DATA FIDUCIARY LIABILITY UNDER THE DPDP FRAMEWORK
Vaidehi Sharma
INTRODUCTION
For years India’s data protection law was more of a paper exercise. The Digital Personal Data Protection Act came into force in August 2023. After that not much happened for over two years. Businesses treated it like a far-off deadline. Something to mention in compliance presentations but not something to worry about. That all changed on November 13 2025. On that day the Ministry of Electronics and Information Technology announced the DPDP Rules, 2025. They also released the enforcement timeline. Formally set up the Data Protection Board of India. Suddenly the law shifted from being a statement of intent to an actual working regulatory system. It now includes penalties.
Fines that can reach hundreds of crores of rupees. If your business handles data. And realistically that includes almost every business today. You are likely a "Data Fiduciary”, under this law. Being a Data Fiduciary comes with responsibilities that are wider and stronger than most people expect. This article explains what that responsibility really means, where it causes the pain and how a smart business prepares for it.
WHO COUNTS AS A DATA FIDUCIARY, AND WHY IT MATTERS
The DPDP Act sets out three roles. The Data Principal is the person whose personal data is being processed – that could be your customer, your employee or your app user. The Data Fiduciary is the party that decides why and how that data is processed – normally that is you, the business owner. The Data Processor is anyone that the Data Fiduciary hires to handle data for the Data Fiduciary, such as a cloud vendor, a payroll provider or a marketing analytics firm. This arrangement matters because the DPDP Act puts all the legal responsibility on the Data Fiduciary not on the Data Processor. If your outsourced customer‑support vendor mishandles a customer database the law will not primarily target the vendor. Instead, the law will target you because you are the one who chose to hand that data over and who is responsible, for ensuring it is handled correctly. You can hold a Data Processor to account through a contract. The statutory liability remains with the Data Fiduciary. That single design choice is probably the important point to grasp about this law because it shows that outsourcing a task does not outsource the risk.
THE OBLIGATIONS THAT ACTUALLY CREATE EXPOSURE
Section 8 of the Act lays out a long list of duties, for fiduciaries but a handful of fiduciaries are doing most of the work when it comes to liability:
Consent: Before processing personal data, a fiduciary must give the individual a clear itemised Notice that explains what data is collected and why. The fiduciary must also obtain consent for that specific purpose. Consent that comes from vague all‑purpose privacy policies—like those most Indian apps have used for years—does not pass this standard. The DPDP Rules add pressure by requiring Notice to stand alone separate, from any other information the fiduciary may wish to bundle.
Reasonable security safeguards: This is the obligation with the single largest penalty attached to it. Fiduciaries are expected to implement technical and organisational measures encryption, access controls, monitoring, and so on appropriate to the nature of the data they hold. Failure here is judged harshly precisely because it is the one obligation most directly tied to actual harm to real people.
Breach notification: If a personal data breach occurs, the fiduciary must inform both the Data Protection Board and the affected individuals. The Rules set a tight clock on this notification to the Board within 72 hours of becoming aware of the breach, and notification to individuals "without delay," with a plain-language description of what happened and what they can do about it. Many organisations underestimate how fast this clock runs, especially when the breach is discovered by a third party rather than internally.
Children's data: Where the fiduciary is processing a child's data, it needs verifiable parental consent, and it is barred from certain kinds of tracking, behavioural monitoring, and targeted advertising directed at children. This obligation carries one of the steepest penalties in the Schedule, reflecting how seriously the law treats this category.
Erasure and retention: Once the purpose for which data was collected is no longer being served, and no legal requirement to retain it exists, the fiduciary is expected to erase it. The Rules require fiduciaries to define purpose-linked retention periods up front, rather than keeping data indefinitely "just in case."
Grievance redressal: Every fiduciary needs a functioning mechanism for individuals to raise complaints, and a response window currently set at a matter of weeks within which those complaints have to be addressed.
None of these individually sound unreasonable. What creates the exposure is that a single lapse says, a breach caused by weak security, discovered late, and notified even later can trigger liability under three or four of these heads at once, and the Act treats these as separate, stackable violations rather than one combined offence.
THE PENALTY SCHEDULE, DECODED
Unlike the GDPR's turnover-based fines, the DPDP Act uses fixed rupee ceilings set out in a Schedule attached to the Act, assessed by the Data Protection Board under Section 33. Roughly, the structure looks like this:
-
Up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach — the single largest exposure in the Schedule, and the one most closely tied to actual harm.
-
Up to ₹200 crore for failing to notify the Board or affected individuals of a breach, and separately, up to ₹200 crore for violations involving children's personal data.
-
Up to ₹150 crore for a Significant Data Fiduciary's failure to meet its additional obligations, discussed below.
-
A residual category, capped lower, for other general non-compliance that doesn't fall into a specifically listed head.
-
A modest penalty of up to ₹10,000 against a Data Principal who misuses their own rights or files a frivolous or false complaint — a rare instance of the law imposing liability the other way.
I find two points about this structure worth noting: First penalties are applied for each instance and each violation not for each incident. If a breach happens because security is weak and it is reported late penalties can fall under both categories. Commentators say that one enforcement step that covers obligations could in theory make the total penalty exceed ₹500–650 crore.
Second smaller businesses do not get a cap built into the limits. The caps are fixed. This means that a small company that faces a small part of the maximum penalty could be, in serious trouble while the same amount would barely matter for a large enterprise.
HOW THE BOARD ACTUALLY SETS THE NUMBER
The Schedule sets limits, not fixed amounts and Section 33(2) requires the Data Protection Board to weigh factors before deciding what any particular fiduciary actually pays. These factors include the nature, gravity and duration of the breach; the type and volume of data affected; whether the fiduciary has a history of similar conduct; whether the fiduciary gained anything or caused loss to individuals; and importantly what the fiduciary did to mitigate the harm once it became aware of the problem.
This last factor is worth sitting with because it is the one variable a business can actually control after the fact. Self‑disclosure, remediation, cooperation with the Board’s inquiry and a documented compliance history all appear to shift the outcome in the fiduciary’s favour. Section 33(3) also allows the Board to enhance a penalty potentially doubling it for repeat or grave conduct. Orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal and from there on a question of law, to the Supreme Court.
SIGNIFICANT DATA FIDUCIARIES: A SECOND, HEAVIER TIER
The Central Government can designate certain fiduciaries based on factors like the volume and sensitivity of data processed, the risk to electoral democracy or state security, or their potential impact on India's sovereignty as "Significant Data Fiduciaries." This category is expected to sweep in large platforms, financial institutions, healthcare providers, and telecom operators, though the specific list had not been published as of the most recent updates.
Significant Data Fiduciaries carry a heavier compliance load appointing a Data Protection Officer based in India, engaging an independent data auditor, conducting periodic Data Protection Impact Assessments, and in some cases undergoing algorithmic fairness reviews. Falling short of these obligations carries its own dedicated penalty head under the Schedule, separate from the general security and breach-notification penalties meaning an SDF that gets both its baseline obligations and its enhanced obligations wrong is looking at two separate exposure lines running in parallel.
WHERE THINGS ACTUALLY STAND RIGHT NOW
It's worth being precise about the current state of play, because a fair amount of commentary treats the Act as either "not yet in force" or "fully enforced," when the truth is somewhere in between. The Data Protection Board is constituted and operational. The Rules are notified and legally binding. But implementation is explicitly phased: provisions relating to Consent Managers become effective roughly a year after notification, and the bulk of substantive fiduciary obligations are on a runway extending toward mid-2027. Certain pieces including the country list for permitted cross-border data transfers and the formal list of designated Significant Data Fiduciaries remain pending separate notification.
In practice, this means the underlying obligations and the penalty framework are real and legally operative now, even as some of the machinery around them is still being built out. Waiting for "full enforcement" before starting to comply is a bet on a moving target, not a safe harbour.
WHAT THIS MEANS FOR A BUSINESS, PRACTICALLY
None of the above is an argument for panic, but it is an argument for treating this seriously and early. A few things tend to make the biggest difference in practice:
I think you should map your data before you try to protect it. Most organisations cannot say with certainty which data they hold, where that data is stored who can see it or why it was gathered. This mapping job is not glamorous. It is essential for almost everything that follows. Write consent. Notice wording that can stand alone instead of being hidden inside a long privacy policy that nobody reads. Regulators usually spot the difference, between a notice made to inform and a notice made to shield a company.
Put your vendor contracts in order. Since liability for a processor's failure lands on you, your contracts with processors need real teeth audit rights, security obligations, and breach-notification clauses that give you enough time to meet your own 72-hour clock.
Build (and actually rehearse) a breach response plan before you need one. The fiduciaries who come out of a breach in reasonable shape are usually the ones who had already worked out who do what in the first 24 hours, rather than improvising under pressure.
Document your compliance efforts as you go. Given how heavily the penalty framework weighs mitigating conduct, a paper trail showing genuine effort DPIAs conducted, training done, security reviews carried out is worth more after an incident than it might seem worth before one.
CONCLUSION
Data Fiduciary liability under the DPDP framework is not a distant, theoretical risk anymore. The law is notified, the regulator exists, and the penalty ceilings are high enough to matter to almost any business, regardless of size. The good news, if there is any, is that the framework rewards genuine effort: fiduciaries who can show real security measures, honest notices, fast breach response, and a documented compliance program are treated very differently from those who cannot. The businesses that will struggle are not the ones with imperfect systems — every system is imperfect — but the ones that never built a system at all.
REFERENCES
-
Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 — Ministry of Electronics and Information Technology, Government of India (Gazette Notification G.S.R. 846(E), November 13, 2025)
-
"Transforming Data Privacy: DPDP Act, 2023 and DPDP Rules, 2025," EY India Insights
-
"India's DPDP Rules 2025: A Practical Guide with Implementation Checklist," Scrut.io
-
"DPDP Rules 2025: India's Complete Compliance Guide,"
-
"India's Digital Personal Data Protection Regime Takes Effect," Lexology
-
"Penalties and Adjudication under India's DPDP Act, 2023," K&K (ksandk.com)
-
"DPDPA Penalties — Complete Guide to Section 33," Sara Privacy
-
"DPDP Act Penalties: Fines Up to ₹250 Crore," TCSA
-
Digital Personal Data Protection Rules, 2025 — overview, Wikipedia
AUTHOR(s): Isha Kumari, BBA.LL.B graduate from ITM University, intern at The Legal Lock
More to Read
CHILDREN'S DATA PROTECTION UNDER THE DPDP FRAMEWORK
blogs
REGULATION OF AI-GENERATED DEEPFAKES UNDER INDIAN LAW
blogs
Handcuffing of Arrested Persons in India: A Critical Constitutional and Human Rights Analysis
blogs
The Difference Between Simple and Aggravated Assault Under New Jersey Law
blogs
DOES INDIA NEED A COMPREHENSIVE AI REGULATION ACT?
blogs
DATA FIDUCIARY LIABILITY UNDER THE DPDP FRAMEWORK
blogs