Compliance

What Indian Data Fiducaries Must Do Under DPDP Act Section 8

Failure to meet these duties can attract scheduled penalties, including fines for inadequate security and for not reporting breaches, making non‑compliance a costly risk for small businesses.

Check your DPDP readiness — free More on the blog

What Indian Data Fiducaries Must Do Under DPDP Act Section 8

Section 8 of the Digital Personal Data Protection Act places the onus on any entity that decides to collect, store or use personal data, termed a Data Fiduciary. Whether the data is processed in‑house or by a third‑party processor, the fiduciary remains fully responsible for complying with the Act’s requirements. This means that delegating work does not delegate liability, and the business must ensure its contracts reflect this responsibility.

Ensuring Accuracy When Data Drives Decisions

The law obliges the fiduciary to make reasonable efforts to keep personal data complete, accurate and consistent, especially when that data influences a decision about the individual or is shared with another fiduciary. In practice, this requires regular data audits, validation checks and updating records promptly when errors are identified, to avoid decisions based on stale or incorrect information.

Reasonable Security Safeguards and Breach Reporting

A fiduciary must put in place reasonable technical and organisational measures to protect data from unauthorised access, loss or disclosure. If a breach occurs, the fiduciary must inform the Data Protection Board and each affected person without undue delay. The schedule of penalties imposes separate fines for lacking adequate safeguards and for failing to notify, making both aspects financially significant.

  • Encrypt data at rest and in transit
  • Implement role‑based access controls
  • Conduct periodic vulnerability assessments
  • Maintain an incident response plan

Obligation to Erase Data When Purpose Ends

When an individual withdraws consent or the specific purpose for which the data was collected is no longer being served, the fiduciary must delete the data promptly, unless another law mandates retention. Retaining data merely because it might be useful later breaches the Act and can trigger penalties, so businesses need clear retention schedules linked to legal requirements.

Publishing a Dedicated Grievance Contact

The Act requires the fiduciary to publish the contact details of a Data Protection Officer or another person who can answer queries about data processing. A generic email address without a responsible individual does not satisfy this requirement. The contact point must be reachable and capable of addressing data‑related grievances, otherwise the business risks non‑compliance. Small enterprises often assume the Act does not apply to them, but the obligations arise from the act of processing personal data, not from turnover or employee count. Therefore, any Indian business handling personal data must align its practices with Section 8, or face the schedule‑based fines that the law prescribes.

Common questions

What are the key duties of a Data Fiduciary under Section 8?

A Data Fiduciary must ensure data accuracy when it influences decisions or is shared, implement reasonable security safeguards, report any breach to the Board and affected individuals, erase data once consent is withdrawn or the purpose ends (unless law requires retention), and publish a contact who can answer processing queries.

Who is liable if a third‑party vendor processes my customers' data?

Liability remains with the Data Fiduciary. Even if a vendor processes data on the business’s behalf, the fiduciary must ensure the vendor complies with the Act, as Section 8 makes the fiduciary responsible for all processing activities.

When must I delete personal data to avoid penalties?

Data must be erased as soon as the individual withdraws consent or when the original purpose for collecting the data is fulfilled, whichever occurs first, unless a separate law requires the data to be retained for a specific period.

What happens if I fail to report a data breach?

Failure to notify the Data Protection Board and affected persons triggers a separate penalty under the schedule of fines. The breach reporting obligation is distinct from the security safeguard requirement, and non‑compliance can lead to substantial monetary penalties.

Related reading

  • Understanding the Writing Requirement for Arbitration Agreements — Section 7 of the Arbitration and Conciliation Act mandates that arbitration agreements be in writing, and a mere venue clause does not satisfy the requirement, costing businesses delays and extra litigation if ignored
  • Cost of Ignoring Internal Committee Rules Under POSH Act — Failing to set up an Internal Committee or file the required annual report can attract a fine of up to fifty thousand rupees and, on repeat, double the penalty plus possible licence cancellation, threatening a small business’s ability to operate.
  • Understanding Section 73 Compensation for Breach of Contract — Section 73 limits recoverable damages to losses that naturally flow from a breach or were foreseen by the parties, excluding remote or indirect losses and reducing awards where the injured party failed to mitigate.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this