Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

significant data fiduciary explained

Significant Data Fiduciary: 6 Essential Extra Duties (2026)

A Significant Data Fiduciary is a data fiduciary the Central Government has notified as such under section 10 of the Digital Personal Data Protection Act, 2023 — and the designation is the DPDP Act’s way of concentrating its heaviest duties on the organisations whose processing matters most. The Act sets no numeric threshold. Notification rests on an assessment of factors the section lists: the volume and sensitivity of personal data processed, the risk to the rights of data principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, the security of the State and public order. Once notified, a Significant Data Fiduciary must appoint a Data Protection Officer based in India who answers to the board, appoint an independent data auditor, and — under Rule 13 of the DPDP Rules 2025 — undertake a Data Protection Impact Assessment and an audit every twelve months with a report of significant observations to the Data Protection Board, verify that its algorithmic software does not pose a risk to data principals’ rights, and keep government-specified data inside India. Breach of these duties sits in the Schedule’s ₹150 crore band. This guide sets out who is likely to be notified, each additional duty and what it requires in practice, the timeline, how the designation compares with GDPR’s DPO and DPIA triggers, and how to prepare before the notification arrives.

Significant Data Fiduciary: designation and the extra duties
Notified by the Central Government on section 10 factors → DPO based in India, responsible to the board · independent data auditor · annual DPIA and audit reported to the Board (Rule 13) · algorithmic due diligence · localisation of specified data → penalties up to ₹150 crore.

Who becomes a Significant Data Fiduciary

Section 10(1) factor What it points at Likely candidates
Volume and sensitivity of personal data processed Scale, and data whose misuse harms — health, financial, biometric, location, children’s Large platforms, telecoms, banks and payment providers, insurers, health networks, e-commerce
Risk to the rights of data principals Profiling, automated decisions, inference at scale Adtech, credit scoring, recommendation-driven services
Potential impact on the sovereignty and integrity of India Data of strategic significance Mapping, infrastructure, large-scale identity data
Risk to electoral democracy Political profiling and messaging Social media, political consultancies
Security of the State Data relevant to national security Telecoms, critical infrastructure operators
Public order Platforms shaping public discourse Large social and messaging platforms

The designation is by notification of a fiduciary or a class of fiduciaries, so an organisation may be caught individually or as part of a described class. There is no self-assessment or registration step; the duties attach when the notification names you or your class, and Rule 13’s twelve-month clock starts on that date. Our guide to the DPDP Act covers where section 10 sits in the Act.

The additional duties of a Significant Data Fiduciary

Duty Source What it requires in practice
Data Protection Officer Section 10(2)(a) An individual who represents the fiduciary under the Act, is based in India, is responsible to the board of directors or similar governing body, and is the point of contact for grievance redressal — a named, resident, board-accountable role, not a mailbox
Independent data auditor Section 10(2)(b) An auditor independent of the fiduciary’s processing functions who evaluates compliance with the Act — appointed, with terms of reference and access
Periodic Data Protection Impact Assessment Section 10(2)(c)(i); Rule 13(1) Once in every twelve months from notification: a process comprising a description of data principals’ rights and the purposes of processing, and assessment and management of the risk to those rights
Periodic audit Section 10(2)(c)(ii); Rule 13(1) Once in every twelve months: an audit to ensure effective observance of the Act and Rules
Report to the Board Rule 13(2) The person carrying out the DPIA and audit furnishes the Board a report containing significant observations
Algorithmic due diligence Rule 13(3) Verify that technical measures, including algorithmic software used for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data, are not likely to pose a risk to data principals’ rights
Localisation of specified data Rule 13(4) Personal data the Central Government specifies on a committee’s recommendation, and the traffic data pertaining to its flow, is not transferred outside India
Other measures as prescribed Section 10(2)(c)(iii) The Rules may add more; the current set is Rule 13

Each duty in practice

  1. The DPO. The Act’s four requirements are cumulative: representation under the Act, residence in India, accountability to the board, and the grievance contact role. A group DPO in another country does not satisfy the second; a compliance manager reporting to the CIO does not satisfy the third. The role needs a reporting line to the board, a budget and the authority to stop processing.
  2. The independent data auditor. Independence is from the processing being audited — an internal audit function that reports to the audit committee can qualify; the team that built the consent flow cannot. The auditor’s Rule 13 report to the Board makes the appointment a public-facing one.
  3. The annual DPIA. The Act defines its content: rights of data principals, purposes of processing, and assessment and management of the risk to those rights. Run it across the processing inventory, not per project only, because the duty is periodic and organisation-wide.
  4. The annual audit. Against the whole Act and Rules — notice, consent, security safeguards, breach, children, rights, retention, transfers — with evidence sampled, and the significant observations going to the Board.
  5. Algorithmic due diligence. An inventory of algorithmic systems that touch personal data, a risk assessment per system against data principals’ rights, and evidence of verification — testing, review, documentation — before and after deployment.
  6. Localisation readiness. The government’s specification does not exist yet; a data map that can identify where each category is processed and transferred is what makes compliance possible when it does.

Our guide to the DPDP Rules 2025 covers Rule 13 alongside the rest; DPDP penalties covers the ₹150 crore band.

Timeline

Date What happens Significant Data Fiduciary relevance
13 November 2025 Act sections on the Board and rule-making in force; Rules 1, 2, 17–21 The Board exists; no designations yet
13 November 2026 Rule 4: consent manager registration Consent manager integration where the fiduciary’s consent flows will use them
13 May 2027 Sections 3–17 and Rules 3, 5–16, 22, 23 in force — including section 10 and Rule 13 Designations can take effect; the twelve-month DPIA and audit clock runs from notification
Notification + 12 months First DPIA and audit due; report to the Board The first hard deliverable

Significant Data Fiduciary vs GDPR’s DPO and DPIA

DPDP Act — Significant Data Fiduciary GDPR
Trigger Government notification on section 10 factors DPO: public authority, large-scale regular monitoring, or large-scale special categories (Article 37); DPIA: high-risk processing (Article 35)
DPO location Based in India Anywhere; easily accessible from the establishments
DPO accountability Responsible to the board or governing body Reports to the highest management level; cannot be dismissed for performing tasks
External auditor Independent data auditor appointed None required
DPIA cadence Every twelve months, organisation-wide Before high-risk processing; reviewed when risk changes
Report to regulator Significant observations to the Board, annually Prior consultation only where residual risk is high
Algorithmic review Rule 13(3) due diligence Article 22 and DPIA; AI Act for high-risk systems
Localisation Government-specified data stays in India None; transfers by Chapter V mechanisms

Our guide to DPDP Act vs GDPR covers the wider comparison.

Preparing before the notification

  • Self-assess against the six factors and record the conclusion; if two or more apply at scale, plan as if notified.
  • Identify the DPO candidate — resident, senior, with a board reporting line — and the independent auditor route.
  • Build the processing inventory and data map now; the annual DPIA, the audit and any localisation order all depend on it.
  • Inventory algorithmic systems that touch personal data and start the risk assessments.
  • Design the annual cycle — DPIA in month 1–3, remediation, audit in month 9–11, Board report by month 12 — so the first year is not a scramble.

Frequently asked questions

What is a Significant Data Fiduciary?
A data fiduciary or class of fiduciaries notified by the Central Government under section 10 of the DPDP Act on factors including the volume and sensitivity of data, risk to data principals’ rights, sovereignty, electoral democracy, security of the State and public order — and thereby subject to additional duties: a Data Protection Officer based in India, an independent data auditor, an annual DPIA and audit reported to the Board, algorithmic due diligence and localisation of specified data.

Is there a threshold for designation?
No numeric threshold. Section 10(1) lists assessment factors; the government notifies fiduciaries or classes on that basis. Scale plus sensitivity, or profiling at scale, are the practical indicators.

Does every organisation need a DPO under the DPDP Act?
No. Every data fiduciary must publish the contact details of a DPO or of a person able to answer data principals’ questions (section 8(9)), but the statutory DPO — India-based, board-accountable — is a Significant Data Fiduciary duty.

How often are the DPIA and audit required?
Once in every twelve-month period from the date of notification, under Rule 13(1), with a report of significant observations furnished to the Data Protection Board by the person who carried them out.

What is the penalty for breaching these duties?
Item 4 of the Schedule: a penalty that may extend to ₹150 crore for breach of the additional obligations under section 10, determined by the Board on the section 33(2) factors.

Where this leaves you

Treat Significant Data Fiduciary status as a probability to plan for rather than a letter to wait for: self-assess on the six factors, line up the resident DPO and the independent auditor, build the data map and the algorithmic inventory, and design the twelve-month DPIA-and-audit cycle now — because from 13 May 2027 the notification can arrive, and the first report to the Board is due a year after it does.

References

More on the DPDP Act

The Significant Data Fiduciary readiness assessment, the DPO role description, the independent data auditor terms of reference, the annual DPIA and audit templates and the algorithmic due diligence register are in the DPDP Act Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.