A Data Processor does not decide why or how personal data is used; it acts on the Data Fiduciary's instructions. Typical examples are cloud hosting providers, payment processors, email and customer-support platforms, and analytics vendors.
Under the DPDPA, a Data Fiduciary may engage a Data Processor only under a valid contract, and the Data Fiduciary remains responsible for complying with the Act, including for processing its Data Processors carry out on its behalf. Data Principals exercise their rights against the Data Fiduciary rather than the processor.
In ConsentX
Related terms
Under India's DPDPA, a Data Fiduciary is the entity that decides why and how personal data is processed, equivalent to a 'controller' under the GDPR.
Under India's DPDPA, a Data Principal is the individual whose personal data is being processed, equivalent to a 'data subject' under the GDPR.
The DPDPA (DPDP Act 2023) is India's national data-protection law, requiring clear notice and free, specific, informed consent before processing personal data, with the DPDP Rules notified on 13 November 2025.
Data Principal rights are the rights India's DPDPA gives individuals over their personal data: access to information, correction and erasure, grievance redressal, nomination and withdrawal of consent.