· 8 min read
By Correct Editorial — Compliance Research Desk
Data Fiduciary vs Data Processor: Key Differences
Published on: July 29, 2026
Almost every avoidable dispute under India's Digital Personal Data Protection Act, 2023 will trace back to one unexamined assumption: that everyone in the data chain knows which role they occupy. They frequently do not. A payroll vendor believes it is "just a processor" while quietly enriching employee records for its own product analytics. A SaaS platform assumes its enterprise customer carries all the risk while it decides retention periods unilaterally. Both assumptions are wrong, and after 13 May 2027 both are expensive.
This primer explains the statutory test, why the distinction determines who pays, how to classify each processing activity, and what must appear in your contracts. For the broader framework, see DPDP Act 2023: An Overview for Businesses.
What Is the Statutory Difference?
The Act defines the two roles in adjacent clauses of Section 2:
- Data Fiduciary — Section 2(i): "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data."
- Data Processor — Section 2(k): "any person who processes personal data on behalf of a Data Fiduciary."
The test is decisional authority, not data possession, technical sophistication, or contract value. If you decide why personal data is processed and how it is processed in substance, you are a Data Fiduciary — even if you never store a byte yourself. If you execute another organisation's decisions within the boundaries it sets, you are a Data Processor, however large your infrastructure.
Two features of the Indian drafting deserve attention. First, the phrase "alone or in conjunction with other persons" means joint fiduciary status exists in substance even though the Act never uses the term. Second, "person" is defined broadly to include individuals, HUFs, companies, firms, associations of persons, the State, and every artificial juristic person — so intra-group entities and government bodies are covered by the same test.
Why Does the Distinction Matter So Much?
Because Section 8(1) puts the entire compliance burden on one side of the line:
A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.
Three consequences follow.
You cannot contract out of accountability. An indemnity in your master services agreement may allocate money between you and your vendor, but it does not move the statutory duty. The Board will look to the fiduciary.
Your vendor's failure is your breach. If a processor loses data, the fiduciary has failed to take reasonable security safeguards under Section 8(5) — exposure up to ₹250 crore — and it is the fiduciary who must intimate affected individuals and file the 72-hour report under Section 8(6), with a further ₹200 crore head for failing to do so.
Misclassification cuts both ways. A processor that begins determining purposes — training its own models on client data, monetising insights, deciding retention on its own initiative — becomes a Data Fiduciary for that processing and inherits the full obligation set, usually without having built any of the machinery to discharge it.
How Do You Classify a Given Activity?
Classify per processing activity, not per company. The same vendor can be a processor for one dataset and a fiduciary for another. Ask five questions.
- Who decided the purpose? Who wrote down why this data is being processed and for what outcome?
- Who decides the essential means? What data is collected, from whom, how long it is retained, who it is disclosed to, and on what legal basis. Technical means — which database engine, which region, which encryption library — can sit with the processor without changing the role.
- Whose relationship is it with the individual? Who gave the Rule 3 notice and holds the consent record?
- Could the party use the data for its own benefit without asking? If yes, it is deciding purposes.
- What happens on termination? A processor must return or delete on instruction; a fiduciary keeps deciding.
| Dimension | Data Fiduciary | Data Processor |
|---|---|---|
| Statutory basis | Section 2(i) | Section 2(k) |
| Decides purpose | Yes | No |
| Decides essential means | Yes | No — technical means only |
| Gives notice under Rule 3 | Yes | No |
| Obtains and manages consent | Yes | No |
| Answers rights requests (Sections 11 to 14) | Yes | Assists the fiduciary |
| Intimates breaches under Rule 7 | Yes | Notifies the fiduciary per contract |
| Direct exposure to the Schedule | Yes | Only if it becomes a fiduciary in substance |
| Must engage sub-vendors under contract | Yes, Section 8(2) | Per contract with the fiduciary |
| Erasure duty | Section 8(7)(a) | Section 8(7)(b), on the fiduciary causing it |
Where Do Indian Businesses Get This Wrong?
Payroll and HR outsourcing. The employer is the fiduciary for employee data. The payroll bureau is a processor — until it uses aggregated salary data to build benchmarking products, at which point it is a fiduciary for that purpose and needs its own lawful basis.
Cloud and hosting. A hyperscaler is a processor for customer workloads and a fiduciary for its own account, billing, support and security telemetry data. Both statements are true simultaneously.
Marketing agencies and adtech. An agency running campaigns on the brand's instructions is a processor. An agency that appends third-party audience data, builds look-alike segments, or retains contact lists after the engagement ends is a fiduciary.
KYC and verification vendors. The regulated entity is the fiduciary. The verification vendor is a processor for the specific check — but if it retains the verification record to sell repeat-verification services to other clients, that retention is its own purpose.
AI and analytics vendors. The sharpest current risk. A vendor that processes customer prompts solely to return outputs is a processor. A vendor that retains prompts to train or fine-tune its own models has determined a purpose of its own. Contractual silence on training rights is the single most common gap we see; our guide to AI compliance under the DPDP Act covers the lifecycle controls in detail.
Group companies. Sharing customer data with a subsidiary for its own cross-sell is a disclosure between fiduciaries, requiring its own notice and consent — not an internal transfer to a processor.
What Must the Contract Say?
Section 8(2) is unambiguous: a Data Fiduciary may engage a Data Processor for any activity related to offering goods or services to Data Principals only under a valid contract. Rule 6(1) adds that reasonable security safeguards must include "appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards."
A DPDP-fit processing agreement should carry, at minimum:
- Scope and instruction clause — the processor acts only on documented instructions and only for the specified purposes
- Security schedule mirroring Rule 6 — encryption, obfuscation, masking or tokenisation; access control over computer resources; logging, monitoring and review; backups for continuity; and retention of logs and personal data for one year to enable detection, investigation and remediation
- Breach notification to the fiduciary without delay, with enough detail for the fiduciary to meet its own 72-hour obligation to the Board
- Sub-processor controls — prior approval, flow-down of equivalent terms, and a maintained list
- Assistance obligations for access, correction, erasure, nomination and grievance requests, calibrated to the fiduciary's 90-day grievance window under Rule 14(3)
- Erasure and return on termination, operationalising Section 8(7)(b)
- Location and sub-processing transparency, feeding the transfer register discussed in Cross-border Data Transfer Rules Explained
- Audit and evidence rights, including certifications and the right to inspect on reasonable notice
- Express prohibition on independent use, including training AI models on the fiduciary's data without a separate written basis
Legacy master services agreements signed before 2024 almost never contain these terms. Repapering the vendor estate is a twelve-month exercise for most mid-sized enterprises, which is precisely why it should start now rather than in 2027.
Does the Distinction Change Anything for Significant Data Fiduciaries?
Yes, but only on the fiduciary side. An entity notified as a Significant Data Fiduciary under Section 10 must appoint an India-based Data Protection Officer and an independent data auditor, and under Rule 13 conduct an annual Data Protection Impact Assessment and audit, report significant observations to the Board, and exercise algorithmic due diligence over technical measures including software used for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data. Where the Central Government specifies categories of personal data on a committee's recommendation, the SDF must ensure that data and its traffic data are not transferred outside India.
Processors are not notified as SDFs. But a processor serving SDF clients will inherit those requirements contractually — expect DPIA cooperation clauses, audit participation, and localisation commitments to appear in enterprise procurement from 2027.
An Action Plan for the Next Two Quarters
- Build a processing register listing each activity, the personal data involved, the purpose, and the parties. Assign a role to every party for every activity.
- Flag the ambiguous ones — anything where a vendor derives its own value from the data — and resolve them in writing.
- Score your contracts against the checklist above and prioritise the vendors touching the highest-risk data.
- Align breach clauses so vendor timelines are strictly shorter than your own 72-hour clock. See Data Breach Compliance Under the DPDP Act.
- Brief the business, because sales and product teams sign data-sharing arrangements that legal never sees.
For more explainers on Indian compliance, visit Correct Learn, or work through the phased programme in our DPDP compliance roadmap.
References
- Gazette of India — The Digital Personal Data Protection Act, 2023 — Sections 2(i), 2(k), 8 and 10, and the Schedule of penalties.
- Digital Personal Data Protection Rules, 2025 — notified text — Rule 6 security safeguards and Rule 13 obligations of Significant Data Fiduciaries.
- MeitY — Explanatory Note to the DPDP Rules, 2025 — Official commentary on fiduciary duties and processor arrangements.
- Ministry of Electronics and Information Technology — Nodal ministry notifications and policy documents.
- India Code — Consolidated statutory text with commencement details.
- Gazette of India portal — G.S.R. 843(E) and G.S.R. 846(E) dated 13 November 2025.
- Press Information Bureau — Official releases on the DPDP framework and its implementation timeline.
Frequently asked questions
- What is the difference between a Data Fiduciary and a Data Processor?
- A Data Fiduciary (Section 2(i)) determines the purpose and means of processing personal data. A Data Processor (Section 2(k)) processes personal data only on behalf of a Data Fiduciary. The fiduciary decides why and how; the processor executes within those instructions.
- Can a Data Processor be penalised directly under the DPDP Act?
- The Act places accountability on the Data Fiduciary under Section 8(1), irrespective of any agreement to the contrary. A processor that steps outside instructions and starts determining purposes becomes a fiduciary for that processing and carries fiduciary liability, including exposure under the Schedule.
- Does the DPDP Act require a written contract with processors?
- Yes. Section 8(2) permits a Data Fiduciary to engage a Data Processor for activities related to offering goods or services only under a valid contract. Rule 6(1) further requires appropriate contractual provisions for reasonable security safeguards.
- Is a cloud provider a Data Fiduciary or a Data Processor?
- Usually a processor for customer data hosted on its infrastructure, because the customer decides purpose and means. The same provider is a fiduciary for its own account, billing and telemetry data, where it decides those purposes itself. Classification is per processing activity, not per company.