Section 8 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 8(3) requires a Data Fiduciary to ensure that personal data is complete, accurate and consistent where it is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary. Section 8(4) requires appropriate technical and organisational measures to make the Act's observance effective. A short legal consultation can help map where your data feeds decisions.
Where personal data is likely to be used to make a decision that affects the Data Principal, or likely to be disclosed to another Data Fiduciary, the fiduciary processing it must ensure its completeness, accuracy and consistency (section 8(3)). Separately, it must implement appropriate technical and organisational measures to ensure effective observance of the Act and the rules (section 8(4)). There is no specific Schedule entry, so a breach falls under the fifty crore rupee ceiling for any other provision.
Sub-sections (3) and (4) at a glance
| Sub-section | Trigger | Duty |
|---|---|---|
| 8(3)(a) | Data likely to be used to make a decision that affects the Data Principal | Ensure completeness, accuracy and consistency |
| 8(3)(b) | Data likely to be disclosed to another Data Fiduciary | Ensure completeness, accuracy and consistency |
| 8(4) | Always | Implement appropriate technical and organisational measures to ensure effective observance of the Act and the rules |
Section 8(3): accuracy is triggered by use
The duty is not a blanket "keep all data accurate". It is conditional on two situations, each using the words "is likely to be":
- (a) used to make a decision that affects the Data Principal. Examples are credit approval, hiring or promotion, insurance pricing, service eligibility or account suspension. The Act does not define "a decision that affects" her, so read it by ordinary meaning: an outcome that changes her position.
- (b) disclosed to another Data Fiduciary. Sharing data with a group company, a credit bureau, a business partner or a marketplace seller engages the duty, even if no decision is made at your end.
The "likely" wording means you cannot wait until the data is actually used. If a record is held for a purpose where decisions are an ordinary outcome, the duty is already on you. "Data Fiduciary processing such personal data" is the bound party, which includes a fiduciary that received the data from another.
Three words deserve a separate look. Completeness means missing fields that change the picture, for example a loan record showing a default but not the later settlement. Accuracy means correct facts. Consistency means the same person's data does not differ across your systems, for example two addresses in CRM and billing with no rule for which prevails. The text gives no test or standard, so the assessment is factual: what you did to keep data fit for the decision.
Interaction with the Data Principal's right to correction
Section 12(2) says that on a Data Principal's request the fiduciary must correct inaccurate or misleading data, complete incomplete data and update it. Section 8(3) works on the fiduciary's own initiative; section 12 works on request. Section 15(e) in turn requires the Data Principal to furnish only verifiably authentic information when exercising the right to correction or erasure. See section 12.
Where section 8(3) may not apply
Section 17(3) lets the Central Government notify certain Data Fiduciaries or classes, including startups, to whom section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 do not apply. That covers sub-section (3) of section 8, but only where such a notification exists. The other exemptions in section 17(1) switch off Chapter II except sub-sections (1) and (5) of section 8, so sub-section (3) is exempt in those cases. Check the notifications for your category. See section 17(3).
Section 8(4): "technical and organisational measures"
Section 8(4) is general and short. The fiduciary "shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder". The Act gives no list, so the standard is that the measures be appropriate and effective. In practice, this is the accountability layer that sits behind every other obligation:
- Technical: access controls, logging, encryption, automated retention and deletion, consent records, a way to route a withdrawal to all systems.
- Organisational: a named owner for compliance, written policies, staff training, a vendor register, an incident playbook, periodic internal review.
It is different from section 8(5), which is specifically about security safeguards to prevent a personal data breach and carries its own higher penalty. Section 8(4) is about making the whole Act work in the organisation. See reasonable security safeguards.
The word "appropriate" scales with the business. A five-person firm and a national platform will not look alike. Section 33(2) does not use "appropriateness" but does require the Board to weigh the nature of the data, the gravity and duration of a breach and mitigation, which in practice is where documented measures help.
Consequence of breach
There is no dedicated Schedule entry for section 8(3) or 8(4). Item 7 of the Schedule covers breach of any other provision of the Act or the rules: penalty may extend to fifty crore rupees. The Board can impose it only after an inquiry, a hearing, and a determination that the breach is significant (section 33(1)). Inaccurate data that leads to a data breach could additionally engage section 8(5), which has its own entry. See penalties.
Practical examples
Example 1: lender and bureau. A lender shares repayment data with another Data Fiduciary. If the lender has not updated a settled account, the data is incomplete and inaccurate at the point of disclosure. Section 8(3)(b) is the relevant duty.
Example 2: hiring tool. An employer uses applicant records to shortlist candidates. The decision affects the applicant, so section 8(3)(a) expects reasonably complete, accurate and consistent records, for example no mix-up between two candidates with the same name.
Example 3: no owner for compliance. A company has a privacy policy on its website but no process to route requests, no training and no vendor list. The gap is one of organisational measures under section 8(4).
Common mistakes
- Treating accuracy as only a Data Principal's right to ask, not as the fiduciary's own duty.
- Ignoring disclosure to other fiduciaries because "no decision is made here".
- Relying on a policy document as the only measure.
- Confusing section 8(4) with security safeguards in section 8(5).
Need help with data quality and accountability measures?
If you are unsure which of your systems feed decisions or get shared with other businesses, a structured review helps set priorities. Speak to us under our legal consultation service to shape practical measures for your size of business.
Key takeaways
- The accuracy duty is triggered by likely decisions affecting the Data Principal or likely disclosure to another Data Fiduciary.
- It covers completeness, accuracy and consistency.
- Technical and organisational measures must be appropriate and effective.
- No Schedule entry is specific to these sub-sections; the fifty crore ceiling for other provisions applies.
- Section 17(3) notifications, if any, can remove sub-section (3) for certain fiduciaries.
Read next
- Section 8 of the DPDP Act, 2023: reasonable security safeguards
- Section 12 of the DPDP Act, 2023: right to correction and erasure
- Section 8 of the DPDP Act, 2023: responsibility for compliance and Data Processors
- DPDP compliance checklist for businesses
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
