Strategy

Data fiduciary or processor: who answers for it

Marketplaces, 3PLs and agencies all touch your customer data. The party that decided why it is being used carries the duty, and no contract moves that.

Key takeaways
  • The party that determines the purpose and means of processing carries the primary duty. Size and server ownership are irrelevant.
  • On a marketplace the platform holds the shopper relationship, but anything you pull into your own systems is yours to answer for.
  • The Act makes a fiduciary responsible for processing done on its behalf irrespective of any agreement to the contrary, so contracts allocate cost, not duty.
  • Before any customer export leaves for an agency, check it against the purpose the customer was actually told about.

Three brands sell the same lipstick. One sells only on a marketplace. One sells only on its own site. One does both, ships through a 3PL, and hands a customer list to an agency once a quarter. When something goes wrong with customer data, those three brands are not equally answerable, and the difference is not size.

The line the framework draws

The Digital Personal Data Protection Act, 2023 defines a Data Fiduciary as any person who alone or with others determines the purpose and means of processing personal data, and a Data Processor as any person who processes personal data on behalf of a Data Fiduciary. Those are sections 2(i) and 2(k) of the Act text published on meity.gov.in.

Read those two definitions slowly, because the whole allocation follows from them. The question is never who holds the server or who is bigger. It is who decided. The party that chose why this data is being used, and broadly how, carries the primary duty. The party acting on that party’s instruction carries a narrower one. A vendor with a thousand engineers can still be the one merely following instructions, and a ten person brand can still be the one deciding.

Marketplace orders: you may never hold the customer

On a marketplace, the platform owns the shopper relationship. It runs the account, sets the terms the shopper agrees to, and decides what a seller is shown. In several arrangements the seller only ever sees a masked phone number or a partially hidden address, and delivery runs on the platform’s own network. The shape of the arrangement matters more than the label. For the shopper relationship, the party determining purpose and means is the platform, not you.

There is a drafting detail worth knowing. The Third Schedule of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025, attaches an inactivity erasure period to defined classes, including an e-commerce entity with at least two crore registered users. The note to that Schedule says an e-commerce entity does not include a seller offering her goods on a marketplace e-commerce entity. That Schedule is aimed at platforms, not at you as a seller on one.

None of which makes you invisible. Whatever you pull down into your own systems, exports, remarketing files, buyer contact for service issues, you decided to pull down and you decided what it is for. Your seller agreement will also say things about the data you receive. Read that document with the same attention you give the margin arithmetic of selling there.

Your own site: it all lands on you

On D2C the picture is simple and unforgiving. You chose the checkout, the order management system, the courier, the messaging provider and the reviews tool. You determined the purposes. You are the fiduciary for all of it, and the Act says so in blunt language. Section 8(1) makes a fiduciary responsible for complying with the Act in respect of any processing undertaken by it or on its behalf by a processor, irrespective of any agreement to the contrary.

That phrase, irrespective of any agreement to the contrary, is the part brands underweight. You cannot contract your way out of the primary duty. You can allocate cost and liability between commercial parties, which is a different and still useful thing.

The 3PL, the courier and the agency

Your 3PL and your courier get a real name, a live phone number and a full address, because delivery does not work otherwise. In the ordinary case they act on your instruction to fulfil an order, which is processor shape. Two things complicate it. First, a large logistics partner often does things with delivery data for its own purposes, and to that extent it is determining purposes and answers for them itself. Second, the operational risk is not theoretical. Phone numbers and addresses moving through a delivery chain are the most exposed customer data most brands own. Ask about it while you are still choosing the 3PL, not after.

The agency case is the one that gets waved through. Somebody exports a customer list so an agency can build a lookalike audience. Ask one question before that file moves. Is this the purpose the customer was told about. If it is not, the export is the problem, and the agency is not the party that has to answer for it. You decided.

There is a concrete test of whether you know your own stack. Section 11(1)(b) of the Act gives a person the right to ask you for the identities of all other fiduciaries and processors with whom you shared her data, and a description of what was shared. If you cannot answer that from a list you already maintain, the list is the first thing to build.

Why the vendor’s breach is still your incident

Section 8(2) says a fiduciary may involve a processor only under a valid contract. Rule 6 of the 2025 Rules requires that contract to carry appropriate provision for reasonable security safeguards. So a purchase order and a verbal understanding are thin cover for a vendor that touches customer data, and the clause set is worth doing properly once. The mechanics of data ownership, exit and deletion clauses are a separate exercise.

Then there is timing. Rule 7 requires a fiduciary, on becoming aware of a personal data breach, to inform each affected person without delay, and to give the Data Protection Board detailed information within seventy-two hours of becoming aware, or within a longer period the Board allows on a written request. A vendor who learns on Monday and mentions it on Thursday has spent your clock. Put the notification obligation on them in writing, in hours, and rehearse it once. The same applies to the messaging vendor holding numbers you sent for order and refund notifications.

Our vendor had the breach is a true sentence and a useless one. The customer gave her details to your brand. This is how the work gets allocated in practice, and it is not legal advice. Your counsel reads the contracts.

The daily brief

Never miss a move

The moves that move money, every morning.

One email a day. No spam, ever.

FAQ

Quick answers.

Usually less than you think, and often masked. But most sellers pull something down: buyer contact for service issues, exports for campaigns, review follow ups. Whatever you pull down, you decided to pull down and you decided what it is for, which puts you in the deciding seat for that slice.
In the ordinary case a courier acting on your instruction to deliver an order is acting on your behalf. Where a logistics partner uses delivery data for its own purposes, it is determining those purposes and answers for them itself. Ask what they do with it and get the answer written into the contract.
Not the primary duty. Section 8(1) of the Act makes a fiduciary responsible for processing undertaken on its behalf irrespective of any agreement to the contrary. A contract can allocate cost, indemnity and notification duties between the parties, which is worth doing well.
A written contract rather than a purchase order, because the Act permits involving a processor only under a valid contract and the 2025 Rules require security safeguard provisions in it. Add a breach notification window stated in hours, a deletion instruction they must execute on request, and a named contact who answers when something goes wrong.

Related insights

From the wire

India's Commerce Engine

Put it
to work.

hello@zane.marketing

Book a meeting