Working with Data Processors: Roles and Responsibilities

Almost every organisation uses vendors that touch personal data — cloud hosting, payment processing, customer support tools. Here’s how the Act treats that relationship.

FIDUCIARY AND PROCESSOR, SIDE BY SIDE

DATA FIDUCIARY

Carries the Act's obligations

Decides why and how data is processed, and answers to the Board if something goes wrong.

DATA PROCESSOR

Acts only on instruction

No direct statutory duties under the Act — bound instead by a contract with the Fiduciary.

THE CONTRACT

Where responsibility actually gets defined

Security expectations, breach duties, and cooperation on rights requests all need to be written in.

This means the contract itself carries real weight — it’s the mechanism that makes a processor’s conduct enforceable at all, since the Act doesn’t reach the processor directly the way it reaches the Fiduciary. A vague or missing data processing agreement is a real gap, not a formality.

Common misconception — That processors carry their own direct obligations under the DPDP Act, similar to Fiduciaries. They don’t — the Fiduciary stays accountable and has to manage the relationship through contract.

Outsourcing the processing never outsources the accountability. That stays with the Data Fiduciary.

SOURCES  The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.