Data Fiduciary or Data Processor? Getting DPDP Roles Right in Your Contracts
The data fiduciary decides why and how personal data is processed; the processor only acts on instructions. Labelling the wrong party in a contract misallocates every obligation that follows from the role.
Almost every data protection obligation attaches to a role, so the first question any contract has to answer is which role each party occupies. Indian contracts frequently leave that unstated, which means the obligations are unallocated rather than allocated conveniently.
Key takeaways
- A data fiduciary determines the purpose and means of processing personal data.
- A data processor processes on behalf of a fiduciary.
- The same company can be a fiduciary for some data and a processor for other data.
- The Act contemplates a fiduciary binding its processor by contract.
- Contracts predating November 2025 rarely name the roles at all.
The distinction
Under the Digital Personal Data Protection Act, 2023, a data fiduciary is the person who alone or with others determines the purpose and means of processing personal data. A data processor processes personal data on behalf of a fiduciary.
The test is decision-making rather than possession. A vendor holding a large volume of your customer records is a processor if you decide what happens to them and the vendor acts on your instructions. A vendor deciding for its own purposes what to do with data it holds is acting as a fiduciary in respect of that processing, whatever the contract calls it.
Why one company can be both
Take a payroll provider. In respect of your employee data, processed to run your payroll on your instructions, it is a processor and you are the fiduciary. In respect of its own customer relationship with you, including the contact details of your finance team and its own billing records, it decides purposes and means and is a fiduciary.
This is why a single sentence stating that the vendor is a processor is usually inaccurate. Well-drafted terms allocate roles by category of data and activity rather than making one blanket statement, and that granularity is what makes the rest of the clause work.
What follows from the allocation
- The fiduciary is answerable for the personal data it is responsible for, including where a processor carries out the processing.
- A processor should be permitted to process only for the stated purposes and on the fiduciary instructions.
- Security obligations and breach notification need to run from the processor to the fiduciary with a workable timeline.
- Sub-processing needs to be addressed, since most vendors use infrastructure providers of their own.
- Deletion or return on termination, and assistance with data principal requests, belong to the processor obligations.
The clause that is usually missing
Contracts signed before the Rules were notified in November 2025 typically contain a confidentiality clause, sometimes a security schedule, and no allocation of data protection roles at all. Confidentiality and data protection are related but not the same: a confidentiality clause governs disclosure, while the data protection framework governs purpose, security, retention, transfer and the rights of the individual.
The practical fix for existing contracts is a data processing addendum, which most enterprise vendors now have as a standard document because their other customers have asked. For new contracts it belongs in the negotiation rather than as a later amendment.
Getting it right in your own paperwork
Start by mapping which vendors receive personal data and what they do with it, then allocate roles per category rather than per vendor. Where a vendor insists it is a processor for everything, ask what it does with usage and telemetry data, which is frequently where its own purposes appear.
Where the allocation is genuinely unclear, that is a question for advice rather than a drafting preference. Getting it wrong does not just misdescribe the arrangement; it puts obligations on the party that is not in a position to discharge them.
Have a contract in front of you?
Upload it and get every clause checked against Indian law, with the provision each finding rests on.
Review your saas & vendor contractCommon questions
Our vendor says it is a processor for everything. Is that right?
It is often an oversimplification. Most vendors decide purposes and means for at least some processing, such as their own analytics, telemetry or billing records. Asking specifically what they do with usage data usually surfaces where their own purposes begin.
Do we need a separate data processing addendum, or can it go in the main agreement?
Either works. A separate addendum is common because vendors maintain a standard version and it can be updated without reopening the commercial terms. What matters is that the roles, purposes, security, sub-processing, deletion and transfer terms are addressed somewhere binding.
Related guides
This article is general information about Indian law as of 2026-07-26, not legal advice, and reading it does not create an advocate–client relationship. Statutes and rules change, particularly under the Labour Codes where State rules are still being notified. Consult a qualified advocate about your own situation.