Data Fiduciary
Under the DPDP Act 2023, the person who determines the purpose and means of processing personal data — the Indian equivalent of a GDPR data controller.
A Data Fiduciary is defined in Section 2(i) of the Digital Personal Data Protection Act 2023 as "any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data." It is the term the Indian statute uses for what GDPR calls a data controller. Every organisation that decides why and how personal data is processed within its operations is a Data Fiduciary in relation to that processing.
The Data Fiduciary carries the primary obligations under the Act — obtaining consent (Section 6), providing notice (Section 5), enabling Data Principal rights (Sections 11–14), publishing the Data Protection Officer's or grievance officer's contact under Rule 12, and reporting personal data breaches to the Data Protection Board within 72 hours under Section 8(6) read with the DPDP Rules 2025.
Where a Data Fiduciary meets specified criteria — volume of data processed, sensitivity of data, risk to the electoral democracy or public order, or risk to Data Principal rights — the Central Government may notify it as a Significant Data Fiduciary under Section 10, triggering additional obligations including mandatory Data Protection Impact Assessments, periodic audits, and appointment of an India-based DPO.