Skip to content

Data Fiduciary

Definition

The term used in India's Digital Personal Data Protection Act 2023 for an entity that determines the purpose and means of processing personal data, equivalent to the GDPR term 'controller'. Data Fiduciaries carry the breach notification obligation under the DPDP Act.

Source law
India Digital Personal Data Protection Act 2023
GDPR equivalent
Controller
Key obligation
Breach notification duty
Determines
Purpose and means of processing

Common questions

How does a Data Fiduciary differ from a Data Processor under the DPDP Act?+

The Fiduciary decides why and how personal data is processed and bears the compliance obligations, while a processor acts only on the Fiduciary's instructions. The DPDP Act places most statutory duties, including breach notification, on the Fiduciary rather than any processor it engages.

Does the DPDP Act use the term controller at all?+

No. It deliberately adopts its own vocabulary, Data Fiduciary and Data Principal, rather than the GDPR's controller and data subject, though the underlying roles map closely onto each other for comparative purposes.

Related terms

Consent Notice
A notice that must be provided to the data principal before or at the time of requesting consent. It must be clear,...
Covered Entity / Business Associate
Terms used in the US HIPAA framework. Covered entities are healthcare providers, health plans, and healthcare clearinghouses. Business Associates are contractors that...
Data Principal
The individual to whom the personal data relates. Equivalent to the data subject under GDPR. The DPDP Act grants data principals rights...
Data Processor
An entity that processes personal data on behalf of a data fiduciary, under the fiduciary's instructions. Equivalent to the data processor under...
Data Protection Board of India (DPBI)
The adjudicatory body established by the DPDP Act to receive complaints, investigate breaches of the Act, and impose penalties. The Board operates...
Notification Trigger
The threshold condition that activates a legal notification obligation. Under GDPR the trigger is any personal data breach that poses a risk...
Personal Data Breach
Under GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal...
Safe Harbour (Encryption)
A provision in many breach notification frameworks that exempts organisations from individual notification obligations if the breached data was encrypted and the...
Significant Data Fiduciary (SDF)
A data fiduciary designated by the central government as carrying elevated risk based on data volume, sensitivity, national security considerations, or impact...
Supervisory Authority
The national data protection regulator responsible for enforcing GDPR in a given EU member state, such as the UK Information Commissioner's Office...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.