The DPDPA concentrates responsibility ruthlessly: one role, the data fiduciary, owns every duty, and delegation buys nothing. Your cloud provider mishandles the data, you answer. Your consent vendor botches the notice, you answer. That design, plus a second tier of designated Significant Data Fiduciaries with governance duties bolted on, makes role-mapping the first exercise in any India compliance program.
| Role | Data fiduciary (DPDPA ss. 8-10) |
|---|---|
| Top penalties | INR 250 crore (security); INR 200 crore (breach notice, children); INR 150 crore (SDF duties) |
| Regulator | Data Protection Board of India |
| Framework | MeitY |
The baseline duty stack (every fiduciary)
- Notice and ground. Itemized notice of data and purpose, in English or any scheduled language, before or at consent; processing rests on consent or a section 7 legitimate use, nothing else.
- Security safeguards. Reasonable measures to prevent breaches, the highest-penalty duty (INR 250 crore cap). The draft rules enumerate minimums: encryption, access control, logging with retention, and backups.
- Breach response. Dual notification (Board + affected individuals), structured by the rules as prompt intimation plus a 72-hour detailed report.
- Lifecycle. Erase on purpose-completion or consent withdrawal; ensure accuracy where data feeds decisions affecting the individual or is disclosed onward.
- Interfaces. A published grievance officer and mechanism; readable rights machinery for access summaries, correction, and erasure; consent withdrawal as easy as grant.
- Processor governance. Valid contracts only; fiduciary liability is non-delegable, so vendor diligence and audit rights are the control surface.
The SDF overlay
Designated fiduciaries add four things: the India-resident DPO answering to the board of directors; an independent data auditor evaluating compliance; periodic DPIAs feeding significant-processing decisions; and, under the draft rules, algorithmic due-diligence obligations (verifying that algorithmic software deployed on personal data does not pose risks to data principals’ rights) plus possible localization directions for government-specified data categories, a hook that could reintroduce data-localization mandates fiduciary by fiduciary.
Treat SDF readiness as contingency planning: if your India footprint involves scale, sensitive categories, or consumer platforms, build the DPO reporting line and DPIA cadence before designation arrives, retrofitting governance under regulatory attention is the expensive path. The children’s-data rules and the GDPR delta map cover the adjacent obligations; a free scan shows what your India-facing properties collect today.