Tuesday, December 23, 2025

Under India’s DPDPA: Who Is Liable When an Indian Firm Processes Data for a US Controller?

 

🎯 Short Answer

The US firm (as the Data Fiduciary) is primarily liable under the DPDPA. The Indian firm (as the Data Processor) has no direct statutory liability under the Act — but it can still face contractual liability and indirect exposure if its failures cause the fiduciary to violate the law.

📘 What the Law and Commentary Say

1. DPDPA places primary accountability on the Data Fiduciary

The Act adopts a fiduciary‑centric model:

  • The entity that determines purpose and means of processing is the Data Fiduciary (equivalent to GDPR controller).

  • The fiduciary is responsible for consent, notices, rights, breach notification, safeguards, and ensuring processor compliance.

This is explicitly stated in legal analyses:

  • The DPDP Act “places primary liability on fiduciaries” and processors operate in a subordinate role.

  • The Act “attributes sole responsibility upon the main custodians of data… even when the actual processing is undertaken by processors”.

  • Unlike GDPR, the DPDPA does not impose direct statutory obligations or penalties on processors.

2. Processors (Indian firm) have obligations only via contract

Processors must:

  • Act only on instructions

  • Maintain security safeguards

  • Restrict sub‑processing

  • Cooperate with the fiduciary

  • Maintain records

But these obligations are contractual, not statutory. If they fail, the fiduciary is still liable to the Data Protection Board.

3. Cross‑border scenario does NOT change liability

If a US company determines purpose/means, it is the Data Fiduciary, even if it is outside India. DPDPA applies because the processing happens in India.

Thus:

  • US firm = Data Fiduciary = legally liable under DPDPA

  • Indian firm = Data Processor = no direct liability under DPDPA

4. However, the Indian processor can still be penalized indirectly

If the processor’s negligence causes a breach or non‑compliance:

  • The Data Fiduciary is penalized by the Board

  • The fiduciary can recover losses contractually (indemnity, breach of DPA, SLA penalties)

So the Indian firm’s exposure is commercial, not regulatory.

🧭 Practical Implication for Your Governance Work

When drafting DPAs for US clients:

  • Make the fiduciary’s DPDPA obligations flow down contractually

  • Include indemnities, audit rights, breach timelines

  • Ensure sub‑processor controls mirror DPDPA expectations

  • Clarify that the processor has no independent obligations under DPDPA, but must support the fiduciary’s compliance

This aligns with the Act’s design and the commentary from leading Indian law firms.

The Priority Gap: When Patchability Does Not Equal Protection

Vulnerability management often fails at the point where security mandates collide with IT operations, creating a Priority Gap between vulne...