Section 8 of the Digital Personal Data Protection Act, 2023 is the most important provision for businesses. It lays down the complete list of obligations that every Data Fiduciary must fulfil — the legal duties your business owes to every user whose data you process. This article explains each obligation in plain language with practical guidance.
- What is a Data Fiduciary?
- Overview of Section 8 Obligations
- Obligation 1 — Lawful Processing & Valid Consent
- Obligation 2 — Purpose Limitation
- Obligation 3 — Data Minimisation
- Obligation 4 — Data Accuracy
- Obligation 5 — Storage Limitation & Erasure
- Obligation 6 — Security Safeguards
- Obligation 7 — Breach Notification
- Obligation 8 — Grievance Redressal
- Special Obligations for Significant Data Fiduciaries
- Penalties for Breach of Section 8
- Practical Compliance Checklist
1. What is a Data Fiduciary?
Under the DPDP Act 2023, a Data Fiduciary is any person, company, firm, state, or body corporate who, alone or in conjunction with others, determines the purpose and means of processing personal data.
In plain language: If your business decides why you collect customer data and how it is processed — you are a Data Fiduciary. This includes almost every business that has a website, app, CRM, or any digital system that holds information about people.
Examples of Data Fiduciaries include:
- An e-commerce company collecting customer names, addresses, and payment data
- A hospital maintaining patient health records
- A startup using email marketing to communicate with users
- An HR software company processing employee data on behalf of its clients
- A mobile app collecting location and device data from users
2. Overview of Section 8 Obligations
Section 8 of the DPDP Act is titled "Obligations of Data Fiduciary." It is the core compliance provision — setting out eight distinct obligations that every Data Fiduciary must meet, regardless of business size, industry, or revenue. There is no small business exemption.
| # | Obligation | Core Requirement | Max Penalty |
|---|---|---|---|
| 1 | Lawful Processing | Valid consent before data collection | ₹250 Cr |
| 2 | Purpose Limitation | Use data only for stated purpose | ₹50 Cr |
| 3 | Data Minimisation | Collect only what is necessary | ₹50 Cr |
| 4 | Data Accuracy | Keep data accurate and updated | ₹50 Cr |
| 5 | Storage Limitation | Delete data when no longer needed | ₹50 Cr |
| 6 | Security Safeguards | Implement reasonable security measures | ₹250 Cr |
| 7 | Breach Notification | Notify Board and individuals of breaches | ₹200 Cr |
| 8 | Grievance Redressal | Appoint officer, handle complaints | ₹50 Cr |
3. Obligation 1 — Lawful Processing & Valid Consent
Section 8(1) requires that a Data Fiduciary shall process personal data only in accordance with the provisions of the Act — meaning every data processing activity must have a valid legal basis, with consent being the primary basis for most commercial data processing.
What Valid Consent Requires
Common violation: "By using this website, you agree to our privacy policy" — this is not valid consent under Section 8. Using a service cannot be conditioned on giving consent to data processing beyond what is strictly necessary for that service.
Legitimate Use — When Consent is Not Required
Section 7 of the Act lists certain "Legitimate Uses" where processing without consent is permitted — including processing for performance of a contract, compliance with a legal obligation, medical emergencies, and certain state functions. However, most commercial data processing by private businesses will require explicit consent.
4. Obligation 2 — Purpose Limitation
Section 8(2) states that a Data Fiduciary shall process personal data only for the purpose for which it was collected, and not use it for any other purpose without fresh consent.
5. Obligation 3 — Data Minimisation
Section 8(3) requires that a Data Fiduciary shall collect only such personal data that is necessary for the purpose of processing. Collecting additional data "just in case it might be useful later" is a direct violation of this provision.
- Do you ask for date of birth when only age verification is needed?
- Do you collect full address when only city/state is required?
- Do you request phone number for an email-based service?
- Does your mobile app request permissions (camera, contacts, location) that the core feature doesn't use?
- Do you retain all historical data indefinitely when only recent data is operationally needed?
If the answer to any of these is yes, your data collection practices may need to be revised for Section 8(3) compliance.
6. Obligation 4 — Data Accuracy
Section 8(4) places a duty on every Data Fiduciary to make reasonable efforts to ensure that the personal data it processes is accurate and not misleading, in a manner that is consistent with the purpose of processing.
This obligation has two dimensions:
7. Obligation 5 — Storage Limitation & Erasure
Section 8(7) requires that a Data Fiduciary shall not retain personal data beyond the period necessary for the purpose for which it was collected and must erase it once the purpose is served — unless retention is required by law.
What this means in practice:
- Unsuccessful job applicants' CVs cannot be retained indefinitely — delete within a reasonable period after hiring decision
- Customer data of users who have closed their accounts must be deleted (subject to statutory retention requirements)
- Marketing lead data that never converted cannot be kept forever "just in case"
- Employee data must be deleted after exit (except statutory HR records required by labour law)
You must document your data retention schedule — a written policy specifying how long each category of personal data is kept and when it is deleted. This schedule is a core compliance document that the Data Protection Board may inspect.
8. Obligation 6 — Security Safeguards
Section 8(5) requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches. This is one of the most important obligations — carrying the highest penalty of ₹250 crore for failure.
The Act does not prescribe specific technical standards but uses the standard of "reasonable security practices" — assessed proportionately against:
Minimum baseline security measures every business should implement:
- Encryption of personal data at rest and in transit (HTTPS, TLS)
- Role-based access controls — only those who need data can access it
- Multi-factor authentication for systems holding personal data
- Regular security patches and vulnerability management
- Secure deletion when data is erased
- Vendor security due diligence and Data Processing Agreements
9. Obligation 7 — Breach Notification
Section 8(6) requires that in the event of a personal data breach, the Data Fiduciary must notify both the Data Protection Board and each affected Data Principal in the manner and within the timeframe prescribed by the Board.
10. Obligation 8 — Grievance Redressal
Section 8(8) and Section 8(9) require every Data Fiduciary to publish the name and contact details of a Grievance Officer on its website and to establish a mechanism for Data Principals to exercise their rights and file complaints.
11. Special Obligations for Significant Data Fiduciaries
Section 10 of the DPDP Act introduces Significant Data Fiduciaries (SDFs) — a category of Data Fiduciaries designated by the government based on volume of data processed, sensitivity, national security risk, and public order considerations. SDFs face additional obligations beyond Section 8:
12. Penalties for Breach of Section 8 Obligations
| Section 8 Breach | Penalty (Schedule) |
|---|---|
| Failure to implement security safeguards (Section 8(5)) resulting in data breach | Up to ₹250 Crore |
| Failure to notify breach to Board or affected Data Principals (Section 8(6)) | Up to ₹200 Crore |
| Any other breach of obligations under Section 8 | Up to ₹50 Crore |
| Breach of Significant Data Fiduciary obligations (Section 10) | Up to ₹150 Crore |
13. Practical Section 8 Compliance Checklist
Use this checklist to assess your current compliance with Section 8 obligations:
Section 8 Is Not Optional — It Is the Law
Every obligation in Section 8 is legally binding on your business from the moment the DPDP Act's provisions come into force. The penalties are real, the Data Protection Board will be active, and the obligation to comply falls on you — not on your IT vendor, not on your CRM provider, and not on your legal counsel.
The good news is that compliance is achievable with the right guidance. Our advocates specialise in DPDP Act compliance and can help you build a documented, defensible compliance programme — from privacy policy to breach response plan.
Get Section 8 Compliance Help →