A Data Fiduciary is responsible for complying with the Act in respect of any processing it undertakes, whether it does the processing itself or through a Data Processor on its behalf.
It must make reasonable efforts to ensure that personal data it processes is complete, accurate and consistent where the data is used to make a decision affecting the person, or is disclosed to another Data Fiduciary.
It must protect personal data in its possession or control by taking reasonable security safeguards to prevent a breach, and must notify the Board and each affected person of a breach.
It must erase personal data once consent is withdrawn or the specified purpose is no longer being served, unless retention is required by law, and must publish the business contact information of a Data Protection Officer or the person who answers questions about processing.
On failure
Schedule penalties. Failure to take reasonable security safeguards and failure to notify a breach are separately penalised under the Schedule.
Where people go wrong
Treating a processor arrangement as a transfer of responsibility. The obligation stays with the fiduciary.
Keeping data because it might be useful later. The section requires erasure once the purpose is served, unless a law requires retention.
Publishing a generic support address with nobody behind it. The contact has to be able to answer questions about processing.
Assuming small businesses are outside the Act. The obligations attach to the processing, not to the size of the business.
Common questions
What are the obligations of a Data Fiduciary under the DPDP Act?
Section 8 requires accuracy where data drives decisions or is shared, reasonable security safeguards, notification of a breach to the Board and to affected people, erasure once consent is withdrawn or the purpose is served, and a published contact for questions about processing.
Who is responsible when a vendor processes the data?
The Data Fiduciary. Section 8(1) makes it responsible for compliance in respect of processing undertaken by a Data Processor on its behalf, which is why the contract with the processor matters.
When does personal data have to be erased?
When consent is withdrawn or as soon as the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with a law in force.
A plain-English summary of what this provision requires, not a reproduction of it and not legal advice. Read alongside the bare Act, and take advice on anything turning on your own facts.