---
title: "Section 10: Additional obligations of Significant Data Fiduciary"
url: https://dpdp.myndsolution.com/wiki/act/section-10-additional-obligations-of-significant-data-fiduciary/
description: "Section 10 of the Digital Personal Data Protection Act, 2023 (Additional obligations of Significant Data Fiduciary). Official text verbatim, comes into…"
kind: act-section
updated: 2026-09-09
official_source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
text_type: official-text-plus-interpretation
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/act/section-10-additional-obligations-of-significant-data-fiduciary/
---
# Section 10: Additional obligations of Significant Data Fiduciary

*The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Chapter II: OBLIGATIONS OF DATA FIDUCIARY. Comes into force on 13 May 2027.*

## Official text

- **(1)** The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including—
  - **(a)** the volume and sensitivity of personal data processed;
  - **(b)** risk to the rights of Data Principal;
  - **(c)** potential impact on the sovereignty and integrity of India;
  - **(d)** risk to electoral democracy;
  - **(e)** security of the State; and
  - **(f)** public order.

- **(2)** The Significant Data Fiduciary shall—
  - **(a)** appoint a Data Protection Officer who shall—
    - **(i)** represent the Significant Data Fiduciary under the provisions of this Act;
    - **(ii)** be based in India;
    - **(iii)** be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and
    - **(iv)** be the point of contact for the grievance redressal mechanism under the provisions of this Act;
  - **(b)** appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and
  - **(c)** undertake the following other measures, namely:—
    - **(i)** periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed;
    - **(ii)** periodic audit; and
    - **(iii)** such other measures, consistent with the provisions of this Act, as may be prescribed.


## Rules made under this section

- [Rule 13: Additional obligations of Significant Data Fiduciary](https://dpdp.myndsolution.com/wiki/rules/rule-13-additional-obligations-of-significant-data-fiduciary/)

## Interpretation in plain English (not legal advice)

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

The Central Government has the power to designate a Data Fiduciary (an entity that decides how and why personal data is processed) as a Significant Data Fiduciary. The government makes this decision based on factors like the volume and sensitivity of the data processed, risks to the rights of the Data Principal (the individual the data is about), and potential impacts on India's sovereignty, security, public order, or electoral democracy.\n\nOnce designated, a Significant Data Fiduciary must appoint a Data Protection Officer. This officer must be an individual based in India who represents the entity under the Act and serves as the main contact for grievance redressal. They must report directly to the entity's Board of Directors or a similar governing body.\n\nThe Significant Data Fiduciary must also appoint an independent data auditor to check its compliance with the Act. Additionally, the entity must conduct periodic audits and periodic Data Protection Impact Assessments. This assessment is a process that describes the processing purposes, the rights of Data Principals, and how risks to those rights are managed, along with any other details the government may prescribe in the rules.

### Key points

- The Central Government can designate certain Data Fiduciaries as Significant Data Fiduciaries based on factors like data volume, sensitivity, and risks to national security or democracy (1).
- A Significant Data Fiduciary must appoint a Data Protection Officer who is based in India and reports to the Board of Directors (2)(a).
- The Data Protection Officer acts as the point of contact for the grievance redressal mechanism (2)(a)(iv).
- The entity must appoint an independent data auditor to evaluate its compliance with the Act (2)(b).
- The entity must conduct periodic audits and Data Protection Impact Assessments to manage risks to the rights of Data Principals (2)(c).

### Common misreadings

- Readers might think any large company is automatically a Significant Data Fiduciary, but the text states the Central Government must specifically notify an entity or class of entities as such.
- Readers might assume the Data Protection Officer can be located anywhere, but the text explicitly requires them to be based in India.

*Interpretation prepared 2026-09-09 from the official text only; the official text prevails.*

---
Cite as: Digital Personal Data Protection Act, 2023, s. 10. Official source: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
