Infosek
INFOSEK

Data Fiduciary, Data Processor, Data Principal: Which Are You?

Getting this wrong changes which obligations you carry. Most SaaS companies are both a Fiduciary and a Processor, in different parts of the same business, and treating themselves as only one is where the gap opens.

Data Fiduciary, Data Processor, Data Principal: Which Are You?

The three definitions

The whole distinction turns on one question: who decided why this data is being processed, and how? Deciding makes you a Fiduciary. Executing someone else's decision makes you a Processor.

Why it matters

The obligations in the Act and Rules attach principally to the Data Fiduciary. Notice under Rule 3, security safeguards under Rule 6, breach intimation under Rule 7, erasure under Rule 8, rights handling under Rule 14 — these are Fiduciary duties.

A Data Processor is bound largely through contract. Rule 6(1)(f) requires the Data Fiduciary to include appropriate provisions in its contract with a Data Processor for taking reasonable security safeguards. Rule 6(1) also makes clear the Fiduciary must protect personal data in its possession or under its control including in respect of processing undertaken on its behalf by a Data Processor.

Appointing a Processor does not transfer the obligation. If your vendor loses the data, the Data Fiduciary is the one the Rules look to, which is why the contract clause is a requirement and not an option.

Infosek Team

Working out which role applies

Ask, for each data set separately rather than for the company as a whole:

The common misclassification

Analytics and support tooling is where it usually goes wrong. A company treats its product data as customer-owned and therefore assumes Processor status across the board, then separately runs product analytics for its own roadmap decisions. That second activity is its own purpose, decided by it, which makes it a Data Fiduciary for that processing regardless of what the customer contract says about the underlying data.

The safe method is to classify per processing activity, not per company. One organisation will hold different roles across its own systems, and the inventory is what makes that visible.

Common questions

What is the difference between a Data Fiduciary and a Data Processor?

Under section 2 of the DPDP Act, a Data Fiduciary is any person who alone or in conjunction with others determines the purpose and means of processing personal data. A Data Processor is any person who processes personal data on behalf of a Data Fiduciary. The distinction is who decides why and how the data is processed.

Can a company be both a Data Fiduciary and a Data Processor?

Yes, and most B2B software companies are. They are a Data Fiduciary for their own employee and customer contact data, where they decide the purpose, and a Data Processor for the end-user data their customers put into the product, where the customer decides the purpose.

Unclear which role you hold?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment