Section 8 of DPDP Act 2023 establishes general obligations of every Data Fiduciary regardless of size or significance. Section 8(1): A Data Fiduciary shall be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. Section 8(2) Engagement of Processor: A Data Fiduciary may engage + appoint + use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals + only under a valid contract (Data Processing Agreement DPA covering scope + purpose + duration + technical and organisational measures + confidentiality + sub-processor approval + assistance + audit rights + breach notification + return/deletion at end). Section 8(3) Accuracy + Completeness + Consistency: where Personal Data processed by Data Fiduciary is likely to be used for making any decision which affects Data Principal + or to be disclosed to another Data Fiduciary + the Data Fiduciary shall ensure its completeness + accuracy + and consistency. Section 8(4) Reasonable Security Safeguards: Every Data Fiduciary shall protect personal data in its possession or under its control + including in respect of any processing undertaken by it or on its behalf by a Data Processor by taking reasonable security safeguards to prevent personal data breach (TOMs technical and organisational measures including encryption + pseudonymisation + access controls + segregation + backup + restore + DR + secure software development + secure operations + vulnerability management + incident response + records of processing activities). Section 8(5) Personal Data Breach Notification: in the event of a personal data breach + the Data Fiduciary shall give the Board (DPBI) and each affected Data Principal intimation of such breach in such form and manner as may be prescribed (per DPDP Rules 2025 - 72 hours to DPBI per Section 8(6); intimation to affected Data Principals as soon as practicable). Section 8(7) Personal Data Erasure: Data Fiduciary shall erase Personal Data upon the Data Principal withdrawing her consent + or as soon as it is reasonable to assume that the specified purpose is no longer being served + whichever is earlier + and cause its Data Processors to erase. Section 8(8) Effective Mechanism for Grievance: establish effective grievance redressal mechanism for Data Principals. Section 8(9) Publication of Business Contact Information: publish business contact info of Data Protection Officer (DPO for SDFs) or other person authorised to respond to data principal communications. Coordinates with GDPR Art 5 + 24 + 28 + 32 + 33 + 34 + RBI Account Aggregator + ISO 27001 + ISO 27701 + NIST Privacy Framework + India CERT-In Directions 2022 + IT Act Sec 43A. DPDP Sec 8 Data Fiduciary Obligations applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.