General obligations of Data Fiduciary
A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.
A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.
Where personal data processed by a Data Fiduciary is likely to be used to make a decision that affects the Data Principal, or disclosed to another Data Fiduciary, the Data Fiduciary shall ensure its completeness, accuracy and consistency.
A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder.
A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed.
A Data Fiduciary shall, unless retention is necessary for compliance with any law, erase personal data upon the Data Principal withdrawing consent or as soon as it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and shall cause its Data Processor to erase any personal data made available to it for processing.
A Data Fiduciary shall publish the business contact information of a Data Protection Officer, if applicable, or a person able to answer questions raised by the Data Principal about processing of her personal data.
A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals.
- This is the section carrying the most operational weight. Liability sits with the Fiduciary — you cannot contract it away, and a Data Principal's own failure to comply with their duties doesn't excuse you.
- A valid, binding contract is mandatory before you can use any Data Processor for goods/services related processing.
- 'Reasonable security safeguards' is undefined in the Act itself — the Rules and prevailing industry practice fill that in.
- Breach intimation has two audiences: the Board and every affected individual — not a materiality-gated subset.
- Erasure obligations run on a 'purpose no longer served OR consent withdrawn, whichever is earlier' test, and must cascade to processors.
Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact wording against the official Gazette of India before relying on this for legal or compliance decisions.