Five terms do almost all the work in the DPDP Act. Once you know who’s who, everything else in this series gets easier to follow.
Role
- Data Principal
- Data Fiduciary
- Data Processor
- Significant Data Fiduciary (SDF)
- Consent Manager
In plain terms
- The individual the data is about. In most sentences in this series, that's simply “you.”
- Whoever decides why and how personal data gets processed — usually the organisation collecting it.
- A Fiduciary the government designates for extra duties, based on the volume or sensitivity of data it handles.
- A registered intermediary that lets you give, review and withdraw consent across multiple Fiduciaries from one place.
Notice what’s missing from this list: the Data Processor doesn’t carry direct obligations under the Act the way a Fiduciary does. That’s deliberate the Fiduciary is the one accountable, even for what its processors do on its behalf. Everything about who owes what to whom traces back to this one distinction.
Common misconception — That “Data Fiduciary” isn’t just a fancy word for “Organisations”. It specifically means whoever decides the purpose and means of processing — which can be one team within a larger organisation, not the whole entity.
Learn these five roles once, and the rest of the DPDP Act reads like a set of relationships, not a wall of jargon.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf