing the processing on instructions
  • "Processing" is defined very broadly: it covers everything from collecting to deleting data
  • A "personal data breach" includes not just hacking, but any unauthorised processing or accidental loss of access
  • "Person" includes companies, firms, HUFs, government bodies, and any artificial juristic person, not just individuals
  • "Consent Manager" is a new concept unique to this Act: a registered intermediary that helps individuals manage consent across platforms

Frequently Asked Questions

What is the meaning of a Data Fiduciary in simple terms?

In simple terms, a Data Fiduciary is whoever decides why and how your personal data is used. Under the DPDP Act 2023 (DPDPA), it is the person or organisation that determines the purpose and means of processing personal data — for example the bank, hospital, employer, or app that collects and uses your information.

What is a data fiduciary under the DPDP Act?

A Data Fiduciary is any person or organisation that, alone or with others, determines the purpose and means of processing personal data. In plain terms, it is the entity that decides why and how personal data is collected and used — for example a bank, hospital, employer, or e-commerce company.

What is the difference between a data fiduciary and a data processor?

A Data Fiduciary decides why and how personal data is processed and is accountable under the Act. A Data Processor processes personal data only on a Data Fiduciary's instructions — for example a cloud host or payroll vendor. The Data Principal is the individual the data is about.

Related: Significant Data Fiduciary

Can you give an example of a data fiduciary?

Any organisation that decides why and how to use people's personal data is a Data Fiduciary: a bank holding customer accounts, a hospital with patient records, an employer managing staff data, or an online retailer processing orders. If you set the purpose of the processing, you are the Data Fiduciary.

Related: Data Fiduciary obligations

Who is the data principal?

The Data Principal is the individual to whom the personal data relates. Where that individual is a child, the Data Principal includes their parents or lawful guardian; for a person with a disability, it includes their lawful guardian.

Not sure if you meet these requirements?

Take the free DPDP Readiness Assessment to get an instant compliance score and a detailed gap analysis report.

Download the full guide as PDF

Disclaimer: This guide is for informational purposes only and does not constitute legal advice. It is a plain-English interpretation of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The official gazette text is the only authoritative source. Consult qualified legal counsel before making compliance decisions.