Under the DPDP Act 2023, a Data Fiduciary decides the purpose and means of processing personal data and carries the primary obligations; a Data Processor processes data on the Fiduciary's behalf and is bound by contract. Many organisations are both, depending on the dataset. Knowing your role for a given activity determines which obligations apply. This checker classifies your role and lists the duties that follow.
Find out whether you are a Data Fiduciary, a Data Processor, or both — and what each role requires.
The DPDP Act assigns most obligations to the Data Fiduciary — the party that decides why and how data is processed — while the Data Processor is bound mainly by its contract with the Fiduciary. Getting the classification wrong means applying the wrong obligations and mis-allocating risk in contracts.
Most organisations are Fiduciaries for their own customer and employee data, and may also be Processors when they handle data for clients. Classify per activity, not per company.
A guide to Fiduciary vs Processor classification with the full obligation list for each role.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.