/Glossary · Defined term
Significant Data Fiduciary
Defined in section 2(z) of the Act.
Act, section 2(z)
(z) “Significant Data Fiduciary” means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10;
The Digital Personal Data Protection Act defines a "Significant Data Fiduciary" as a specific category of Data Fiduciary. A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data. The Act itself does not provide a fixed checklist or mathematical threshold to determine who falls into this category. Instead, the definition relies entirely on future actions by the Central Government.\n\nUnder section 10 of the Act, the Central Government has the authority to officially notify which entities receive this designation. The government can choose to notify a single, specific Data Fiduciary as "Significant," or it can notify an entire class or group of Data Fiduciaries all at once.\n\nBecause the definition depends on these government notifications, an entity only becomes a Significant Data Fiduciary when the Central Government explicitly says it is. This structure gives the government the flexibility to identify which organizations must follow the stricter rules and obligations that the Act assigns to Significant Data Fiduciaries.
Key points
- A Significant Data Fiduciary is a specific Data Fiduciary or a class of Data Fiduciaries. (Section 2(z))
- The Central Government holds the power to notify who qualifies for this designation. (Section 2(z))
- This notification by the Central Government is made under section 10 of the Act. (Section 2(z))
Common misreadings
- Readers might assume the definition includes specific metrics like user count or revenue, but it relies entirely on Central Government notifications.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.