/The Act · Chapter II · Obligations of Data Fiduciary
Section 10: Additional obligations of Significant Data Fiduciary
DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.
- Provision
- Section 10 of The Digital Personal Data Protection Act, 2023
- Status
- Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
- Rules made under it
- Rule 13
- Source
- Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including—
The Significant Data Fiduciary shall—
appoint a Data Protection Officer who shall—
be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and
be the point of contact for the grievance redressal mechanism under the provisions of this Act;
appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and
undertake the following other measures, namely:—
periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed;
The Central Government has the power to designate a Data Fiduciary (an entity that decides how and why personal data is processed) as a Significant Data Fiduciary. The government makes this decision based on factors like the volume and sensitivity of the data processed, risks to the rights of the Data Principal (the individual the data is about), and potential impacts on India's sovereignty, security, public order, or electoral democracy.\n\nOnce designated, a Significant Data Fiduciary must appoint a Data Protection Officer. This officer must be an individual based in India who represents the entity under the Act and serves as the main contact for grievance redressal. They must report directly to the entity's Board of Directors or a similar governing body.\n\nThe Significant Data Fiduciary must also appoint an independent data auditor to check its compliance with the Act. Additionally, the entity must conduct periodic audits and periodic Data Protection Impact Assessments. This assessment is a process that describes the processing purposes, the rights of Data Principals, and how risks to those rights are managed, along with any other details the government may prescribe in the rules.
Key points
- The Central Government can designate certain Data Fiduciaries as Significant Data Fiduciaries based on factors like data volume, sensitivity, and risks to national security or democracy (1).
- A Significant Data Fiduciary must appoint a Data Protection Officer who is based in India and reports to the Board of Directors (2)(a).
- The Data Protection Officer acts as the point of contact for the grievance redressal mechanism (2)(a)(iv).
- The entity must appoint an independent data auditor to evaluate its compliance with the Act (2)(b).
- The entity must conduct periodic audits and Data Protection Impact Assessments to manage risks to the rights of Data Principals (2)(c).
Common misreadings
- Readers might think any large company is automatically a Significant Data Fiduciary, but the text states the Central Government must specifically notify an entity or class of entities as such.
- Readers might assume the Data Protection Officer can be located anywhere, but the text explicitly requires them to be based in India.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.