Back to DPDP Rules
Significant Data Fiduciary Obligations (R.12)
Rule 12 enhanced obligations for SDFs - DPO appointment, annual DPIA, independent audits, algorithmic verification, and reporting to the Data Protection Board.
7 min read
Data Protection Officer
Under the notified DPDP Rules, 2025, the additional obligations for Significant Data Fiduciaries (SDFs) are consolidated under Rule 12 (not Rule 13, which now generally covers Data Principal rights). Rule 12 requires SDFs to appoint a Data Protection Officer (DPO) with the following requirements:
• The DPO must be Resident in India - the law uses the term 'Resident in India' to ensure legal jurisdiction and accountability under Indian tax and residency laws
• The DPO represents the organisation before the Data Protection Board
• The DPO must be an individual responsible to the Board of Directors or similar governing body of the SDF (Section 10(2)(a)(iii))
• The DPO serves as the primary point of contact for Data Principals and the Board
Clarification: While the DPO is the point of contact for SDFs, Rule 9 also requires the publication of the contact details of a 'person to answer questions' (Grievance Officer), who may be different from the DPO for non-SDFs.
This structure ensures that data protection has board-level visibility and that the designated officer can effectively engage with the regulatory authority.
Data Protection Impact Assessment
Rule 12(1)(a) explicitly mandates an annual Data Protection Impact Assessment (DPIA) - at least once every 12 months - removing the ambiguity of 'periodic.' The DPIA should:
• Identify and assess risks to Data Principal rights from processing activities
• Evaluate the necessity and proportionality of processing in relation to stated purposes
• Identify measures to mitigate identified risks
• Document the assessment methodology, findings, and mitigation measures
SDFs should establish DPIA processes using a structured DPIA Framework and align documentation cycles with the annual cadence.
Independent Audit
SDFs must undertake annual independent audits by an Independent Data Auditor. The audit should:
• Verify compliance with the DPDPA and DPDP Rules
• Assess the effectiveness of security safeguards
• Review consent management practices
• Evaluate data retention and erasure procedures
• Examine breach response preparedness
The auditor must be independent - not employed by or affiliated with the SDF - and may need to meet specific certifications (e.g., CISA or empanelment recognised by the Board).
Reporting obligation: Per Rule 12(2), the SDF must furnish a report of significant observations from the DPIA and audit to the Data Protection Board (DPB). Internal reporting to the SDF's own board of directors alone is not sufficient for compliance.
Algorithmic Verification
Rule 12(3) introduces a unique requirement for SDFs in respect of algorithmic software. The notified rule uses broader language than mere 'monitoring': SDFs must verify that technical measures, including algorithmic software used in connection with hosting, display, sharing, or processing of personal data, do not pose likely risks to the rights of Data Principals.
This requirement is particularly relevant for organisations using AI/ML, automated decision-making, profiling, and recommendation systems. Verification should include:
• Bias detection and fairness assessments
• Accuracy verification of algorithmic outputs
• Impact assessment of algorithmic decisions on Data Principals
• Regular review of training data quality and representativeness
• Documentation of algorithmic verification findings and remedial actions
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
