Data Fiduciary obligations
Section 8 and operational Rules 6–9 are scheduled for 13 May 2027.
The Data Fiduciary remains responsible for processing undertaken by it or on its behalf. The product control is therefore attached to the accountable legal entity, not merely to the technical system or vendor.
Section 8 operating map
Section titled “Section 8 operating map”| Obligation | Operational control | Evidence |
|---|---|---|
| comply irrespective of Principal agreement/default | source-linked control plan | applicability approval |
| processor only under valid contract | instruction and contract register | executed clause map |
| ensure completeness, accuracy, consistency for decisions/disclosure | data-quality checkpoint | test and remediation |
| technical and organisational measures | control baseline | owner attestation and tests |
| reasonable security safeguards | Rule 6 map | access, encryption, monitoring, continuity evidence |
| notify breach | multi-regime incident case | notices and receipts |
| erase on withdrawal/purpose end unless law requires retention | retention, hold, disposal | decision and certificate |
| publish business contact | monitored contact directory | publication snapshot |
| grievance mechanism | case route and published period | acknowledgement and resolution |
Processor contracting
Section titled “Processor contracting”The processor record cannot be approved without:
- service and instruction scope;
- data and Data Principal categories;
- allowed systems, purposes and locations;
- confidentiality, access and safeguard requirements;
- incident detection and propagation;
- subprocessor approval and change notice;
- assistance with rights, retention, deletion and evidence;
- audit/regulator access where applicable;
- return/export/deletion and independent assurance at exit;
- survival, records and conflict terms.
Sector overlays may require board approval, materiality assessment, regulator access, India storage or prescribed incident reporting.
Data quality
Section titled “Data quality”The elevated accuracy/completeness/consistency duty is tied to data likely to be used for a decision affecting the Principal or disclosed to another Fiduciary. OpenDPDP identifies critical fields and systems of record, requires a pre-decision/disclosure check, and routes correction to downstream copies. It does not promise universal truth or overwrite source systems.
Contact and grievance
Section titled “Contact and grievance”Rule 9 requires publication of business contact information for a person able to answer questions about processing. The contact must be entity-specific, current and monitored. A no-reply address or generic chatbot without escalation is insufficient product design.
Control ownership
Section titled “Control ownership”| Control | Accountable | Responsible |
|---|---|---|
| purpose and role | business/data owner | privacy admin |
| processor contract | legal/procurement | processor manager |
| safeguards | CISO | system owner |
| breach decision | Data Fiduciary/DPO | incident commander |
| erasure exception | legal reviewer | records/system owners |
| contact/grievance | DPO/privacy leader | support operations |
Failure rules
Section titled “Failure rules”- An expired processor contract blocks new instructions but does not silently delete evidence.
- Missing quality evidence blocks the affected decision/disclosure integration, not unrelated processing.
- An unreachable published contact raises an operational alert and opens a remediation case.
- A processor deletion failure remains visible, escalates and is excluded from a “complete” certificate.