
DPDPA Section 8: General Obligations of Data Fiduciaries
Ensure your business meets all data privacy requirements with our comprehensive guide to DPDP Act compliance. Protect user data and avoid hefty penalties today.
Written by
Himanshu Jotwani
Date
Read time
6 min

Most privacy laws give you a maze of exceptions. DPDPA Section 8 gives you a concrete floor.
It sets the baseline data fiduciary obligations under DPDP, governing how personal data must be processed regardless of your business model, your sector, or how many third-party processors you hide behind. Other sections of India’s Digital Personal Data Protection Act might add to your workload, but nothing reduces the floor set here.
Two obligations in Section 8 never switch off. You remain responsible for compliance even when exemptions apply, and you must implement reasonable security safeguards in all cases. Treat these as non-negotiable.

Who this applies to and what it covers
- Applies to all Data Fiduciaries. It also extends to any processing carried out on your behalf by a Data Processor.
- Applies across the lifecycle: before collection, during processing, and after the purpose is served.
- Remains a baseline even where special regimes apply, such as processing children’s data or Significant Data Fiduciary duties.
Absolute accountability for processing (Section 8(1))
What it says: You are responsible for compliance in respect of any processing you do, or that a processor does on your behalf. This remains true even if your contract says otherwise, or if the individual fails to perform their duties under the Act.
What it means: Liability is non-delegable. You cannot contract out of it or argue user fault. If a vendor drops the ball, you answer to the Board and to affected Data Principals.
What changes in practice:
- Assume full accountability for your processor ecosystem. Build controls, not excuses.
- Maintain audit trails and evidence of compliance across the chain.
- Use indemnities and due diligence to manage commercial risk, but plan to pay the fine first and recover it later.
Processor engagement must be under a valid contract (Section 8(2))
What it says: You may involve processors only under a valid contract for activities related to offering goods or services to Data Principals.
What it means: No processing by vendors without a signed agreement that meets Indian contract law requirements. A handshake and a Slack message do not count.
What changes in practice:
- Do not activate a processor before contract execution.
- Ensure contracts clearly document processing instructions, security obligations, breach duties, cooperation on rights, sub-processor controls, return and deletion, and audit rights.
Data quality for consequential use and disclosure (Section 8(3))
What it says: If personal data is likely to be used to make a decision affecting the individual, or disclosed to another Data Fiduciary, you must ensure data is complete, accurate, and consistent.
What it means: You must anticipate how data will be used and apply quality controls before the decision is made or the data is shared. Bad data leading to bad decisions is now a compliance failure.
What changes in practice:
- Implement validation, reconciliation, and deduplication before decisioning or onward disclosure.
- Document quality checks as a hard gate in your processing flows.
Appropriate technical and organisational measures (Section 8(4))
What it says: You must implement measures that ensure effective observance of the Act and Rules.
What it means: Compliance must be operational, not paper-based. A policy in a Google Doc is not a measure. Measures must be appropriate to your risk profile and processing context.
What changes in practice:
- Operationalize privacy by design principles: access controls, minimisation, logging, training, and governance.
- Be able to demonstrate effectiveness with actual metrics and audits, not just good intentions.
Reasonable security safeguards (Section 8(5) and Rule 6)
What it says: You must protect personal data in your possession or control, including data processed by your processors, by taking reasonable security safeguards to prevent personal data breaches.
What it means: This duty is universal. Reasonableness is judged against technology, costs, and risks. Rule 6 details the implementation of this obligation.
What changes in practice:
- Maintain a risk-based security program that covers prevention, detection, response, and recovery.
- Extend controls to processors through contract, oversight, and evidence. The highest penalties in the Act attach to security failures.
Breach notification to the Board and affected individuals (Section 8(6) and Rule 7)
What it says: On a personal data breach, you must inform the Board and each affected Data Principal in the prescribed form and manner.
What it means: Dual notification is mandatory. Rule 7 requires immediate intimation to the Board without delay and a detailed report within 72 hours. Individuals must be informed as prescribed.
What changes in practice:
- Establish an incident response plan with legal, security, and communications roles.
- Prepare templates and contact mechanisms for Board and individual notifications before you need them.
- Ensure processors are contractually bound to notify you promptly and supply the facts you need within that unforgiving 72-hour window.
Erasure when consent is withdrawn or purpose ends (Section 8(7))
What it says: Unless retention is legally required, you must erase personal data when the Data Principal withdraws consent, or when it is reasonable to assume the specified purpose is no longer being served, whichever is earlier. You must also cause your processor to erase personal data you provided.
What it means: Erasure is an affirmative duty on you, not just a right of the individual. Legal retention obligations override erasure until they expire.
What changes in practice:
- Implement purpose-linked retention schedules, triggered erasure workflows, and processor deletion orders.
- Harmonize erasure duties with mandatory retention under applicable law or Rules. Treat such Rules as “law for the time being in force.”
When the purpose is deemed no longer served (Section 8(8), 8(11), and Rule 8)
What it says: Purpose is deemed to be no longer served if the Data Principal neither approaches you for performance of the purpose nor exercises any of their rights in relation to such processing for the prescribed time period. “Approach” means the individual initiates contact, in person or by electronic or physical communication.
What it means: Inactivity for a prescribed duration triggers a legal presumption that the purpose has ended. You cannot hoard data forever just because a user forgot to delete their account.
What changes in practice:
- Monitor user engagement and rights activity tied to purposes. Start erasure or archival workflows when the inactivity threshold is reached.
- Apply sector and purpose-specific timelines as prescribed. Different classes of Data Fiduciaries may have different timelines.
Publish contact information for queries (Section 8(9) and Rule 9)
What it says: Publish business contact information of your Data Protection Officer, if applicable, or a person who can answer questions about processing.
What it means: Make a responsible contact easily accessible. For Significant Data Fiduciaries, this will be the DPO. Others must still designate a person.
What changes in practice:
- Publish a prominent, functional contact point on websites and apps. Keep it updated and actually monitor the inbox.
- Stand up a tracked, time-bound grievance process that integrates with your operations and processors.
- Resource it to meet prescribed response timelines and to actually resolve issues, not just acknowledge them with an automated reply.

Contracts and processor chains: what good looks like
Section 8(1) makes you vicariously liable for processing done on your behalf, including by sub-processors. A “valid contract” under Section 8(2) is the gate. Use it to enforce your controls.
Practical expectations based on the Act and Rules:
- Prior approval and full disclosure of all sub-processors. Flow down all data protection obligations.
- Security obligations aligned with Rule 6, incident reporting terms that meet Rule 7 timelines, and cooperation on erasure and rights.
- Audit rights, evidence of control effectiveness, and deletion at end of engagement.
- Commercial indemnities to recover losses and penalties that arise from processor failures. These do not reduce your legal responsibility to regulators or individuals.
Governance and enforcement risk
Two anchors never relax: your absolute responsibility and your security safeguards duty. Breach of security controls attracts the highest penalties. Failure to notify a breach carries its own penalty. Regulators will look for effectiveness, not intent.
Build Section 8 into board-level oversight, lifecycle controls, and vendor governance. Treat it as an operating requirement, not a policy on a website.
Compliance teams live this daily: reconciling erasure with statutory retention, chasing processor evidence before the 72-hour report is due, configuring systems to detect inactivity under Rule 8, and keeping published contacts useful.
Ready to simplify compliance?
Explore how Regodit can organize your Section 8 obligations into clear controls, workflows, and evidence. If you want a structured, repeatable way to align your teams, vendors, and systems to the DPDPA baseline with less chaos, schedule a discussion with us.
Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.
Keep reading
All blogs →DPDPA Rule 23: Government Requests for Information from Data Fiduciaries and Intermediaries
Handling a notice under DPDP Act Rule 23 requires strict confidentiality. Discover how to respond to government data requests and ensure full compliance.
DPDPA Rule 22: Appeals to the Appellate Tribunal
Lost at the Data Protection Board? DPDPA Rule 22 governs the digital-first appeals process. Read our complete guide to filing an appeal with the Tribunal.
DPDPA Rule 21: The Machinery Behind the Data Protection Board of India
Ensure your business meets DPDP Act compliance requirements. Discover key obligations for data fiduciaries, penalty risks, and steps to protect user privacy.
