The Act is deliberately one-sided about who’s on the hook when something goes wrong. Here’s why that’s the design, not an oversight.
WHERE ACCOUNTABILITY SITS
DATA FIDUCIARY
Carries the obligations
And faces the Board’s penalties if it falls short — this is where accountability lives under the Act.
DATA PROCESSOR
No direct statutory duties
Bound to the Fiduciary by contract instead, not by the Act itself.
DATA PRINCIPAL
Has a short list of duties too
Not to file false complaints or impersonate others — but breaching these doesn’t excuse the Fiduciary.
That last point is explicit in the Act: even if a Data Principal provides inaccurate information, that doesn’t reduce what the Data Fiduciary owes everyone else. The imbalance is intentional — Fiduciaries hold the technical expertise and the resources, so the accountability sits where the power does.
Common misconception — That if a Data Principal gave incorrect information, the Fiduciary is off the hook for related problems. The Act says explicitly that it isn’t.
Accountability under the DPDP Act sits with whoever has the power to actually prevent the harm — the Data Fiduciary.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdfÂ