Six questions that settle whether India's DPDP Act makes your business a Data Fiduciary — and what changes the moment the answer is yes.
If your business decides *why* personal data gets collected and *how* it gets used, you are a Data Fiduciary under India's Digital Personal Data Protection Act. Not a technology company. Not a large company. Any company. If you hold a customer list, a candidate CV, or a WhatsApp enquiry thread, the role attaches to you.
The word "fiduciary" does the work here. It is borrowed from trust law, and it is doing exactly what it sounds like: the person handed you their data, and you are answerable for it.
Six questions settle whether the role is yours.
The six questions
Answer each one honestly. Not "what does our privacy policy say" — what actually happens on a Tuesday.
1. Do you collect anything that identifies a person? Name, phone, email, address, PAN, photograph, IP address, device ID, biometric data. Digitally collected, or collected on paper and later typed up. Both count.
2. Did you decide to collect it? This is the question that separates Fiduciary from Processor. If the decision to collect was yours — you designed the form, you set up the CRM, you asked for the CV — the purpose is yours, and so is the accountability.
3. Did you decide what it gets used for? Order fulfilment, payroll, marketing, credit assessment. If you set the purpose, you are a Fiduciary for that data.
4. Do you keep it after the immediate transaction? Retention creates obligations. A number written on a delivery slip and shredded that night is one thing; the same number sitting in a spreadsheet for four years is another.
5. Do you share it with anyone? Your accountant, cloud host, courier partner, email tool, marketing agency. Sharing does not transfer accountability. It adds a contract you probably do not have yet.
6. Are the people Indian, or in India? The Act reaches processing done outside India where it relates to offering goods or services to people in India. Where your servers live does not decide this. Where your customers live does.
Scoring is blunt: yes to questions 1, 2 and 3 makes you a Data Fiduciary. Questions 4 to 6 tell you how heavy the obligations run.
Fiduciary, Processor, Principal
Three roles, and people mix them up constantly.
| Role | Who it is | What it means |
|---|---|---|
| Data Principal | The individual the data is about | Your customer, employee, candidate, supplier contact |
| Data Fiduciary | Whoever decides why and how data is processed | Almost certainly you |
| Data Processor | Whoever processes it on the Fiduciary's instructions | Your cloud host, payroll vendor, email platform |
| Significant Data Fiduciary | A Fiduciary the government designates | Extra duties: DPO in India, audits, impact assessments |
The pattern to hold on to: a Processor takes instructions, a Fiduciary gives them. If nobody instructed you and you decided on your own, you are the Fiduciary.
The awkward corollary is that most SMEs are both, at once, for different data. You are a Fiduciary for your employees' payroll and a Processor for the client files you were hired to work on. It is decided dataset by dataset, not by what your company does for a living.
Where SMEs get the answer wrong
"We don't have a database, just Excel." Format is irrelevant. A spreadsheet on a laptop is digital personal data. So is a WhatsApp Business chat list, a Tally ledger with buyer details, and a stack of visiting cards someone typed into Google Sheets.
"We're B2B, we don't hold consumer data." Your B2B contact is a person with a name and a mobile number. The Act protects individuals, not consumers as a market segment. B2B businesses are covered exactly the same.
"We're too small for this." There is no turnover threshold and no headcount threshold in the Act. What scales with size is *how* you discharge the duties, and whether you get designated a Significant Data Fiduciary. The core duties — notice, purpose limitation, security, breach reporting, erasure, honouring rights — do not have a small-business off switch.
"Our vendor is ISO-certified, so we're covered." Your vendor's certificate is evidence about your vendor. It is not a processing agreement, and it does not move accountability off you.
So you're a Fiduciary. What now?
Seven duties attach. In plain terms:
- Give notice before you collect. Standalone, plain language, stating what you collect, the specific purpose, how to withdraw consent, and how to complain to the Board.
- Stick to the stated purpose. A number collected to deliver an order cannot become a marketing list without fresh consent.
- Secure it. Encryption or equivalent, access controls, logs, backups, and the same obligations passed down to your processors in writing.
- Report breaches. Affected individuals in plain language, and the Data Protection Board within 72 hours.
- Erase what you no longer need. When the purpose is served or consent is withdrawn, unless another law makes you keep it. Processing logs are retained for at least a year.
- Answer rights requests. Access, correction, erasure, nomination. Publish a route for people to ask, and respond within 90 days.
- Handle children's data separately. Verifiable parental consent, no behavioural advertising, no tracking, with narrow exemptions.
Start with the data inventory — a single spreadsheet listing every place personal data lives, what it is, why you have it, who can see it, and how long you keep it. Every other duty depends on knowing that, and it is the step teams keep postponing because it is boring rather than hard.
Where CapEasy fits
We run the inventory with SMEs, close the gaps it exposes, and put the notices, processing agreements and breach playbooks in place — sized for a company with a small team and no in-house counsel.
Pramaan, our DPDP platform, is built for Data Fiduciaries: it maps what you hold, tracks consent and data-principal requests, and keeps the audit trail that becomes your evidence if the Board ever asks. *(Pramaan is a compliance tool for Data Fiduciaries. It is not a registered Consent Manager under the DPDP Rules.)*
This article is general information, not legal advice. Regulations change and interpretations evolve. Verify against the current Gazette notification or consult a qualified professional before acting.
Frequently asked questions
Can a business be both a Data Fiduciary and a Data Processor?
Yes, and it is common. You are a Data Fiduciary for your own customer and employee data, and a Data Processor for data a client hands you to work on. A bookkeeping firm is a Fiduciary for its own staff records and a Processor for its clients' ledgers. The roles are decided per dataset, not per company.
Does the DPDP Act apply if we only handle business contact details?
Yes. A procurement manager's name, work email and phone number identify a living individual, so they are personal data. The Act protects individuals, and it does not carve out people you met in a professional capacity.
We are a sole proprietorship. Are we still covered?
Yes. The Act attaches to whoever determines the purpose and means of processing, whatever the legal form. A proprietorship with a customer WhatsApp list is a Data Fiduciary.
What is a Significant Data Fiduciary?
A category the Central Government designates based on factors like volume and sensitivity of data and risk to electoral democracy or public order. Designated entities carry extra duties: a Data Protection Officer based in India, independent data audits, and periodic impact assessments. You do not opt in, and most SMEs will not be designated.
Our data sits with vendors. Are they the Fiduciary instead of us?
No. If you decided to collect the data and why, you are the Fiduciary and they are your Processors. The Data Protection Board holds you accountable for what they do on your instructions, which is why a written processing agreement matters.
When do these duties actually start being enforced?
The DPDP Rules were notified on 13 November 2025 and the substantive obligations become enforceable in May 2027. The Data Protection Board is already constituted and can receive complaints, so the runway is for building compliance, not for ignoring it.

