The Role Matrix (The Two-Hat Entity)
Six Statutory Personas and Multi-Role Enterprise Identity Decomposition
DPDP establishes six distinct statutory personas: Data Principal, Data Fiduciary, Significant Data Fiduciary (SDF), Data Processor, Consent Manager, and the Board/State. A critical organizational reality is the 'Two-Hat' enterprise: an enterprise acts as a Data Fiduciary regarding its own employees and direct consumer customers, while simultaneously acting as a Data Processor when executing IT/SaaS workloads on behalf of corporate B2B clients.
The Role Matrix (The Two-Hat Entity)
Data Principal
s.2(t)Individual to whom personal data relates (including children and parents/guardians).
Data Fiduciary
s.2(i)Entity that determines the purpose and means of personal data processing. Bears primary liability.
Significant Data Fiduciary (SDF)
s.10Designated fiduciaries subject to heightened obligations (DPO, DPIA, annual data audit).
Data Processor
s.2(k)Processes personal data on behalf of a Data Fiduciary under a valid contract (s.8(2)).
Consent Manager
s.2(g)Interoperable, registered platform acting as single point of contact for giving/managing consent.
Data Protection Board
s.18Statutory body adjudicating breaches, hearing grievances, and issuing penalties.
๐ก Core Architectural Insights & Takeaways
Key technical and regulatory takeaways established by this architecture diagram.
๐ Statutory Grounding & Legal Perimeter
Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.
๐๏ธ Target Architecture & Impacted Systems
Enterprise nodes and store topologies impacted by this architectural pattern.
Public client boundary & untrusted intake surface for notices and consent capture
Internal employer database holding employee payroll and candidate records
Immutable consent event store and Policy Decision Point issuing authority tokens
Security log repository preserving tamper-evident dual-clock audit trails
โ๏ธ Associated Operational Controls
Control Master Matrix obligations enforcing the standards illustrated in this infographic.
๐ ๏ธ Implementation Guidance & Traps
Recommended technical sequencing and operational failure modes to avoid.
Recommended Implementation Sequence
- Classify all business units and product lines as Fiduciary or Processor.
- Execute standard Section 8(2) Data Processing Agreements for all Processor activities.
- Establish separate data segregation and access controls for B2B processor workloads.
Enterprise Traps & Failure Modes
- โ ๏ธ Assuming a B2B SaaS vendor is a Fiduciary for customer end-user data.
- โ ๏ธ Failing to recognize that employee HR processing makes an enterprise a Data Fiduciary.
๐ Verifiable Evidence Artifacts Vault
Required evidentiary workpapers for regulatory inspections and SDF audits.