🎯 Short Answer
The US firm (as the Data Fiduciary) is primarily liable under the DPDPA. The Indian firm (as the Data Processor) has no direct statutory liability under the Act — but it can still face contractual liability and indirect exposure if its failures cause the fiduciary to violate the law.
📘 What the Law and Commentary Say
1. DPDPA places primary accountability on the Data Fiduciary
The Act adopts a fiduciary‑centric model:
The entity that determines purpose and means of processing is the Data Fiduciary (equivalent to GDPR controller).
The fiduciary is responsible for consent, notices, rights, breach notification, safeguards, and ensuring processor compliance.
This is explicitly stated in legal analyses:
The DPDP Act “places primary liability on fiduciaries” and processors operate in a subordinate role.
The Act “attributes sole responsibility upon the main custodians of data… even when the actual processing is undertaken by processors”.
Unlike GDPR, the DPDPA does not impose direct statutory obligations or penalties on processors.
2. Processors (Indian firm) have obligations only via contract
Processors must:
Act only on instructions
Maintain security safeguards
Restrict sub‑processing
Cooperate with the fiduciary
Maintain records
But these obligations are contractual, not statutory. If they fail, the fiduciary is still liable to the Data Protection Board.
3. Cross‑border scenario does NOT change liability
If a US company determines purpose/means, it is the Data Fiduciary, even if it is outside India. DPDPA applies because the processing happens in India.
Thus:
US firm = Data Fiduciary = legally liable under DPDPA
Indian firm = Data Processor = no direct liability under DPDPA
4. However, the Indian processor can still be penalized indirectly
If the processor’s negligence causes a breach or non‑compliance:
The Data Fiduciary is penalized by the Board
The fiduciary can recover losses contractually (indemnity, breach of DPA, SLA penalties)
So the Indian firm’s exposure is commercial, not regulatory.
🧭 Practical Implication for Your Governance Work
When drafting DPAs for US clients:
Make the fiduciary’s DPDPA obligations flow down contractually
Include indemnities, audit rights, breach timelines
Ensure sub‑processor controls mirror DPDPA expectations
Clarify that the processor has no independent obligations under DPDPA, but must support the fiduciary’s compliance
This aligns with the Act’s design and the commentary from leading Indian law firms.
No comments:
Post a Comment