Chapter II — Obligations

DPDPA Section 8 — General obligations of a Data Fiduciary

Applies to: Data Fiduciary

What this section does

The core accountability section. The Data Fiduciary remains responsible for compliance even when a Data Processor acts on its behalf, must ensure data accuracy, implement reasonable security safeguards, notify breaches, erase data when the purpose is served, and publish grievance contact details.

Plain-English summary prepared by KensaraAI — not the statutory text. Read the official Act ↗

What you have to do

  • ▸ Accountability persists through processors and sub-processors
  • ▸ Implement reasonable security safeguards
  • ▸ Notify the Board and affected Data Principals of a breach
  • ▸ Erase personal data once the purpose is served or consent withdrawn
  • ▸ Publish a Data Protection Officer / grievance contact

Enforcement under this section (0)

No enforcement action citing this section has been recorded yet. The Data Protection Board is not yet issuing penalties under the DPDPA — this page will populate as enforcement begins.

Related sections

Automate compliance with Section 8

KensaraAI maps your processing to each DPDPA obligation and keeps the evidence trail regulators ask for.

Request a Demo