If Data Principals get rights, Data Fiduciaries get the matching list of duties. Here’s the baseline every one of them carries.
THE BASELINE DUTIES
ACCURACY & SECURITY
Keep data correct and safe
Reasonable security safeguards are a standing duty, not a one-time setup task.
BREACH RESPONSE
Notify when things go wrong
The Board, and affected individuals, have to be told when a breach happens.
ERASURE
Delete when the purpose ends
Data doesn’t get to sit around indefinitely once it’s no longer needed for what it was collected for.
These duties apply even when a Fiduciary uses outside vendors to do the actual processing. Handing data to a processor doesn’t hand off the responsibility — the Fiduciary stays on the hook for what happens to it, which is why contracts with processors matter as much as internal policy does.
Common misconception — That using a third-party vendor or processor shifts legal responsibility onto them. It doesn’t — the Data Fiduciary remains accountable for what its processors do with the data.
The duties follow the data, not just the desk it currently sits on.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdfÂ