DPDPAcademyKnow the law. Prove it.
Home/Key Roles
Section 2 · Section 10 · Sections 18–26

Six Defined Roles Carry Every Obligation

Get the roles right and the rest of the Act reads itself: duties attach to the Data Fiduciary, rights attach to the Data Principal, and everything else is machinery around those two.

§ 2(j)Data PrincipalThe individual the personal data is about. Where she is a child, the expression includes her parents or lawful guardian; where she is a person with disability, her lawful guardian acting on her behalf.
§ 2(i)Data FiduciaryWhoever determines the purpose and means of processing, alone or with others. Accountability sits here - irrespective of any agreement to the contrary, and irrespective of what a Data Principal does or fails to do.
§ 2(k) · § 8(2)Data ProcessorProcesses personal data on behalf of a Data Fiduciary, and may only be engaged for offering goods or services under a valid contract. When the Fiduciary must erase data, it must cause its processors to erase too.
§ 2(g) · § 6(7)–(9)Consent ManagerA single point of contact, registered with the Board, through which a Data Principal can give, manage, review and withdraw consent on an accessible, transparent and interoperable platform. Accountable to her, not to the Fiduciary.
§ 10Significant Data FiduciaryNotified by the Central Government on volume and sensitivity of data, risk to rights, sovereignty, electoral democracy, security of the State and public order. Owes a DPO in India, an independent data auditor, and periodic DPIA and audit.
§§ 18–26Data Protection Board of IndiaA body corporate established by the Central Government, with a Chairperson and Members appointed for two-year terms, functioning as far as practicable as a digital office. Its officers are deemed public servants.

Definitions that decide exam questions

Personal dataAny data about an individual who is identifiable by or in relation to such data. § 2(t)
ProcessingA wholly or partly automated operation on digital personal data - collection, storage, use, sharing, erasure and more. § 2(x)
Personal data breachAny unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability. § 2(u)
ChildAn individual who has not completed the age of eighteen years. § 2(f)
Specified purposeThe purpose stated in the notice given by the Data Fiduciary to the Data Principal. § 2(za)
Digital officeAn office conducting proceedings online end to end, from intimation to disposal. § 2(m)
Roles are the most tested topic on the exam.Run a practice set now while the definitions are fresh.
Who carries the risk

The roles are a liability map

Defining the six roles is the easy half. The half that decides outcomes is which of them the Act can actually hold to account - and the answer is lopsided.

§ 2(s)Almost anything can be a Data Fiduciary“Person” includes an individual, a Hindu undivided family, a company, a firm, an association of persons or body of individuals whether incorporated or not, the State, and every artificial juristic person not already covered.The State is inside the definition, not outside it. A government department determining purpose and means is a Data Fiduciary, subject to the exemptions in sections 7 and 17.
§ 2(i)The test is purpose and means, not possessionA Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing. Holding the data is neither necessary nor sufficient - deciding why and how is what makes you one.“In conjunction with other persons” means two organisations can be Fiduciaries for the same processing. The Act sets out no apportionment between them.
§ 2(k) · § 8(2)The processor has no direct duties under the ActA Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The Act does not impose obligations on it directly. Section 8(2) instead requires the Data Fiduciary to engage one only under a valid contract.This is a genuine structural break from GDPR, where Article 28 binds processors directly and a supervisory authority can act against them. Here, the contract is the whole of the mechanism.
§ 8(1)And the Fiduciary answers for the processor anywayThe Data Fiduciary is responsible for compliance irrespective of any agreement to the contrary, and irrespective of any failure by the Data Principal to carry out her duties.So a processor contract allocates work and cost, never liability. When a processor loses data, the Board still looks at the Data Fiduciary.
§ 6(8)The Consent Manager answers to her, not to youThe one role the Act points away from the Data Fiduciary. A Consent Manager is accountable to the Data Principal and acts on her behalf, even though the commercial relationship runs the other way.
§§ 18–26 · The Board

The regulator, as an institution

The Data Protection Board is the only body that can impose a penalty under this Act, and the only forum - section 39 bars civil courts from matters it is empowered to decide.

§ 18 · § 19A body corporate, appointed by the GovernmentEstablished by the Central Government, with a Chairperson and Members appointed on the qualifications section 19 sets. Their salary and terms are prescribed by rules, and cannot be varied to their disadvantage after appointment.
§ 20(2)Two-year terms, renewableThe Chairperson and every Member hold office for two years and are eligible for re-appointment. Short, by the standards of Indian regulators, and the renewability is the part worth noticing.The Fifth Schedule to the Rules fixes the pay: ₹4,50,000 a month for the Chairperson, ₹4,00,000 for other Members, consolidated, without house or car.
§ 28(1)A digital office by designThe Board functions as far as practicable as a digital office - receipt of complaints, allocation, hearing and pronouncement of decisions all conducted digitally, without requiring anyone to appear in person.
§ 25Members and officers are public servantsDeemed public servants within the meaning of section 21 of the Indian Penal Code, which brings the offences and protections attaching to that status.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →