Almost every organisation uses vendors that touch personal data — cloud hosting, payment processing, customer support tools. Here’s how the Act treats that relationship.
FIDUCIARY AND PROCESSOR, SIDE BY SIDE
DATA FIDUCIARY
Carries the Act's obligations
Decides why and how data is processed, and answers to the Board if something goes wrong.
DATA PROCESSOR
Acts only on instruction
No direct statutory duties under the Act — bound instead by a contract with the Fiduciary.
THE CONTRACT
Where responsibility actually gets defined
Security expectations, breach duties, and cooperation on rights requests all need to be written in.
This means the contract itself carries real weight — it’s the mechanism that makes a processor’s conduct enforceable at all, since the Act doesn’t reach the processor directly the way it reaches the Fiduciary. A vague or missing data processing agreement is a real gap, not a formality.
Common misconception — That processors carry their own direct obligations under the DPDP Act, similar to Fiduciaries. They don’t — the Fiduciary stays accountable and has to manage the relationship through contract.
Outsourcing the processing never outsources the accountability. That stays with the Data Fiduciary.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf