DPDP Act 2023 · Section 8
General obligations of Data Fiduciary
- Status
- Not yet in force
- Commencement
- 13 May 2027 · computed date, presented as interpretation until officially confirmed (how it is computed)
- Source
- The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) · Gazette page 7
- Last verified
- 17 August 2026
What section 8 says, in plain English
Plain English
Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. The summary below is what the provision says, not what is in force today. Status last checked 28 September 2026 against the MeitY library and India Code.
A Data Fiduciary answers for compliance even when a Data Processor handles the work and may engage processors only under a valid contract. It must keep certain data accurate, apply security safeguards, report personal data breaches to the Board and affected Data Principals, erase data no longer needed, publish a contact point and provide grievance redressal.
How 13 May 2027 is computed, and why it could be 1 day later
Publication date 13 November 2025 printed on Gazette issue No. 757, plus eighteen months. The notification states a period rather than a calendar date and does not state how the period is counted. The eGazette record of this same issue carries a code embedding 14112025, which would move the computed date by 1 day; the printed masthead date is used, and the interpretation label carries that uncertainty. CORRECTED 2026-08-25: this note previously also cited the Government's own PIB release for 14 November 2025. That release is about the DPDP Rules, 2025, G.S.R. 846(E) in Gazette issue No. 760, and says nothing about this Act commencement notification, G.S.R. 843(E) in issue No. 757. The missing space in the phrase "section 6,sections 7 to 10" appears as printed in the Gazette text layer.
Official text of section 8
Section 8. General obligations of Data Fiduciary.(1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. (2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract. (3) Where personal data processed by a Data Fiduciary is likely to be— (a) used to make a decision that affects the Data Principal; or (b) disclosed to another Data Fiduciary, the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency. (4) A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder. (5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. Illustrations. (I) X, an individual, registers herself on an online marketplace operated by Y, an e-commerce service provider. X gives her consent to Y for the processing of her personal data for selling her used car. The online marketplace helps conclude the sale. Y shall no longer retain her personal data. (II) X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X’s personal data for the said period. (8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not–– (a) approach the Data Fiduciary for the performance of the specified purpose; and (b) exercise any of her rights in relation to such processing, for such time period as may be prescribed, and different time periods may be prescribed for different classes of Data Fiduciaries and for different purposes. (9) A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data. (10) A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals. (11) For the purposes of this section, it is hereby clarified that a Data Principal shall be considered as not having approached the Data Fiduciary for the performance of the specified purpose, in any period during which she has not initiated contact with the Data Fiduciary for such performance, in person or by way of communication in electronic or physical form.
Commencement basis · Sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 other than section 27(1)(d), sections 28 to 34, sections 36 and 37, and section 44(2) of the Act
“(c) eighteen months from the date of publication of this gazette, on which the provision of sections 3 to 5, sub-sections (1) to (8) and (10) of section 6,sections 7 to 10, sections 11 to 17, section 27 except clause (d) of sub-section (1) of the said section, sections 28 to 34, 36, 37 and sub-section (2) of section 44 of the said Act shall come into force.”
From commencement notification G.S.R. 843(E), Gazette issue No. 757, printed date 13 November 2025.
Sources cited on this page
- [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmedSection 8 begins on Gazette page 7 and concludes on page 8.
- [2]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026Document status: published; in effect per its own termsNotification G.S.R. 843(E) names this section in the group that comes into force eighteen months from the date of publication of the notification gazette. The computed calendar date, 13 May 2027, is interpretation until officially confirmed.
- [3]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Official requirement · Verified 17 August 2026Document status: published; in effect per its own terms
eighteen months from the date of publication of this gazette, on which the provision of sections 3 to 5, sub-sections (1) to (8) and (10) of section 6,sections 7 to 10, sections 11 to 17, section 27 except clause (d) of sub-section (1) of the said section, sections 28 to 34, 36, 37 and sub-section (2) of section 44 of the said Act shall come into force.
- [4]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ Also on MeitY (byte identical) ↗ · Interpretation, requires judgment · Verified 17 August 2026Document status: published; in effect per its own termsThe calendar date 13 May 2027 is computed from the printed publication date and is presented as interpretation until officially confirmed. It aligns with the derived date for the main group of the DPDP Rules 2025.