DPDP NavigatorAct 2023 · Rules 2025
The DPDP Act/Chapter II/Section 8
Section 8Obligations of Data Fiduciary

General obligations of Data Fiduciary

Official statutory text · Gazette of India
Plain-language explanation
  • This is the section carrying the most operational weight. Liability sits with the Fiduciary — you cannot contract it away, and a Data Principal's own failure to comply with their duties doesn't excuse you.
  • A valid, binding contract is mandatory before you can use any Data Processor for goods/services related processing.
  • 'Reasonable security safeguards' is undefined in the Act itself — the Rules and prevailing industry practice fill that in.
  • Breach intimation has two audiences: the Board and every affected individual — not a materiality-gated subset.
  • Erasure obligations run on a 'purpose no longer served OR consent withdrawn, whichever is earlier' test, and must cascade to processors.

Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact wording against the official Gazette of India before relying on this for legal or compliance decisions.