Skip to content

Data Fiduciary obligations

DPDP — not yet effective

Section 8 and operational Rules 6–9 are scheduled for 13 May 2027.

The Data Fiduciary remains responsible for processing undertaken by it or on its behalf. The product control is therefore attached to the accountable legal entity, not merely to the technical system or vendor.

ObligationOperational controlEvidence
comply irrespective of Principal agreement/defaultsource-linked control planapplicability approval
processor only under valid contractinstruction and contract registerexecuted clause map
ensure completeness, accuracy, consistency for decisions/disclosuredata-quality checkpointtest and remediation
technical and organisational measurescontrol baselineowner attestation and tests
reasonable security safeguardsRule 6 mapaccess, encryption, monitoring, continuity evidence
notify breachmulti-regime incident casenotices and receipts
erase on withdrawal/purpose end unless law requires retentionretention, hold, disposaldecision and certificate
publish business contactmonitored contact directorypublication snapshot
grievance mechanismcase route and published periodacknowledgement and resolution

The processor record cannot be approved without:

  • service and instruction scope;
  • data and Data Principal categories;
  • allowed systems, purposes and locations;
  • confidentiality, access and safeguard requirements;
  • incident detection and propagation;
  • subprocessor approval and change notice;
  • assistance with rights, retention, deletion and evidence;
  • audit/regulator access where applicable;
  • return/export/deletion and independent assurance at exit;
  • survival, records and conflict terms.

Sector overlays may require board approval, materiality assessment, regulator access, India storage or prescribed incident reporting.

The elevated accuracy/completeness/consistency duty is tied to data likely to be used for a decision affecting the Principal or disclosed to another Fiduciary. OpenDPDP identifies critical fields and systems of record, requires a pre-decision/disclosure check, and routes correction to downstream copies. It does not promise universal truth or overwrite source systems.

Rule 9 requires publication of business contact information for a person able to answer questions about processing. The contact must be entity-specific, current and monitored. A no-reply address or generic chatbot without escalation is insufficient product design.

ControlAccountableResponsible
purpose and rolebusiness/data ownerprivacy admin
processor contractlegal/procurementprocessor manager
safeguardsCISOsystem owner
breach decisionData Fiduciary/DPOincident commander
erasure exceptionlegal reviewerrecords/system owners
contact/grievanceDPO/privacy leadersupport operations
  • An expired processor contract blocks new instructions but does not silently delete evidence.
  • Missing quality evidence blocks the affected decision/disclosure integration, not unrelated processing.
  • An unreachable published contact raises an operational alert and opens a remediation case.
  • A processor deletion failure remains visible, escalates and is excluded from a “complete” certificate.