Under the notified DPDP Rules, 2025, the additional obligations for Significant Data Fiduciaries (SDFs) are consolidated under Rule 13. Rule 13 requires SDFs to appoint a Data Protection Officer (DPO) with the following requirements:
• The DPO must be Resident in India - the law uses the term 'Resident in India' to ensure legal jurisdiction and accountability under Indian tax and residency laws
• The DPO represents the organisation before the
Data Protection Board
• The DPO must be an individual responsible to the Board of Directors or similar governing body of the SDF (Section 10(2)(a)(iii))
• The DPO serves as the primary point of contact for Data Principals and the Board
Clarification: While the DPO is the point of contact for SDFs, Rule 9 also requires the publication of the contact details of a 'person to answer questions' (Grievance Officer), who may be different from the DPO for non-SDFs.
This structure ensures that data protection has board-level visibility and that the designated officer can effectively engage with the regulatory authority.