Legal Roles

Fiduciary vs Processor vs SDF

The DPDP Act assigns specific legal labels to entities based on how they handle data. Your obligations—and your potential fines—depend entirely on which category you fall into.

Data Fiduciary

Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.

Example

An E-commerce company collecting customer emails to sell shoes.

Key Obligations

  • Must obtain consent and provide Notice.
  • Responsible for protecting the data.
  • Must establish a grievance redressal mechanism.
  • Fully liable for any breaches, even if caused by their processor.

Data Processor

Any person who processes personal data on behalf of a Data Fiduciary.

Example

A cloud hosting provider (AWS) or a third-party payroll agency processing the E-commerce company's data.

Key Obligations

  • The DPDP Act imposes no direct obligations on Data Processors.
  • They are governed entirely by the contract (Data Processing Agreement) they sign with the Fiduciary.
  • Cannot process data for their own purposes.

Significant Data Fiduciary (SDF)

A subset of Data Fiduciaries notified by the Central Government based on the volume and sensitivity of data processed, risk to democracy, etc.

Example

Large social media platforms, major banks, or massive telecom operators.

Extra Obligations

  • Must appoint a Data Protection Officer (DPO) based in India.
  • Must appoint an Independent Data Auditor.
  • Must conduct periodic Data Protection Impact Assessments (DPIA).

Who is the Data Principal?

The Data Principal is the individual to whom the personal data relates. In the context of children or persons with disabilities, it includes their parents or lawful guardians. The entire Act is designed to protect the rights of the Data Principal.

Consent Manager

A new class of entity introduced by the DPDP Act. A Consent Manager is an entity registered with the Board that acts as a single point of contact to enable a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform.

Data Protection Board (DPB)

The regulatory body established by the Central Government under this Act. The DPB functions as a digital office to direct data fiduciaries in the event of a breach, conduct inquiries, and impose massive financial penalties for non-compliance.