Data fiduciary or processor: who answers for it
Marketplaces, 3PLs and agencies all touch your customer data. The party that decided why it is being used carries the duty, and no contract moves that.
- The party that determines the purpose and means of processing carries the primary duty. Size and server ownership are irrelevant.
- On a marketplace the platform holds the shopper relationship, but anything you pull into your own systems is yours to answer for.
- The Act makes a fiduciary responsible for processing done on its behalf irrespective of any agreement to the contrary, so contracts allocate cost, not duty.
- Before any customer export leaves for an agency, check it against the purpose the customer was actually told about.
Three brands sell the same lipstick. One sells only on a marketplace. One sells only on its own site. One does both, ships through a 3PL, and hands a customer list to an agency once a quarter. When something goes wrong with customer data, those three brands are not equally answerable, and the difference is not size.
The line the framework draws
The Digital Personal Data Protection Act, 2023 defines a Data Fiduciary as any person who alone or with others determines the purpose and means of processing personal data, and a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. Those are sections 2(i) and 2(k) of the Act text published on meity.gov.in.
Read those two definitions slowly, because the whole allocation follows from them. The question is never who holds the server or who is bigger. It is who decided. The party that chose why this data is being used, and broadly how, carries the primary duty. The party acting on that party’s instruction carries a narrower one. A vendor with a thousand engineers can still be the one merely following instructions, and a ten person brand can still be the one deciding.
Marketplace orders: you may never hold the customer
On a marketplace, the platform owns the shopper relationship. It runs the account, sets the terms the shopper agrees to, and decides what a seller is shown. In several arrangements the seller only ever sees a masked phone number or a partially hidden address, and delivery runs on the platform’s own network. The shape of the arrangement matters more than the label. For the shopper relationship, the party determining purpose and means is the platform, not you.
There is a drafting detail worth knowing. The Third Schedule of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025, attaches an inactivity erasure period to defined classes, including an e-commerce entity with at least two crore registered users. The note to that Schedule says an e-commerce entity does not include a seller offering her goods on a marketplace e-commerce entity. That Schedule is aimed at platforms, not at you as a seller on one.
None of which makes you invisible. Whatever you pull down into your own systems, exports, remarketing files, buyer contact for service issues, you decided to pull down and you decided what it is for. Your seller agreement will also say things about the data you receive. Read that document with the same attention you give the margin arithmetic of selling there.
Your own site: it all lands on you
On D2C the picture is simple and unforgiving. You chose the checkout, the order management system, the courier, the messaging provider and the reviews tool. You determined the purposes. You are the fiduciary for all of it, and the Act says so in blunt language. Section 8(1) makes a fiduciary responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a processor, irrespective of any agreement to the contrary.
That phrase, irrespective of any agreement to the contrary, is the part brands underweight. You cannot contract your way out of the primary duty. You can allocate cost and liability between commercial parties, which is a different and still useful thing.
The 3PL, the courier and the agency
Your 3PL and your courier get a real name, a live phone number and a full address, because delivery does not work otherwise. In the ordinary case they act on your instruction to fulfil an order, which is processor shape. Two things complicate it. First, a large logistics partner often does things with delivery data for its own purposes, and to that extent it is determining purposes and answers for them itself. Second, the operational risk is not theoretical. Phone numbers and addresses moving through a delivery chain are the most exposed customer data most brands own. Ask about it while you are still choosing the 3PL, not after.
The agency case is the one that gets waved through. Somebody exports a customer list so an agency can build a lookalike audience. Ask one question before that file moves. Is this the purpose the customer was told about. If it is not, the export is the problem, and the agency is not the party that has to answer for it. You decided.
There is a concrete test of whether you know your own stack. Section 11(1)(b) of the Act gives a person the right to ask you for the identities of all other fiduciaries and processors with whom you shared her data, and a description of what was shared. If you cannot answer that from a list you already maintain, the list is the first thing to build.
Why the vendor’s breach is still your incident
Section 8(2) says a fiduciary may involve a processor only under a valid contract. Rule 6 of the 2025 Rules requires that contract to carry appropriate provision for reasonable security safeguards. So a purchase order and a verbal understanding are thin cover for a vendor that touches customer data, and the clause set is worth doing properly once. The mechanics of data ownership, exit and deletion clauses are a separate exercise.
Then there is timing. Rule 7 requires a fiduciary, on becoming aware of a personal data breach, to inform each affected person without delay, and to give the Data Protection Board detailed information within seventy-two hours of becoming aware, or within a longer period the Board allows on a written request. A vendor who learns on Monday and mentions it on Thursday has spent your clock. Put the notification obligation on them in writing, in hours, and rehearse it once. The same applies to the messaging vendor holding numbers you sent for order and refund notifications.
Our vendor had the breach is a true sentence and a useless one. The customer gave her details to your brand. This is how the work gets allocated in practice, and it is not legal advice. Your counsel reads the contracts.