India's DPDP Act comes with a vocabulary of roles, and they matter because they assign responsibility. If your organisation collects personal data — including visitor data at the front desk — it is worth knowing which role you play and what it entails. This is a plain explainer, not legal advice.
Data Fiduciary and Data Principal
The Data Fiduciary is the entity that decides why and how personal data is processed — that is your organisation when you collect visitor details. The Data Principal is the individual the data is about — the visitor. The Fiduciary carries the obligations; the Principal holds the rights, as covered in DPDP data-principal rights.
Data Processor
A Data Processor processes data on behalf of a Fiduciary — for example, a software provider handling data under your instructions. The responsibility to the Data Principal still rests with the Fiduciary.
Significant Data Fiduciary and the DPO
The Act allows certain organisations to be classed as Significant Data Fiduciaries, based on factors like the volume and sensitivity of data, with additional obligations — including appointing a Data Protection Officer (DPO) as a point of contact and accountability. Whether you fall into this class depends on the notified criteria.
What it means practically
- Know whether you are acting as Fiduciary or Processor for a given dataset.
- Understand your obligations — consent, security, retention, rights.
- Identify who is accountable, and whether a DPO is required.
- Document it, so you can demonstrate accountability.
How Certopact fits
For visitor data you collect, you are typically the Data Fiduciary and Certopact a processor acting on your instructions, with security and retention controls to support your obligations — see the DPDP Act and visitor data. This is general information, not legal advice; confirm your roles and obligations with your own counsel.