Indian Journal for Research in Law and Management

Advancing Law and Management

ISSN No. : 2583-9896

NEED FOR A 'JOINT DATA FIDUCIARY' FRAMEWORK IN INDIA: LESSONS FROM THE GDPR'S JOINT CONTROLLERS CONCEPT

Cite this Article

Hitesh Bhootra (2026). NEED FOR A 'JOINT DATA FIDUCIARY' FRAMEWORK IN INDIA: LESSONS FROM THE GDPR'S JOINT CONTROLLERS CONCEPT. The Indian Journal for Research in Law and Management, Volume III(Issue 11). Retrieved from https://ijrlm.com/journal/need-for-a-joint-data-fiduciary-framework-in-india-lessons-from-the-gdprs-joint-controllers-concept/

Abstract

India's Digital Personal Data Protection Act, 2023 (DPDPA) establishes a framework centred on the distinction between Data Fiduciaries and Data Processors. While this model is suitable for conventional data-processing relationships, it does not adequately reflect the realities of today's interconnected digital economy, where multiple entities frequently participate in determining how and why personal data is processed. Digital lending arrangements, healthcare platforms, online marketplaces, advertising technology, and other collaborative digital ecosystems increasingly involve shared decision-making, creating uncertainty over accountability when privacy obligations are breached. This paper argues that the absence of an explicit framework governing entities that jointly determine the purposes and means of processing personal data constitutes a significant structural gap in India's data protection regime. Drawing on comparative developments in European data protection law, the paper demonstrates that accountability can be allocated according to the actual influence exercised by participating entities over specific processing activities, rather than relying solely on formal contractual designations. It further contends that a functional approach to shared responsibility would better protect data principals while providing greater legal certainty to businesses operating in collaborative digital environments. The paper proposes the introduction of a "Joint Data Fiduciary" framework through subordinate legislation or regulatory guidance under the DPDPA. It recommends recognising shared decision-making based on substance rather than form, requiring transparent allocation of compliance responsibilities among participating entities, limiting liability to the processing activities over which an entity exercises genuine control, and ensuring that data principals may effectively enforce their statutory rights without navigating complex contractual arrangements. Such a framework would strengthen accountability, align the DPDPA with India's constitutional commitment to informational privacy, and provide a more practical regulatory foundation for the country's rapidly evolving digital ecosystem.

Journal Information

The Indian Journal for Research in Law and Management
ISSN No.
2583-9896
Submit Manuscript
Licensing
All research articles published in The Indian Journal for Research in Law and Management are fully open-access. i.e. immediately freely available to read, download, and share. Articles are published under the terms of a Creative Commons license, which permits use, distribution, and reproduction in any medium, provided the original work is properly cited.
Disclaimer
The opinions expressed in this publication are those of the authors. They do not purport to reflect the opinions or views of the IJRLM or its members. The designations employed in this publication and the presentation of material therein do not imply the expression of any opinion whatsoever on the part of the IJRLM.

Article Analytics

28
Page Views
1
Downloads