Data Fiduciary
Definition
The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing personal data, equivalent to the GDPR term 'controller'. Data Fiduciaries carry the breach notification obligation under the DPDP Act.
- Source law
- India Digital Personal Data Protection Act 2023
- GDPR equivalent
- Controller
- Key obligation
- Breach notification duty
- Determines
- Purpose and means of processing
Common questions
How does a Data Fiduciary differ from a Data Processor under the DPDP Act?+
The Fiduciary decides why and how personal data is processed and bears the compliance obligations, while a processor acts only on the Fiduciary's instructions. The DPDP Act places most statutory duties, including breach notification, on the Fiduciary rather than any processor it engages.
Does the DPDP Act use the term controller at all?+
No. It deliberately adopts its own vocabulary, Data Fiduciary and Data Principal, rather than the GDPR's controller and data subject, though the underlying roles map closely onto each other for comparative purposes.
Related terms
- Consent Notice
- A notice that must be provided to the data principal before or at the time of requesting consent. It must be clear,...
- Covered Entity / Business Associate
- Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
- Data Principal
- The individual to whom the personal data relates. Equivalent to the data subject under GDPR. The DPDP Act grants data principals rights...
- Data Processor
- An entity that processes personal data on behalf of a data fiduciary, under the fiduciary's instructions. Equivalent to the data processor under...
- Data Protection Board of India (DPBI)
- The adjudicatory body established by the DPDP Act to receive complaints, investigate breaches of the Act, and impose penalties. The Board operates...
- Notification Trigger
- The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
- Personal Data Breach
- Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
- Safe Harbour (Encryption)
- A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
- Significant Data Fiduciary (SDF)
- A data fiduciary designated by the central government as carrying elevated risk based on data volume, sensitivity, national security considerations, or impact...
- Supervisory Authority
- The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...
Explained in these topics
- Breach Notification Laws and Obligations
- India's Digital Personal Data Protection Act 2023Any person or entity that determines the purpose and means of processing personal data. Equivalent to the data controller under GDPR. Data fiduciaries bear the...