DPDP Glossary
Data Fiduciary
Any person who alone or with others determines the purpose and means of processing of personal data.
Section 2(i)
What it means
Section 2(i) defines a Data Fiduciary as any person who alone or jointly determines the purpose and means of processing personal data. That decision-making role carries Section 8 general obligations — even when a Data Processor performs day-to-day operations under contract. Fiduciary status follows who decides purpose and means, not who hosts the largest engineering team or whose logo appears on the invoice.
Worked example
An Indian retailer that decides to collect purchase history for loyalty rewards is the Data Fiduciary for that purpose, even if a cloud vendor stores the database. The vendor processing on the retailer’s documented instructions is typically a Data Processor — the retailer remains accountable under Section 8 for compliance in respect of that processing, including security and breach intimation duties that attach to the Fiduciary.
In practice
Map who decides purpose and means in each vendor relationship. Own purpose catalogues, processor contracts, security, breach intimation, retention, public contact points and rights desks. Consent tooling can support purpose-linked consent records; it does not replace the full Section 8 programme or legal advice.
Source
Section 2(i) · Official text (PDF)
Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.