Back to Key Provisions

Obligations of Data Fiduciaries

Comprehensive analysis of the obligations imposed on Data Fiduciaries under the DPDPA - purpose limitation, security safeguards, breach notification, and more.

11 min read

Overview of Fiduciary Obligations

Chapter II of the DPDPA establishes the core obligations for Data Fiduciaries. These obligations reflect the Act's principle-based approach, setting broad standards that organisations must meet while allowing flexibility in implementation. The fiduciary relationship - rooted in trust law - imposes a higher duty of care than a simple contractual obligation.

Lawful Ground for Processing (Section 4)

A Data Fiduciary may process personal data only: 1. For a lawful purpose for which the Data Principal has given consent, or 2. For certain legitimate uses recognised under the Act Processing for any purpose not disclosed in the consent notice, or beyond the scope of legitimate uses, is a violation. The purpose limitation principle requires that data collected for one stated purpose must not be repurposed without fresh consent. This is a fundamental obligation - without a valid ground for processing, all subsequent processing is unlawful regardless of the security measures applied.

Notice Obligation (Section 5)

Before or at the time of collecting personal data, the Data Fiduciary must give the Data Principal a notice containing: • A description of the personal data sought and the purpose of processing • The manner in which the Data Principal may exercise their rights, including the right to make a complaint to the Board • The manner in which the Data Principal may make a complaint to the Board The notice must be in clear and plain language. Where consent was obtained before the Act's commencement, the Fiduciary must provide the notice as soon as reasonably practicable. The DPDP Rules (R.3) further detail the notice requirements.

Data Accuracy (Section 8(3))

Data Fiduciaries must ensure the completeness, accuracy, and consistency of personal data, particularly where such data is likely to be used to make a decision affecting the Data Principal, or where the data is likely to be disclosed to another Data Fiduciary. This obligation requires organisations to implement processes for regular data quality reviews and to respond promptly to Data Principal requests for correction.

Security Safeguards (Section 8(5))

Every Data Fiduciary must implement reasonable security safeguards to protect personal data in its possession or under its control from: • Personal data breach • Unauthorised access, use, or disclosure The Act does not prescribe specific technical standards, using the "reasonable" standard instead. The DPDP Rules (R.6) require the application of appropriate technical and organisational measures, including encryption, access controls, and monitoring. Failure to implement reasonable security safeguards can attract a penalty of up to Rs 250 crore - the highest penalty under the Act.

Breach Notification (Section 8(6))

In the event of a personal data breach, the Data Fiduciary must notify: 1. The Data Protection Board of India 2. Each affected Data Principal The notification must be made in such form and manner as may be prescribed by the Rules. The DPDP Rules (R.7) set out the specific timelines, content requirements, and procedures for breach notification. The obligation applies regardless of the scale of the breach - there is no materiality threshold. However, the Board may issue guidance on the manner and urgency of notification based on the severity of the breach.

Data Retention and Erasure (Section 8(7))

Personal data must not be retained beyond the period necessary for the purpose for which it was collected. Once the purpose has been fulfilled and retention is no longer necessary for legal or business purposes: • The Data Fiduciary must erase the personal data • The Data Fiduciary must ensure its Data Processors also erase the data Where a Data Principal has withdrawn consent, the Fiduciary must erase the data unless retention is required by law. The DPDP Rules (R.8) prescribe specific data retention thresholds for different scenarios.

Grievance Redressal Mechanism (Section 8(10))

Every Data Fiduciary must: • Publish the business contact information of a Data Protection Officer (for Significant Data Fiduciaries) or a person authorised to answer questions • Establish an effective mechanism for addressing grievances The mechanism must be easily accessible and operate through the same medium by which services are offered. Response timelines are prescribed under the DPDP Rules (R.14).

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.