What the Act Expects of a Data Fiduciary

If Data Principals get rights, Data Fiduciaries get the matching list of duties. Here’s the baseline every one of them carries.

THE BASELINE DUTIES

ACCURACY & SECURITY

Keep data correct and safe

Reasonable security safeguards are a standing duty, not a one-time setup task.

BREACH RESPONSE

Notify when things go wrong

The Board, and affected individuals, have to be told when a breach happens.

ERASURE

Delete when the purpose ends

Data doesn’t get to sit around indefinitely once it’s no longer needed for what it was collected for.
These duties apply even when a Fiduciary uses outside vendors to do the actual processing. Handing data to a processor doesn’t hand off the responsibility — the Fiduciary stays on the hook for what happens to it, which is why contracts with processors matter as much as internal policy does.
Common misconception — That using a third-party vendor or processor shifts legal responsibility onto them. It doesn’t — the Data Fiduciary remains accountable for what its processors do with the data.

The duties follow the data, not just the desk it currently sits on.

SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf 

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.