Who Is a Significant Data Fiduciary Under DPDP?
You do not become a Significant Data Fiduciary by crossing a number. You become one when the Central Government notifies you as one, and the obligations that follow are the heaviest in the framework.
The short answer
A Significant Data Fiduciary is any Data Fiduciary, or class of them, that the Central Government notifies as such under section 10. It is a designation, not a threshold you cross automatically.
Section 10(1) says the assessment is made on relevant factors the government determines, including:
- The volume and sensitivity of personal data processed.
- Risk to the rights of Data Principals.
- Potential impact on the sovereignty and integrity of India.
- Risk to electoral democracy.
- Security of the State.
- Public order.
What an SDF has to do that others do not
Section 10(2) sets three additional obligations:
- Appoint a Data Protection Officer who represents the SDF under the Act, is based in India, is an individual responsible to the board of directors or similar governing body, and is the point of contact for the grievance redressal mechanism.
- Appoint an independent data auditor to carry out a data audit evaluating compliance with the Act.
- Undertake periodic Data Protection Impact Assessments, along with other prescribed measures.
Rule 13 then puts a clock and a reporting line on it. An SDF must undertake a Data Protection Impact Assessment and an audit once every twelve months from the date it is notified, and must cause the person carrying them out to furnish a report of significant observations to the Board.
Two obligations in Rule 13 that catch people out
Algorithmic due diligence. Rule 13(3) requires the SDF to verify that technical measures, including algorithmic software it uses for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data, are not likely to pose a risk to the rights of Data Principals. That is a standing obligation over recommendation systems, ranking and automated decisioning, not a one-off review.
Data localisation. Rule 13(4) requires the SDF to ensure that personal data specified by the Central Government, on the recommendations of a committee it constitutes, is not transferred outside India, together with the traffic data pertaining to its flow. The committee includes officials from the Ministry of Electronics and Information Technology and may include others.
The DPO reports to the board, the auditor is independent, and the audit findings go to the regulator. That combination is designed so the assessment is not something the compliance team can quietly grade itself on.
Infosek Team
The penalty position
The Schedule to the Act sets a penalty of up to ₹150 crore for breaching the additional obligations of a Significant Data Fiduciary under section 10. That sits on top of the general heads, so an SDF that suffers a breach can be exposed under section 8(5), section 8(6) and section 10 for the same incident.
What to do if you might be notified
- Identify who would credibly serve as an India-based DPO answerable to your board. This is a governance appointment, not a job title reassignment.
- Establish whether your auditor would qualify as independent. An internal team almost certainly does not.
- Start the DPIA now rather than on notification. Rule 13 gives twelve months from notification, and a first assessment on unmapped systems takes longer than that suggests.
- Inventory what personal data crosses borders, and the traffic data associated with it, because Rule 13(4) may require it to stop.
Common questions
Who is a Significant Data Fiduciary under the DPDP Act?
Any Data Fiduciary or class of Data Fiduciaries that the Central Government notifies as such under section 10 of the DPDP Act 2023. The assessment considers the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
Does every company need a Data Protection Officer under DPDP?
No. The obligation to appoint a Data Protection Officer applies to Significant Data Fiduciaries under section 10(2)(a). The DPO must be based in India and be responsible to the board of directors or similar governing body.
Think you may be notified as an SDF?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment