A Significant Data Fiduciary is a data fiduciary the Central Government has notified as such under section 10 of the Digital Personal Data Protection Act, 2023 — and the designation is the DPDP Act’s way of concentrating its heaviest duties on the organisations whose processing matters most. The Act sets no numeric threshold. Notification rests on an assessment of factors the section lists: the volume and sensitivity of personal data processed, the risk to the rights of data principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, the security of the State and public order. Once notified, a Significant Data Fiduciary must appoint a Data Protection Officer based in India who answers to the board, appoint an independent data auditor, and — under Rule 13 of the DPDP Rules 2025 — undertake a Data Protection Impact Assessment and an audit every twelve months with a report of significant observations to the Data Protection Board, verify that its algorithmic software does not pose a risk to data principals’ rights, and keep government-specified data inside India. Breach of these duties sits in the Schedule’s ₹150 crore band. This guide sets out who is likely to be notified, each additional duty and what it requires in practice, the timeline, how the designation compares with GDPR’s DPO and DPIA triggers, and how to prepare before the notification arrives.

Who becomes a Significant Data Fiduciary
| Section 10(1) factor | What it points at | Likely candidates |
|---|---|---|
| Volume and sensitivity of personal data processed | Scale, and data whose misuse harms — health, financial, biometric, location, children’s | Large platforms, telecoms, banks and payment providers, insurers, health networks, e-commerce |
| Risk to the rights of data principals | Profiling, automated decisions, inference at scale | Adtech, credit scoring, recommendation-driven services |
| Potential impact on the sovereignty and integrity of India | Data of strategic significance | Mapping, infrastructure, large-scale identity data |
| Risk to electoral democracy | Political profiling and messaging | Social media, political consultancies |
| Security of the State | Data relevant to national security | Telecoms, critical infrastructure operators |
| Public order | Platforms shaping public discourse | Large social and messaging platforms |
The designation is by notification of a fiduciary or a class of fiduciaries, so an organisation may be caught individually or as part of a described class. There is no self-assessment or registration step; the duties attach when the notification names you or your class, and Rule 13’s twelve-month clock starts on that date. Our guide to the DPDP Act covers where section 10 sits in the Act.
The additional duties of a Significant Data Fiduciary
| Duty | Source | What it requires in practice |
|---|---|---|
| Data Protection Officer | Section 10(2)(a) | An individual who represents the fiduciary under the Act, is based in India, is responsible to the board of directors or similar governing body, and is the point of contact for grievance redressal — a named, resident, board-accountable role, not a mailbox |
| Independent data auditor | Section 10(2)(b) | An auditor independent of the fiduciary’s processing functions who evaluates compliance with the Act — appointed, with terms of reference and access |
| Periodic Data Protection Impact Assessment | Section 10(2)(c)(i); Rule 13(1) | Once in every twelve months from notification: a process comprising a description of data principals’ rights and the purposes of processing, and assessment and management of the risk to those rights |
| Periodic audit | Section 10(2)(c)(ii); Rule 13(1) | Once in every twelve months: an audit to ensure effective observance of the Act and Rules |
| Report to the Board | Rule 13(2) | The person carrying out the DPIA and audit furnishes the Board a report containing significant observations |
| Algorithmic due diligence | Rule 13(3) | Verify that technical measures, including algorithmic software used for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data, are not likely to pose a risk to data principals’ rights |
| Localisation of specified data | Rule 13(4) | Personal data the Central Government specifies on a committee’s recommendation, and the traffic data pertaining to its flow, is not transferred outside India |
| Other measures as prescribed | Section 10(2)(c)(iii) | The Rules may add more; the current set is Rule 13 |
Each duty in practice
- The DPO. The Act’s four requirements are cumulative: representation under the Act, residence in India, accountability to the board, and the grievance contact role. A group DPO in another country does not satisfy the second; a compliance manager reporting to the CIO does not satisfy the third. The role needs a reporting line to the board, a budget and the authority to stop processing.
- The independent data auditor. Independence is from the processing being audited — an internal audit function that reports to the audit committee can qualify; the team that built the consent flow cannot. The auditor’s Rule 13 report to the Board makes the appointment a public-facing one.
- The annual DPIA. The Act defines its content: rights of data principals, purposes of processing, and assessment and management of the risk to those rights. Run it across the processing inventory, not per project only, because the duty is periodic and organisation-wide.
- The annual audit. Against the whole Act and Rules — notice, consent, security safeguards, breach, children, rights, retention, transfers — with evidence sampled, and the significant observations going to the Board.
- Algorithmic due diligence. An inventory of algorithmic systems that touch personal data, a risk assessment per system against data principals’ rights, and evidence of verification — testing, review, documentation — before and after deployment.
- Localisation readiness. The government’s specification does not exist yet; a data map that can identify where each category is processed and transferred is what makes compliance possible when it does.
Our guide to the DPDP Rules 2025 covers Rule 13 alongside the rest; DPDP penalties covers the ₹150 crore band.
Timeline
| Date | What happens | Significant Data Fiduciary relevance |
|---|---|---|
| 13 November 2025 | Act sections on the Board and rule-making in force; Rules 1, 2, 17–21 | The Board exists; no designations yet |
| 13 November 2026 | Rule 4: consent manager registration | Consent manager integration where the fiduciary’s consent flows will use them |
| 13 May 2027 | Sections 3–17 and Rules 3, 5–16, 22, 23 in force — including section 10 and Rule 13 | Designations can take effect; the twelve-month DPIA and audit clock runs from notification |
| Notification + 12 months | First DPIA and audit due; report to the Board | The first hard deliverable |
Significant Data Fiduciary vs GDPR’s DPO and DPIA
| DPDP Act — Significant Data Fiduciary | GDPR | |
|---|---|---|
| Trigger | Government notification on section 10 factors | DPO: public authority, large-scale regular monitoring, or large-scale special categories (Article 37); DPIA: high-risk processing (Article 35) |
| DPO location | Based in India | Anywhere; easily accessible from the establishments |
| DPO accountability | Responsible to the board or governing body | Reports to the highest management level; cannot be dismissed for performing tasks |
| External auditor | Independent data auditor appointed | None required |
| DPIA cadence | Every twelve months, organisation-wide | Before high-risk processing; reviewed when risk changes |
| Report to regulator | Significant observations to the Board, annually | Prior consultation only where residual risk is high |
| Algorithmic review | Rule 13(3) due diligence | Article 22 and DPIA; AI Act for high-risk systems |
| Localisation | Government-specified data stays in India | None; transfers by Chapter V mechanisms |
Our guide to DPDP Act vs GDPR covers the wider comparison.
Preparing before the notification
- Self-assess against the six factors and record the conclusion; if two or more apply at scale, plan as if notified.
- Identify the DPO candidate — resident, senior, with a board reporting line — and the independent auditor route.
- Build the processing inventory and data map now; the annual DPIA, the audit and any localisation order all depend on it.
- Inventory algorithmic systems that touch personal data and start the risk assessments.
- Design the annual cycle — DPIA in month 1–3, remediation, audit in month 9–11, Board report by month 12 — so the first year is not a scramble.
Frequently asked questions
What is a Significant Data Fiduciary?
A data fiduciary or class of fiduciaries notified by the Central Government under section 10 of the DPDP Act on factors including the volume and sensitivity of data, risk to data principals’ rights, sovereignty, electoral democracy, security of the State and public order — and thereby subject to additional duties: a Data Protection Officer based in India, an independent data auditor, an annual DPIA and audit reported to the Board, algorithmic due diligence and localisation of specified data.
Is there a threshold for designation?
No numeric threshold. Section 10(1) lists assessment factors; the government notifies fiduciaries or classes on that basis. Scale plus sensitivity, or profiling at scale, are the practical indicators.
Does every organisation need a DPO under the DPDP Act?
No. Every data fiduciary must publish the contact details of a DPO or of a person able to answer data principals’ questions (section 8(9)), but the statutory DPO — India-based, board-accountable — is a Significant Data Fiduciary duty.
How often are the DPIA and audit required?
Once in every twelve-month period from the date of notification, under Rule 13(1), with a report of significant observations furnished to the Data Protection Board by the person who carried them out.
What is the penalty for breaching these duties?
Item 4 of the Schedule: a penalty that may extend to ₹150 crore for breach of the additional obligations under section 10, determined by the Board on the section 33(2) factors.
Where this leaves you
Treat Significant Data Fiduciary status as a probability to plan for rather than a letter to wait for: self-assess on the six factors, line up the resident DPO and the independent auditor, build the data map and the algorithmic inventory, and design the twelve-month DPIA-and-audit cycle now — because from 13 May 2027 the notification can arrive, and the first report to the Board is due a year after it does.
References
- The Digital Personal Data Protection Act, 2023 — Gazette text (MeitY) — Section 10 and the Schedule.
- The Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E) (MeitY) — Rule 13, additional obligations of Significant Data Fiduciary.
- MeitY — Data protection framework — Notifications and updates.
More on the DPDP Act
- The Significant Data Fiduciary — you are here
- The DPDP Act: the complete guide
- The DPDP Rules 2025
- DPDP Act vs GDPR
- DPDP penalties: the Schedule
- Consent managers under the DPDP Rules
The Significant Data Fiduciary readiness assessment, the DPO role description, the independent data auditor terms of reference, the annual DPIA and audit templates and the algorithmic due diligence register are in the DPDP Act Toolkit, or start with the free templates.