Organisations that handle personal data have different accountabilities under the DPDP Act. To understand a Data Processor, you need to know about the following.
The Data Principal is the individual whose data is processed, while the Data Fiduciary determines why and how personal data is collected and processed.
Often, the Fiduciary brings outside partners that help them to automate workflows, run systems, or handle the data processing. According to the Act, these partners are called Data Processors.
Under the DPDP Act, A Data Processor is any entity that processes digital personal data for a Data Fiduciary. A cloud hosting provider, third-party payroll firms, and external customer support are examples of data processors.
Read ahead to know about Data Processor’s roles, duties, and regulations.
Who is a Data Processor under the DPDP Act, 2023?
Under Section 2(k) of the DPDP Act 2023, a Data Processor means “any person who processes personal data on behalf of a Data Fiduciary.”
A Data Processor is any person, corporation, association of persons, or any organization handling the personal data for a data fiduciary. It has no independent decision-making power over the data. It executes the operations or tasks based entirely on the documented instructions and terms provided by the Data Fiduciary.

What are the Obligations and Rules for a Data Processor under the DPDP Act?
The Data Processors only carry direct contractual obligations and shared operational responsibilities.
The DPDP Act puts almost all the duties on the Data Fiduciary. A Data Processor is bound only through the contract, but the fiduciary becomes fully liable for processor’s activities under Section 8(1,2).
Data Processor’s Obligations and Responsibilities:
A valid contract
According to Section 8(2), a data fiduciary can engage a processor only under a valid contract. A fiduciary engaging, appointing, using or involving any data processor to process personal data on its behalf can only do so under a valid contract. This valid contract is known as Data Processing Agreements (DPAs).
Security Safeguards
The Data Fiduciary has the duty to safeguard the personal data of an individual, and this duty carries down to the Data Processor as well.
Under Section 8(5) of the DPDP Act, 2023, the Data Fiduciary must take reasonable security safeguards to prevent a data breach, including for processing done by its Data Processor. The processor is bound to these safeguards through its contract.
Now according to DPDP Rules, 2025, a Data Fiduciary (and any Data Processor working for it) must put these safeguards in place:
Rule 6 (1)(a) – Protect the data – Use encryption, masking, obfuscation, or tokens that are used instead of the real personal data.
Rule 6 (1)(b) – Control access – Limit access to the systems and computers that handle the data.
Rule 6 (1)(c) – Visibility on Accessing – Maintain logs and regularly review the data so unauthorised access can be spotted, investigated, and prevented from happening again.
Rule 6 (1)(d) – Have Backups – If the data is destroyed, lost, or compromised, the processing can be continued through backups.
Rule 6 (1)(e) – Retain logs for one year – Keep the personal data for at least one year to help detection, investigation, remediation, and recovery. The time period can be different under the compliance of another law.
Rule 6 (1)(f) – Appropriate requirements in the contract – Add reasonable security requirements in the contract between the Data Fiduciary and the Data Processor
Rule 6 (1)(g) – Use technical and organisational measures: Make sure the safeguards are actually followed in practice.
Breach Handling
In case of a data breach, the processor must immediately tell the fiduciary, as required by their contract. The fiduciary must then inform affected Data Principals and the Board without delay, and send the Board a detailed report within 72 hours. [Under Section 8(6) and Rule 7]
Erasure
When the individual’s consent is withdrawn or its purpose is served, the fiduciary must ensure the processor also erases the data. [Under Section 8(7-b) and Rule 8]

How Do Data Processors Stay Compliant under the DPDP Act?
As a Data Processor handles personal data on behalf of a Data Fiduciary. The act puts a legal responsibility on the fiduciary only and not on the processor even if the processor does the work. So the processor stays compliant mainly by meeting the terms of its contract (presented by fiduciary) which the Act, 2023 and the DPDP Rules, 2025 shape.
Following is the Data Processor compliance checklist:
- Sign a valid legal contract with the fiduciary before handling any data – Section 8(2)
- Use data only for the fiduciary’s purpose and stop when told to – Section 6(6)
- Apply security safeguards like encryption or masking, access controls, activity logs and monitoring – Section 8(5), Rule 6
- Keep logs and data for at least one year – Rule 6
- Report breaches to the fiduciary quickly so it can notify the Board and affected individuals – Section 8(6)
- Erase data when the fiduciary asks – Section 8(7)(b)
- Follow cross-border transfer limits set by the Government – Section 16
Why Data Processors Can’t Ignore DPDP Compliance?
According to Section 8(1), the Data Fiduciary remains legally responsible if any data processor fails. If reasonable security safeguards are not in place, even because of the processor, the fiduciary can face a penalty of up to ₹250 crore.
In practice, Data Fiduciaries who appoint Data processors make Data Processing Agreements to manage risk by writing security and breach obligations into the contracts. Through these contracts, if a processor fails to comply may face contractual claims.
Conclusion
A Data Processor handles personal data only on behalf of a Data Fiduciary. It has no authority to decide the purpose or means of processing. The Section 8(1) and 8(5) puts the pressure on the fiduciary for protecting personal data, even when a processor handles it.
But this doesn’t mean that the processor doesn’t have any particular responsibility. The processor’s duties are laid out in the Data Processing Agreements and contracts.
Violating security guidelines can cost the fiduciary up to ₹250 crore in penalties, so fiduciaries have every reason to choose compliant processors. Clear contracts, strong security and quick breach reporting make a processor a safer partner for fiduciaries.
FAQs
Ques: Is Data Fiduciary and a Data Processor the same?
Ans: No, they are not the same. A Data Fiduciary determines the means and purpose of processing personal data. A Data Processor only processes it on behalf of a fiduciary.
Ques: What does data processor do?
Ans: A Data Processor manages and processes data for a Data Fiduciary based strictly on their orders.
Ques: Why does a Data Processor need a contract to work for a Data Fiduciary?
Ans: Section 8(2) says a fiduciary can engage a processor only under a valid contract.
Ques: What are the roles and responsibilities of a data processor?
Ans: A Data Processor processes personal data on behalf of a Data Fiduciary. This processing is done under the fiduciary’s instructions and contract. It does not decide why or how the data is used.
Ques: What are the obligations of data processors under the DPDP Act?
Ans: The DPDP Act places the main duties on the Data Fiduciary only. A processor’s work is limited through the contract between processor and fiduciary.
Ques: What are the compliance requirements for Data Processors?
Ans: A processor should have a valid contract with the fiduciary, and follow Rule 6 of DPDP Act 2025 to have safeguards like encryption, access controls, monitoring, backups. It should also keep record for at least one year, help report breaches, and erase data when the fiduciary asks.
Ques: What is the difference between data controller vs data processor?
Ans: Data Controller is the same as Data Fiduciary. While under the GDPR law, Data Controller is used and under DPDP Act, Data Fiduciary is used. A data controller (fiduciary) decides why and how personal data is processed, while a data processor handles it only on the controller’s behalf and instructions.
