Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the difference between a data fiduciary…
Governance, Ownership & Risk

What is the difference between a data fiduciary under DPDPA and a data protection authority under GDPR?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

A data fiduciary is the organisation or entity that decides the purpose and means of personal data processing. A data protection authority is the regulator that supervises compliance and enforces the law. The two are not interchangeable. One manages processing responsibilities, while the other monitors, investigates, and can impose penalties when obligations are breached.

How the two roles differ in the law

The difference is structural, not just terminological. Under DPDPA, the data fiduciary is the entity that decides why and how personal data is processed, so it carries the operational duty to justify processing, secure it, and act on data subject rights. Under GDPR, the data protection authority is the public regulator that supervises compliance, investigates complaints, and enforces the law.

A useful way to read the distinction is that the fiduciary sits inside the processing activity, while the authority sits outside it. The fiduciary makes and executes processing decisions; the authority tests whether those decisions comply with the law and intervenes when they do not.

That split matters in practice because the fiduciary is accountable for day-to-day design and controls, while the authority has supervisory powers such as inquiry, corrective action, and penalties. The relationship is therefore asymmetric: one role creates and runs the processing posture, the other oversees and remedies it.

Who owes duties, and who exercises oversight?

A data fiduciary is usually the organisation that collects, uses, stores, shares, or otherwise processes personal data in pursuit of a defined purpose. Its duties are framed around lawful processing, proportionality, security, retention, and handling requests from individuals. The Identity Security Regulatory Map is useful for seeing how governance obligations map across regimes such as GDPR and related control domains.

A data protection authority, by contrast, is a statutory regulator such as a national supervisory authority under GDPR. It does not process the data as the business owner would; it checks whether the controller or processor has a lawful basis, proper safeguards, and compliant procedures. In that sense, the authority is an enforcement and oversight mechanism, not a processing role.

Because the roles sit on opposite sides of the compliance boundary, they answer different questions. The fiduciary answers, "Are we allowed to process this data, and have we controlled it properly?" The authority answers, "Have you complied, and what remedy is required if you have not?"

Why the distinction matters in governance and enforcement

In governance terms, the fiduciary is responsible for building the control environment, while the authority is responsible for validating and, if necessary, correcting it. That means the fiduciary must be able to document purpose limitation, lawful basis, retention, security, and response processes, whereas the authority expects evidence that those controls actually operate in practice. The EU General Data Protection Regulation (GDPR) is the core reference for those supervisory and processing obligations.

This distinction also affects how organisations think about risk. If a fiduciary misunderstands its role, it may over-collect data, retain it too long, or treat compliance as a legal afterthought instead of a design constraint. If a regulator is misunderstood as a business role, teams may incorrectly expect it to approve processing decisions in advance, when its real function is supervision and enforcement after the rules are set.

For practitioners, the key implication is that compliance evidence must be assembled by the fiduciary, not presumed to be supplied by the authority. The regulator may issue guidance, investigate, and impose corrective measures, but it does not assume the fiduciary's internal accountability for data handling.

Risk and Threat Considerations

The main risk is role confusion, because it leads organisations to assign compliance ownership to the wrong party. When that happens, processing decisions may be made without clear accountability, response timelines slip, and violations can persist until a complaint or investigation forces remediation.

Failure mechanism: The fiduciary treats regulatory oversight as if it were operational ownership, or assumes the authority will validate each decision in advance, creating gaps in lawful basis, controls, and evidence.

Impact: Personal data may be processed without adequate justification or safeguards, increasing exposure to supervisory action, enforcement orders, fines, and avoidable operational disruption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 4(7) — ControllerDefines the party that determines purposes and means of processing, matching the fiduciary concept.
Art. 51 — Supervisory authorityCreates the independent authority role that oversees GDPR compliance and enforcement.
Art. 58 — PowersCovers the authority's investigative and corrective powers central to the distinction.
Recommendation — Assign processing accountability to the controller and document lawful purposes and means. Route compliance oversight and enforcement questions to the supervisory authority. Prepare to respond to investigations, orders, and corrective measures from the authority.
ISO/IEC 27001:2022A.5.34 — Privacy and protection of PIISupports governance over personal-data handling and accountability controls.
Recommendation — Map personal-data processing duties to documented privacy and protection controls.
NIST SP 800-53 Rev 5AU-2 — Event LoggingSupports evidence generation for compliance and supervisory review.
Recommendation — Log processing and access events so compliance evidence is available on demand.

Practitioner Guidance

What to verify: Confirm that the entity acting as the fiduciary can demonstrate a named purpose, a lawful basis, a retention rule, and a documented path for handling rights requests and complaints. If any of those are owned by a different team but not formally assigned, the governance model is too weak.

What good looks like: The fiduciary has internal decision records, policies, and evidence of control operation; the authority remains external, independent, and able to supervise without being treated as part of the operating chain. That separation should be obvious in contracts, policies, and escalation paths.

Practitioner takeaway: Treat the fiduciary as the accountable operator of personal-data processing and the authority as the independent checker of that operation. If those roles blur, compliance failures usually come from ownership gaps, not from missing legal theory.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org