DPDP Wiki Talk to us

/The Act · Chapter II · Obligations of Data Fiduciary

Section 10: Additional obligations of Significant Data Fiduciary

DPDP Act, 2023 (No. 22 of 2023). Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) G.S.R. 843(E)Chapter II: Obligations of Data Fiduciary
Provision
Section 10 of The Digital Personal Data Protection Act, 2023
Status
Comes into force on 13 May 2027 (phase 3) G.S.R. 843(E)
Rules made under it
Rule 13
Source
Ministry of Law and Justice (Legislative Department) · 11 August 2023 · Official PDF

Section 10. Additional obligations of Significant Data Fiduciary

Verbatim from the Gazette of India
(1)

The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including—

(a)

the volume and sensitivity of personal data processed;

(b)

risk to the rights of Data Principal;

(c)

potential impact on the sovereignty and integrity of India;

(d)

risk to electoral democracy;

(e)

security of the State; and

(f)

public order.

(2)

The Significant Data Fiduciary shall—

(a)

appoint a Data Protection Officer who shall—

(i)

represent the Significant Data Fiduciary under the provisions of this Act;

(ii)

be based in India;

(iii)

be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and

(iv)

be the point of contact for the grievance redressal mechanism under the provisions of this Act;

(b)

appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and

(c)

undertake the following other measures, namely:—

(i)

periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed;

(ii)

periodic audit; and

(iii)

such other measures, consistent with the provisions of this Act, as may be prescribed.

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Central GovernmentSignificant Data FiduciaryData FiduciaryData Principal

The Central Government has the power to designate a Data Fiduciary (an entity that decides how and why personal data is processed) as a Significant Data Fiduciary. The government makes this decision based on factors like the volume and sensitivity of the data processed, risks to the rights of the Data Principal (the individual the data is about), and potential impacts on India's sovereignty, security, public order, or electoral democracy.\n\nOnce designated, a Significant Data Fiduciary must appoint a Data Protection Officer. This officer must be an individual based in India who represents the entity under the Act and serves as the main contact for grievance redressal. They must report directly to the entity's Board of Directors or a similar governing body.\n\nThe Significant Data Fiduciary must also appoint an independent data auditor to check its compliance with the Act. Additionally, the entity must conduct periodic audits and periodic Data Protection Impact Assessments. This assessment is a process that describes the processing purposes, the rights of Data Principals, and how risks to those rights are managed, along with any other details the government may prescribe in the rules.

Key points

  • The Central Government can designate certain Data Fiduciaries as Significant Data Fiduciaries based on factors like data volume, sensitivity, and risks to national security or democracy (1).
  • A Significant Data Fiduciary must appoint a Data Protection Officer who is based in India and reports to the Board of Directors (2)(a).
  • The Data Protection Officer acts as the point of contact for the grievance redressal mechanism (2)(a)(iv).
  • The entity must appoint an independent data auditor to evaluate its compliance with the Act (2)(b).
  • The entity must conduct periodic audits and Data Protection Impact Assessments to manage risks to the rights of Data Principals (2)(c).

Common misreadings

  • Readers might think any large company is automatically a Significant Data Fiduciary, but the text states the Central Government must specifically notify an entity or class of entities as such.
  • Readers might assume the Data Protection Officer can be located anywhere, but the text explicitly requires them to be based in India.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.