You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.
What the law says
Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Section 17(1)(d): When an organisation in India processes personal data of people outside India under a contract with a party outside India, most of the Act does not apply. The duty of security safeguards and the responsibility for processors still apply.
Steps
List each data set you handle.
For each, ask: who decides the purpose?
Mark yourself as fiduciary or processor, and name the other party.
Check that contracts match the role.
Route requests about processor data to the fiduciary.
Evidence to keep
Role register by data set
Contracts matching the role
Common mistakes
Calling yourself a processor for data you use for your own purposes