Infosek
INFOSEK

Who Is a Significant Data Fiduciary Under DPDP?

You do not become a Significant Data Fiduciary by crossing a number. You become one when the Central Government notifies you as one, and the obligations that follow are the heaviest in the framework.

Who Is a Significant Data Fiduciary Under DPDP?

The short answer

A Significant Data Fiduciary is any Data Fiduciary, or class of them, that the Central Government notifies as such under section 10. It is a designation, not a threshold you cross automatically.

Section 10(1) says the assessment is made on relevant factors the government determines, including:

What an SDF has to do that others do not

Section 10(2) sets three additional obligations:

Rule 13 then puts a clock and a reporting line on it. An SDF must undertake a Data Protection Impact Assessment and an audit once every twelve months from the date it is notified, and must cause the person carrying them out to furnish a report of significant observations to the Board.

Two obligations in Rule 13 that catch people out

Algorithmic due diligence. Rule 13(3) requires the SDF to verify that technical measures, including algorithmic software it uses for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data, are not likely to pose a risk to the rights of Data Principals. That is a standing obligation over recommendation systems, ranking and automated decisioning, not a one-off review.

Data localisation. Rule 13(4) requires the SDF to ensure that personal data specified by the Central Government, on the recommendations of a committee it constitutes, is not transferred outside India, together with the traffic data pertaining to its flow. The committee includes officials from the Ministry of Electronics and Information Technology and may include others.

The DPO reports to the board, the auditor is independent, and the audit findings go to the regulator. That combination is designed so the assessment is not something the compliance team can quietly grade itself on.

Infosek Team

The penalty position

The Schedule to the Act sets a penalty of up to ₹150 crore for breaching the additional obligations of a Significant Data Fiduciary under section 10. That sits on top of the general heads, so an SDF that suffers a breach can be exposed under section 8(5), section 8(6) and section 10 for the same incident.

What to do if you might be notified

Common questions

Who is a Significant Data Fiduciary under the DPDP Act?

Any Data Fiduciary or class of Data Fiduciaries that the Central Government notifies as such under section 10 of the DPDP Act 2023. The assessment considers the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.

Does every company need a Data Protection Officer under DPDP?

No. The obligation to appoint a Data Protection Officer applies to Significant Data Fiduciaries under section 10(2)(a). The DPO must be based in India and be responsible to the board of directors or similar governing body.

Think you may be notified as an SDF?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment