Skip to content
DPDP deadline in
Learn more →
PrivacySuraksha - Privacy. Trust. Compliance

India's DPDP privacy operations platform

Chapter II · Obligations of Data Fiduciary

Section 8 — General obligations of Data Fiduciary

What this section requires

Section 8 is the general-obligations backbone of the Act — the duties that apply regardless of which lawful ground the processing relies on. A Data Fiduciary is responsible for compliance no matter what any contract says or whether the Data Principal held up her end of Section 15 (sub-section (1)); may only engage a Data Processor under a valid contract (2); must keep personal data complete, accurate and consistent wherever it feeds a decision about the Data Principal or gets disclosed to another fiduciary (3); must implement technical and organisational measures to actually observe the Act (4); must take reasonable security safeguards to prevent a breach (5); must notify the Board and every affected Data Principal in the event of a breach (6); must erase personal data once consent is withdrawn or the purpose is no longer served — and cause its processors to do the same — unless retention is required by another law (7)-(8); must publish contact information for processing queries (9); and must run an effective grievance-redressal mechanism (10).

Who it applies to

Every Data Fiduciary, for every processing activity — unlike Sections 4-7 (which govern the ground for processing), Section 8 applies on top, regardless of ground.

Checklist

  • Only engage Data Processors under a valid, written contract — Section 8(2) has no informal-arrangement exception.
  • Keep personal data complete, accurate and consistent wherever it will feed a decision about the Data Principal or be shared with another fiduciary.
  • Take reasonable security safeguards against a breach, per Rule 6 once in force — encryption or masking, access control, monitoring and logs, backups, processor contracts binding the same safeguards, and one year's retention of breach-related logs.
  • On a breach, notify the Board and every affected Data Principal without delay, and give the Board the full follow-up (cause, impact, mitigation) within 72 hours — see Rule 7.
  • Erase personal data once the Data Principal withdraws consent, or once the purpose it was collected for stops being served — whichever is earlier — unless another law requires retention.
  • Publish, on your website or app, the business contact information of a Data Protection Officer or another person able to answer processing questions.
  • Stand up a grievance-redressal mechanism the Data Principal can actually use.

Penalty exposure

Failing to take reasonable security safeguards to prevent a breach — sub-section (5) — carries the Act's single highest penalty: up to ₹250 crore.

Failing to notify the Board or an affected Data Principal of a breach — sub-section (6) — carries up to ₹200 crore.

Every other Section 8 duty (processor contracts, accuracy, erasure, contact publication, grievance redressal) falls under the Schedule's residual item 7 — up to ₹50 crore — since none of them has its own named Schedule entry.

Implementation timeline

Not yet in force. Commences 13 May 2027, eighteen months after the DPDP Rules, 2025 were published (13 November 2025) — per the commencement notification G.S.R. 843(E).

Section 8 · Rule 6 · Rule 7 · Rule 8

← Back to the DPDP guide index