Back to home

Insights · DPDP Act, 2023

Significant Data Fiduciary (SDF) Requirements Under the DPDP Act — A Practical Guide

Most organisations under the DPDP Act are ordinary Data Fiduciaries. A smaller set can be notified as Significant Data Fiduciaries, and that notification adds obligations that take months — not weeks — to stand up. This guide explains who qualifies, what changes, and what to do before a notification arrives.

What is a Significant Data Fiduciary?

An SDF is not a category you self-certify into, and it is not decided by revenue or headcount. Under Section 10(1) of the Digital Personal Data Protection Act, 2023, the Central Government may notify any Data Fiduciary — or an entire class of Data Fiduciaries — as significant, based on an assessment of relevant factors. In other words: you become an SDF when you are notified as one, but the factors behind that decision are visible in advance, and they are worth measuring yourself against today.

The factors used to designate an SDF

  • Volume and sensitivity of personal data processed

    Large-scale processing, and processing of categories that carry higher potential for harm — health, financial, biometric, precise location, or children's data — weigh heaviest in practice.

  • Risk to the rights of Data Principals

    Processing that can lead to exclusion, denial of a service, profiling, or discriminatory outcomes for individuals.

  • Potential impact on the sovereignty and integrity of India

    Data holdings that, in aggregate, are strategically sensitive — critical infrastructure, defence-adjacent supply chains, large population-scale datasets.

  • Risk to electoral democracy

    Platforms and intermediaries capable of targeting or influencing voters at scale.

  • Security of the State and public order

    Processing whose compromise or misuse could disrupt public order or State security.

Practical read: if you process personal data at population scale, or you process higher-risk categories such as health or financial data for a large user base, treat SDF status as a plausible future state rather than someone else's problem.

The additional obligations an SDF carries

Every SDF duty sits on top of the baseline duties that already apply to all Data Fiduciaries — lawful notice and consent, purpose limitation, data minimisation, accuracy, reasonable security safeguards, breach notification to the Data Protection Board of India and affected Data Principals, retention limits, and grievance redressal.

  1. 1.Appoint a Data Protection Officer based in India

    The DPO must be an individual (not a vendor or a committee) who is answerable to the board or equivalent governing body, and whose contact details are published for Data Principals and for grievance redressal.

  2. 2.Appoint an independent data auditor

    An auditor independent of the teams being audited, engaged to evaluate the fiduciary's compliance with the Act — not the same thing as an internal IT audit or an existing statutory audit.

  3. 3.Carry out a periodic Data Protection Impact Assessment

    A documented assessment of processing activities, the rights of Data Principals, and the management of risk — refreshed periodically rather than produced once and filed away.

  4. 4.Carry out a periodic compliance audit

    A recurring audit of DPDP compliance, with the observations and remedial actions recorded and reported upward.

  5. 5.Exercise due diligence over algorithmic systems

    Verify that algorithmic software used to process personal data is unlikely to pose a risk to the rights of Data Principals — relevant to scoring, ranking, pricing, and automated eligibility decisions.

  6. 6.Observe restrictions on cross-border transfer of specified data

    Certain classes of personal data and traffic data may be restricted from being transferred outside India. Know where each dataset physically sits, including sub-processors and backups.

The SDF notification process, in sequence

  1. 1. Designation. The Central Government notifies a Data Fiduciary, or a class of them, as significant under Section 10(1).
  2. 2. Governance appointments. An India-based DPO answerable to the governing body, and an independent data auditor, are put in place, and the DPO's contact details are published.
  3. 3. Assessment and audit cycle. Periodic DPIAs and compliance audits begin, with findings and remediation recorded.
  4. 4. Ongoing verification. Algorithmic due diligence and cross-border transfer restrictions are monitored as living controls, not one-time sign-offs.

Timelines and procedural detail are set by the rules made under the Act, so confirm current requirements against the notified rules applicable to your class of fiduciary before committing to a compliance calendar.

What to do now, before any notification

  • Build a data inventory that records volume, categories, purposes, retention, and location for every processing activity.
  • Identify who would credibly be your India-based DPO, and what they would need reporting-line authority to change.
  • Run a first DPIA on your two or three highest-risk processing activities rather than the whole estate.
  • Separate audit from operations now, so an independent auditor is not auditing their own work later.
  • Map every cross-border flow, including SaaS vendors, analytics, support tooling, and backups.
  • Document algorithmic decision systems that touch individuals, and how their outputs are reviewed.

Check your own SDF exposure

Our free 12-question SDF readiness assessment maps your processing profile against the Section 10(1) factors and the additional SDF obligations, and takes about three minutes.

This guide is general information about the DPDP Act, 2023 and is not legal advice. Obligations depend on the rules in force and on your specific processing activities.