Back to Key Provisions
Significant Data Fiduciaries
Analysis of the Significant Data Fiduciary designation under the DPDPA - criteria, enhanced obligations, DPO appointment, DPIA, and audit requirements.
9 min read
What is a Significant Data Fiduciary?
Section 10 of the DPDPA empowers the Central Government to designate certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on an assessment of specified factors. SDFs face enhanced compliance obligations beyond those applicable to ordinary Data Fiduciaries.
This tiered approach allows the Act to impose proportionate obligations - lighter for smaller entities and more rigorous for organisations that pose greater risks to data protection.
Designation Criteria (Section 10(1))
The Central Government may consider the following factors when designating SDFs:
• Volume and sensitivity of personal data processed
• Risk to the rights of Data Principals
• Potential impact on the sovereignty and integrity of India
• Risk to electoral democracy
• Security of the State
• Public order
The DPDP Rules (R.13) further operationalise these criteria, providing guidance on the assessment methodology and thresholds.
Designation is by government notification - entities are individually identified, not automatically classified based on size or sector. This differs from the GDPR, where enhanced obligations apply based on objective criteria (e.g., "large-scale processing"). Unlike the GDPR's objective thresholds (e.g., number of data subjects), the Indian Government retains discretionary power to notify any entity as an SDF based on the listed risks (sovereignty, electoral democracy, etc.).
Data Protection Officer (Section 10(2)(a))
SDFs must appoint a Data Protection Officer (DPO) who:
• Is based in India
• Represents the SDF before the Board
• Serves as the point of contact for Data Principals
• Is responsible for monitoring compliance
The DPO must have appropriate qualifications and expertise. Unlike the GDPR's DPO, the DPDPA's DPO is specifically required to be based in India, reflecting the Act's territorial focus. The Act also mandates that the DPO must be 'an individual responsible to the Board of Directors or similar governing body' (Section 10(2)(a)(iii)) - this internal reporting line is as critical as the residency requirement.
The DPO's contact details must be published and made available to Data Principals and the Board.
Data Protection Impact Assessment (Section 10(2)(b))
SDFs must conduct Data Protection Impact Assessments (DPIAs) to evaluate:
• The nature and scope of personal data processing
• Risks to the rights of Data Principals
• Adequacy of safeguards and mitigation measures
• Compliance with the Act's requirements
Under the DPDP Rules, 2025, 'periodic' has been quantified - Rule 13(1) mandates a DPIA at least once every 12 months (annually). DPIAs must be submitted to the Board. This is a proactive compliance mechanism that requires SDFs to identify and address risks before they materialise.
The DPIA framework under the DPDPA is less prescriptive than the GDPR's (which requires DPIAs for specific high-risk processing activities). The DPDPA mandates annual assessments regardless of the specific processing activity.
Independent Audit (Section 10(2)(c))
SDFs must arrange for audits of their data processing practices by an independent data auditor. The audit must assess:
• Compliance with the Act and Rules
• Effectiveness of security safeguards
• Adequacy of data protection practices
Under Rule 13(1) of the DPDP Rules, 2025, the independent audit must be conducted annually. The audit must be performed by an auditor independent of the SDF. The Board may prescribe the qualifications and registration requirements for data auditors.
This audit requirement creates an additional layer of accountability and provides the Board with independently verified compliance information.
Algorithmic Software Verification (Rule 13)
Rule 13(3) requires SDFs to undertake 'due diligence' to ensure that any technical measures, including algorithmic software deployed for processing personal data, are not likely to pose a risk to the rights of Data Principals.
This obligation requires SDFs to:
• Assess algorithms used in automated decision-making for fairness and bias
• Evaluate the risk of algorithmic outcomes on Data Principal rights
• Document the verification process and findings
• Periodically re-evaluate as algorithms are updated or retrained
This is a forward-looking provision that addresses the growing use of AI and machine learning in data processing, ensuring that automated systems do not inadvertently harm individual rights.
Practical Implications
Organisations that anticipate SDF designation should proactively:
1. Identify a suitable DPO candidate with India-based presence
2. Develop a DPIA methodology and conduct baseline assessments
3. Engage independent auditors and establish audit protocols
4. Build internal compliance reporting structures
5. Allocate budget for the enhanced compliance infrastructure
6. Establish a process to verify that algorithmic software does not pose risks to Data Principal rights
The enhanced obligations represent a significant compliance investment, but also provide a competitive advantage - SDF status signals a higher standard of data protection that can build trust with customers and regulators.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
