DPDPA Section 8 — General obligations of a Data Fiduciary
Applies to: Data Fiduciary
What this section does
The core accountability section. The Data Fiduciary remains responsible for compliance even when a Data Processor acts on its behalf, must ensure data accuracy, implement reasonable security safeguards, notify breaches, erase data when the purpose is served, and publish grievance contact details.
Plain-English summary prepared by KensaraAI — not the statutory text. Read the official Act ↗
What you have to do
- ▸ Accountability persists through processors and sub-processors
- ▸ Implement reasonable security safeguards
- ▸ Notify the Board and affected Data Principals of a breach
- ▸ Erase personal data once the purpose is served or consent withdrawn
- ▸ Publish a Data Protection Officer / grievance contact
Enforcement under this section (0)
No enforcement action citing this section has been recorded yet. The Data Protection
Board is not yet issuing penalties under the DPDPA — this page will populate as
enforcement begins.