Share 💬 💼
DPDP

Section 8 Explained: Key Obligations of Data Fiduciaries Under DPDPA

📅 Feb 28, 2026
👤 Adv. Deepak Kumar
⏱️ 10 min read
📂 DPDP
Section 8 Explained: Key Obligations of Data Fiduciaries Under DPDPA
Section 8 of the DPDP Act 2023 is the most important provision for businesses — it lays down 8 binding obligations every Data Fiduciary must comply with. This article explains each obligation in plain language with practical guidance and a compliance checklist.
DPDP Act 2023 — Section 8 Deep Dive

Section 8 of the Digital Personal Data Protection Act, 2023 is the most important provision for businesses. It lays down the complete list of obligations that every Data Fiduciary must fulfil — the legal duties your business owes to every user whose data you process. This article explains each obligation in plain language with practical guidance.

📋 What This Article Covers
  1. What is a Data Fiduciary?
  2. Overview of Section 8 Obligations
  3. Obligation 1 — Lawful Processing & Valid Consent
  4. Obligation 2 — Purpose Limitation
  5. Obligation 3 — Data Minimisation
  6. Obligation 4 — Data Accuracy
  7. Obligation 5 — Storage Limitation & Erasure
  8. Obligation 6 — Security Safeguards
  9. Obligation 7 — Breach Notification
  10. Obligation 8 — Grievance Redressal
  11. Special Obligations for Significant Data Fiduciaries
  12. Penalties for Breach of Section 8
  13. Practical Compliance Checklist

1. What is a Data Fiduciary?

Under the DPDP Act 2023, a Data Fiduciary is any person, company, firm, state, or body corporate who, alone or in conjunction with others, determines the purpose and means of processing personal data.

In plain language: If your business decides why you collect customer data and how it is processed — you are a Data Fiduciary. This includes almost every business that has a website, app, CRM, or any digital system that holds information about people.

Examples of Data Fiduciaries include:

  • An e-commerce company collecting customer names, addresses, and payment data
  • A hospital maintaining patient health records
  • A startup using email marketing to communicate with users
  • An HR software company processing employee data on behalf of its clients
  • A mobile app collecting location and device data from users

2. Overview of Section 8 Obligations

Section 8 of the DPDP Act is titled "Obligations of Data Fiduciary." It is the core compliance provision — setting out eight distinct obligations that every Data Fiduciary must meet, regardless of business size, industry, or revenue. There is no small business exemption.

# Obligation Core Requirement Max Penalty
1 Lawful Processing Valid consent before data collection ₹250 Cr
2 Purpose Limitation Use data only for stated purpose ₹50 Cr
3 Data Minimisation Collect only what is necessary ₹50 Cr
4 Data Accuracy Keep data accurate and updated ₹50 Cr
5 Storage Limitation Delete data when no longer needed ₹50 Cr
6 Security Safeguards Implement reasonable security measures ₹250 Cr
7 Breach Notification Notify Board and individuals of breaches ₹200 Cr
8 Grievance Redressal Appoint officer, handle complaints ₹50 Cr

3. Obligation 1 — Lawful Processing & Valid Consent

Section 8(1) requires that a Data Fiduciary shall process personal data only in accordance with the provisions of the Act — meaning every data processing activity must have a valid legal basis, with consent being the primary basis for most commercial data processing.

What Valid Consent Requires

✅ Free
No coercion or conditioning of service on consent
✅ Specific
For a defined, stated purpose only
✅ Informed
User knows what data, why, and who gets it
✅ Unambiguous
A clear affirmative action — not silence or pre-ticked boxes
✅ Withdrawable
Can be withdrawn as easily as it was given

Common violation: "By using this website, you agree to our privacy policy" — this is not valid consent under Section 8. Using a service cannot be conditioned on giving consent to data processing beyond what is strictly necessary for that service.

Legitimate Use — When Consent is Not Required

Section 7 of the Act lists certain "Legitimate Uses" where processing without consent is permitted — including processing for performance of a contract, compliance with a legal obligation, medical emergencies, and certain state functions. However, most commercial data processing by private businesses will require explicit consent.

4. Obligation 2 — Purpose Limitation

Section 8(2) states that a Data Fiduciary shall process personal data only for the purpose for which it was collected, and not use it for any other purpose without fresh consent.

Practical Example
❌ Violation
A user gives their email address to receive an order confirmation. The company then adds them to a marketing newsletter without asking. This is an unlawful use of the data for a different purpose.
✅ Compliant
The company sends the order confirmation (original purpose) and separately asks: "Can we send you marketing emails?" with an opt-in checkbox. Only users who check the box receive marketing.

5. Obligation 3 — Data Minimisation

Section 8(3) requires that a Data Fiduciary shall collect only such personal data that is necessary for the purpose of processing. Collecting additional data "just in case it might be useful later" is a direct violation of this provision.

Audit Questions for Your Business
  • Do you ask for date of birth when only age verification is needed?
  • Do you collect full address when only city/state is required?
  • Do you request phone number for an email-based service?
  • Does your mobile app request permissions (camera, contacts, location) that the core feature doesn't use?
  • Do you retain all historical data indefinitely when only recent data is operationally needed?

If the answer to any of these is yes, your data collection practices may need to be revised for Section 8(3) compliance.

6. Obligation 4 — Data Accuracy

Section 8(4) places a duty on every Data Fiduciary to make reasonable efforts to ensure that the personal data it processes is accurate and not misleading, in a manner that is consistent with the purpose of processing.

This obligation has two dimensions:

Active Accuracy Maintenance
Where accuracy matters for decisions affecting individuals (credit scoring, health records, HR files), you must have mechanisms to keep data current — periodic verification, user-update facilities, and data source quality controls.
Responding to Correction Requests
When a Data Principal (user) exercises their right to correction under Section 12 and points out inaccurate data, you must update or correct it promptly. Ignoring a correction request is a double violation — of both Section 8(4) and Section 12.

7. Obligation 5 — Storage Limitation & Erasure

Section 8(7) requires that a Data Fiduciary shall not retain personal data beyond the period necessary for the purpose for which it was collected and must erase it once the purpose is served — unless retention is required by law.

What this means in practice:

  • Unsuccessful job applicants' CVs cannot be retained indefinitely — delete within a reasonable period after hiring decision
  • Customer data of users who have closed their accounts must be deleted (subject to statutory retention requirements)
  • Marketing lead data that never converted cannot be kept forever "just in case"
  • Employee data must be deleted after exit (except statutory HR records required by labour law)

You must document your data retention schedule — a written policy specifying how long each category of personal data is kept and when it is deleted. This schedule is a core compliance document that the Data Protection Board may inspect.

8. Obligation 6 — Security Safeguards

Section 8(5) requires every Data Fiduciary to implement reasonable security safeguards to prevent personal data breaches. This is one of the most important obligations — carrying the highest penalty of ₹250 crore for failure.

The Act does not prescribe specific technical standards but uses the standard of "reasonable security practices" — assessed proportionately against:

Volume of data
More users = higher security standard expected
Sensitivity of data
Health, financial, biometric data = highest standard
Nature of business
Industry-specific standards may apply (RBI, IRDAI)
Available technology
Current best practices for encryption, access control

Minimum baseline security measures every business should implement:

  • Encryption of personal data at rest and in transit (HTTPS, TLS)
  • Role-based access controls — only those who need data can access it
  • Multi-factor authentication for systems holding personal data
  • Regular security patches and vulnerability management
  • Secure deletion when data is erased
  • Vendor security due diligence and Data Processing Agreements

9. Obligation 7 — Breach Notification

Section 8(6) requires that in the event of a personal data breach, the Data Fiduciary must notify both the Data Protection Board and each affected Data Principal in the manner and within the timeframe prescribed by the Board.

⚠️ Key Points on Breach Notification
Both parties must be notified — the Data Protection Board AND every individual whose data was affected. Notifying one but not the other is still a violation.
Content requirements are strict — the notification must contain the nature of the breach, categories of data affected, number of individuals impacted, likely consequences, and remedial measures taken.
Concealment is the worst outcome — attempting to hide a breach carries maximum penalties and can expose individual directors to personal liability.
Prepare in advance — have pre-drafted notification templates, an incident response plan, and a breach response team identified before any breach occurs.

10. Obligation 8 — Grievance Redressal

Section 8(8) and Section 8(9) require every Data Fiduciary to publish the name and contact details of a Grievance Officer on its website and to establish a mechanism for Data Principals to exercise their rights and file complaints.

Grievance Officer Requirements
Publication
Name, designation, email, and address must be published on the website and in the Privacy Policy
Acknowledgement
Every complaint must be acknowledged promptly and tracked through to resolution
Timeline
Complaints must be resolved within the prescribed period — failure enables escalation to the Data Protection Board
Rights Handling
Access, correction, erasure, and nomination requests must all flow through this mechanism

11. Special Obligations for Significant Data Fiduciaries

Section 10 of the DPDP Act introduces Significant Data Fiduciaries (SDFs) — a category of Data Fiduciaries designated by the government based on volume of data processed, sensitivity, national security risk, and public order considerations. SDFs face additional obligations beyond Section 8:

Data Protection Officer (DPO)
Must appoint a DPO who is based in India, responsible to the Board of Directors, and acts as the primary contact for the Data Protection Board.
Independent Data Auditor
Must have data processing activities audited by an independent data auditor who evaluates compliance with the Act and submits an audit report.
Data Protection Impact Assessment
Must conduct a DPIA for new high-risk data processing activities — assessing privacy risks before deployment, not after.
Algorithmic Accountability
Must assess the risk of harm from algorithmic processes — particularly AI and profiling systems — that make significant decisions about individuals.

12. Penalties for Breach of Section 8 Obligations

Section 8 Breach Penalty (Schedule)
Failure to implement security safeguards (Section 8(5)) resulting in data breach Up to ₹250 Crore
Failure to notify breach to Board or affected Data Principals (Section 8(6)) Up to ₹200 Crore
Any other breach of obligations under Section 8 Up to ₹50 Crore
Breach of Significant Data Fiduciary obligations (Section 10) Up to ₹150 Crore

13. Practical Section 8 Compliance Checklist

Use this checklist to assess your current compliance with Section 8 obligations:

Privacy Policy updated and DPDP-compliant with all mandatory disclosures
Valid consent mechanisms in place at every data collection point
Consent withdrawal mechanism available and as easy as giving consent
Data processing mapped to stated purposes — no undisclosed secondary uses
Data minimisation review completed — only necessary data collected
Data retention schedule documented and enforced with deletion procedures
Security safeguards implemented — encryption, access controls, MFA
Data breach incident response plan drafted with notification templates
Grievance Officer appointed with contact details published on website
Vendor DPAs in place with all third-party data processors
Data Principal rights mechanisms working (access, correction, erasure requests)

Section 8 Is Not Optional — It Is the Law

Every obligation in Section 8 is legally binding on your business from the moment the DPDP Act's provisions come into force. The penalties are real, the Data Protection Board will be active, and the obligation to comply falls on you — not on your IT vendor, not on your CRM provider, and not on your legal counsel.

The good news is that compliance is achievable with the right guidance. Our advocates specialise in DPDP Act compliance and can help you build a documented, defensible compliance programme — from privacy policy to breach response plan.

Get Section 8 Compliance Help →
AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp