On this page
The DPDP Act sorts everyone who touches personal data into a few roles, and almost every duty in it is tied to one of them. Knowing which role you play is the first step to knowing what you owe. The roles are defined by what a person does with the data, not by size, sector or what the person calls itself.
The three roles side by side
| Role | In plain words |
|---|---|
| Data Fiduciary | Any person who, alone or with others, decides why and how personal data is processed. |
| Data Processor | Any person who processes personal data on behalf of a Data Fiduciary. |
| Data Principal | The individual the personal data is about. For a child, this includes the parents or lawful guardian. For a person with disability, it includes her lawful guardian acting on her behalf. |
Two further roles appear in many articles on this site:
| Role | In plain words |
|---|---|
| Significant Data Fiduciary | A Data Fiduciary, or a class of them, that the Central Government notifies because of factors such as the volume and sensitivity of the data it processes and the risk to people’s rights. |
| Consent Manager | A person registered with the Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent on an interoperable platform. |
Who counts as a “person”
The Act’s word “person” is wide. It includes an individual, a Hindu undivided family, a company, a firm, an association of persons or a body of individuals (incorporated or not), the State, and any other artificial juristic person. So an individual, a company and a firm can all be Data Fiduciaries. The Act does not apply to personal data an individual processes for a personal or domestic purpose.
What “personal data” and “processing” mean
Personal data is any data about an individual who is identifiable by or in relation to that data. Processing is a wholly or partly automated operation, or set of operations, on digital personal data. The Act’s list of examples includes collection, recording, storage, use, sharing, disclosure, restriction, erasure and destruction. A role therefore attaches as soon as you do any of these things with digital personal data of individuals.

How to tell Fiduciary from Processor
Ask who decides the purpose and the means. The Fiduciary decides. The Processor acts on the Fiduciary’s behalf. The Act gives one example: a telecom service provider hires a company to email telephone bills to its customers. The telecom provider is the Data Fiduciary and the emailing company is the Data Processor. The Rules give another: a company engages a cloud service provider to host customer records, and the cloud provider is the company’s Data Processor.
The definitions turn on what a person does with the data, not on a label in a contract. The same company can therefore be a Data Fiduciary for some data and a Data Processor for other data.
What follows for each role
- Data Fiduciary. Carries the duties, among them: a lawful purpose, notice and consent, accuracy, security safeguards, breach intimation, erasure, a published contact, and a grievance process. It is responsible for complying with the Act for processing it does itself or that a Data Processor does on its behalf, whatever the contract says.
- Data Processor. A Fiduciary may engage one for activities connected with offering goods or services to people only under a valid contract. The Fiduciary must cause its processors to stop processing when a person withdraws consent, unless the law requires or authorises it, and to erase data when erasure is due. See processors and vendors.
- Data Principal. Holds the rights: access, correction and erasure, grievance redressal and nomination, and has duties too, such as not impersonating another person or filing a false complaint. See rights and the 90-day limit.
- Significant Data Fiduciary. Carries extra duties once notified, among them: a Data Protection Officer based in India, an independent data auditor, a periodic impact assessment and audits.
The definitions have applied since 13 November 2025. The duties apply from 13 May 2027 (counted from 13 November 2025).
The child rule
The Act defines a child as an individual who has not completed eighteen years. For a child, the Data Principal includes the parents or lawful guardian, and a Fiduciary must obtain the verifiable consent of the parent, subject to the exemptions in the Fourth Schedule to the Rules, before processing a child’s personal data. Children’s data under the Act covers the consent test, the tracking ban and every exemption.
Check your own role
List each activity in which you handle personal data. For each, write down who decides why the data is used and who else touches it. That gives you a Fiduciary list, a Processor list and the vendors you must contract with. The processing map walks through this by the tools you use, and the applicability article covers the scope questions that come before it.
Common questions
What is a Data Fiduciary?
Any person who, alone or with others, decides why and how personal data is processed.
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides the purpose and means of processing. A Data Processor processes personal data on its behalf. The Data Fiduciary remains responsible for complying with the Act for processing done on its behalf, whatever the contract says.
Who is a Data Principal?
The individual the personal data is about. For a child, that includes the parents or lawful guardian. For a person with disability, it includes her lawful guardian acting on her behalf.
Can an individual or a small business be a Data Fiduciary?
Yes. The Act’s word person includes an individual, a company, a firm and a Hindu undivided family. The Act does not apply to personal data an individual processes for a personal or domestic purpose.
Who counts as a child?
An individual who has not completed eighteen years.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 03: Know your data, in the toolkit
- How-to 09: Control your vendors, in the toolkit
- The free duties list, every duty in plain words
In the news
- Third-Party Data Processors And Privacy Compliance: Emerging Risks Under Digital Personal Data Protection Act, 2023
Shows how the role split plays out with vendors such as cloud, CRM and payroll providers.
- What are the Digital Personal Data Protection Rules and when do they apply?
Newspaper explainer on the Rules and when they apply, for readers new to these terms.
- First DPDP challenge: Knowing where your personal data lives
A practical view on finding where personal data sits, which comes before assigning roles.
Sources
Every section, rule and date above was checked against the official text on 5 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 2(f)Child
- Section 2(g)Consent Manager
- Section 2(i)Data Fiduciary
- Section 2(j)Data Principal
- Section 2(k)Data Processor
- Section 2(s)Person
- Section 2(t)Personal data
- Section 2(x)Processing
- Section 2(z)Significant Data Fiduciary
- Section 3(c)Personal or domestic purpose is excluded
- Section 6(6)Illustration: a telecom provider and the Data Processor that emails its bills
- Section 8(1)Responsible for processing by a Data Processor, whatever the agreement
- Section 8(2)Processor engaged for offering goods or services: only under a valid contract
- Section 9(1)Verifiable consent of a parent or lawful guardian
- Section 10(1), 10(2)Significant Data Fiduciary: Data Protection Officer, data auditor, impact assessment, audit
- Section 15Duties of Data Principals
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 8(3)Illustration: a company and its cloud service provider as Data Processor
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


