How an SDF is named
The Central Government may notify any Data Fiduciary or class as a Significant Data Fiduciary after assessing relevant factors. They include the volume and sensitivity of data, risk to people's rights, and impact on India's sovereignty and integrity. They also include risk to electoral democracy, security of the State and public order.
Sources: Act s.10(1)
The Data Protection Officer
An SDF must appoint a Data Protection Officer who represents it under the Act and is based in India. The DPO is responsible to its board of directors or similar governing body, and is the point of contact for grievance redressal.
Sources: Act s.10(2)(a)
Auditor, DPIA and audit
An SDF must appoint an independent data auditor to evaluate its compliance, and carry out periodic Data Protection Impact Assessments and audits. A DPIA describes people's rights and the purposes of processing, and assesses and manages the risk to those rights.
Rule 13 makes these yearly: a DPIA and an audit once in every twelve months from the date of notification. The person carrying them out must give the Board a report of the significant observations.
Sources: Act s.10(2)(b)Act s.10(2)(c)Rules r.13(1)Rules r.13(2)
Algorithms and data that stays in India
An SDF must use due diligence to check that its technical measures, including algorithmic software, are not likely to pose a risk to people's rights. It must also ensure that personal data the Government specifies, on a committee's recommendation, and its traffic data, are not transferred outside India.
Sources: Rules r.13(3)Rules r.13(4)
Penalty and exemption
Breaching the additional SDF obligations under section 10 can attract a penalty of up to Rs 150 crore. The Government may also notify classes of Fiduciaries, including startups, to whom section 10 does not apply.
Sources: Act Schedule item 4Act s.17(3)
Key points
- SDFs are named by Government notification, not self-assessment.
- The DPO must be based in India and answer to the board.
- A DPIA and an audit every twelve months, reported to the Board.
- Check that algorithms do not risk people's rights.
- Specified data may have to stay in India.
In practice
A checklist for your organisation.
- Assess whether your data volume or sensitivity could lead to SDF notification.
- Draft a DPIA method that describes rights, purposes and risks.
- Line up an independent data auditor before any notification.
- Keep an inventory of algorithms that shape decisions about people.
Check what you learned
4 questions. Choose an answer to see why it is right.
0 of 4 answered
Question 1 of 4
Who decides that an organisation is a Significant Data Fiduciary?
Show the answer
A. The Central Government, by notification
Section 10(1) lets the Central Government notify any Data Fiduciary or class as a Significant Data Fiduciary after assessing relevant factors.
Act s.10(1)Section 10(1) lets the Central Government notify any Data Fiduciary or class as a Significant Data Fiduciary after assessing relevant factors.
Act s.10(1)Question 2 of 4
Where must an SDF's Data Protection Officer be based?
Show the answer
A. In India
Section 10(2)(a)(ii) requires the DPO to be based in India.
Act s.10(2)(a)Section 10(2)(a)(ii) requires the DPO to be based in India.
Act s.10(2)(a)Question 3 of 4
How often must an SDF carry out a DPIA and an audit under Rule 13?
Show the answer
C. Once in every twelve months
Rule 13(1) requires a DPIA and an audit once in every period of twelve months from the date of notification.
Rules r.13(1)Rule 13(1) requires a DPIA and an audit once in every period of twelve months from the date of notification.
Rules r.13(1)Question 4 of 4
What is the maximum penalty for breaching the SDF obligations in section 10?
Show the answer
B. Rs 150 crore
Item 4 of the Schedule: breach of the additional SDF obligations may attract up to one hundred and fifty crore rupees.
Act Schedule item 4Item 4 of the Schedule: breach of the additional SDF obligations may attract up to one hundred and fifty crore rupees.
Act Schedule item 4
Official sources for this lesson
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India, Extraordinary, Part II, Section 1, 11 August 2023
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY, 13 November 2025 (with Schedules)
- G.S.R. 843(E), 13 November 2025: dates on which provisions of the DPDP Act come into force
A plain-English summary of the DPDP Act 2023 and DPDP Rules 2025, checked on 28 September 2026. It is not legal advice. Words in this lesson are explained in the DPDP dictionary.