Significant Data Fiduciary
Do you need a Data Protection Officer, independent audits, impact assessments? Almost certainly not — and no one does yet. Here's who the 'Significant Data Fiduciary' rules are actually for.
What a Significant Data Fiduciary is
Under Section 10, the government can designate a data fiduciary — or a whole class of them — as "Significant".
Designation weighs several things: how much personal data you handle, how sensitive it is, the risk to people's rights, and risks to the security of the State. It's not a punishment. It's closer oversight for the highest-risk, largest-scale processing.
Who is an SDF right now? — No one, yet
PendingThe Act sets out the factors for designation. But the government has not yet notified the criteria or thresholds that decide who actually qualifies. Until it does, and then names specific entities or classes, no organisation is a Significant Data Fiduciary. Numbers circulating in commentary — user-count thresholds and the like — are informed guesses, not notified law. So we don't repeat them here.
Track this in what's still pending →
What extra obligations apply if you're designated
These sit on top of the baseline duties every data fiduciary already has — notice, consent, security, breach reporting, rights requests.
- An India-resident Data Protection Officer. They must report to your board or an equivalent senior body, not sit under the CTO or the legal team. They are the point of contact for the Board and for individuals.
- An independent data auditor.
- Periodic Data Protection Impact Assessments (DPIAs) and audits of your processing.
- Algorithmic due diligence — checking your algorithms don't put people's rights at risk (Rule 13).
- Possible limits on moving certain personal data outside India, where the government specifies (Rule 13).
These start from the date of designation, not before.
If you're a founder, freelancer, or small/mid-size business: no. The DPO requirement is an SDF-only duty. SDF designation hasn't started. Appointing one now is optional preparation, not a legal obligation.
Should you prepare now?
Are you clearly large-scale or high-risk — very large user bases, sensitive data at scale? Then it can be sensible to start early. A qualified, board-reporting DPO and an independent auditor take time to line up. For everyone else, this is worth understanding, not acting on yet. This is general information, not legal advice. Assess your own position or take advice on it.
Sources
DPDP Act, 2023 — Section 10
Status unverified — no status check recorded
DPDP Rules, 2025 — Rule 13 (SDF obligations)
Status unverified — no status check recorded
Last updated: 4 Sep 2026 · Reviewed by Sandesh Kokate, Editor
Educational only. Re-verify against the Gazette of India before relying on anything here.
How does this apply to you?
Take the 2-minute self-check to find out whether you're a Data Fiduciary, Data Processor, or both — with your personalised action checklist.
Take the DPDP Applicability CheckNothing you answer leaves your browser.