DPDP Wiki Talk to us

/Guides · Large enterprises

Significant Data Fiduciaries: designation and extra duties

How the Central Government designates a Significant Data Fiduciary and the extra duties that follow, including the twelve-month DPIA and audit.

Interpretation · not legal adviceUpdated 9 September 20266 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

A Significant Data Fiduciary is not a category an organisation opts into or discovers by counting its users. It is a status the Central Government confers by notification, and once conferred it adds a small but demanding set of duties on top of everything section 8 already requires of every Data Fiduciary.

How designation works#

The Central Government may notify any Data Fiduciary, or a whole class of them, as a Significant Data Fiduciary "on the basis of an assessment of such relevant factors as it may determine" (section 10(1)). The Act lists six factors the assessment includes, without limiting it to them:

  • the volume and sensitivity of personal data processed;
  • risk to the rights of the Data Principal;
  • potential impact on the sovereignty and integrity of India;
  • risk to electoral democracy;
  • security of the State; and
  • public order.

The definition in section 2(z) confirms the point: a Significant Data Fiduciary is any Data Fiduciary or class of Data Fiduciaries notified as such under section 10. No threshold of users, revenue or data volume appears anywhere in the Act or the Rules. Designation is a government decision, and the assessment behind it is itself a recognised purpose for which the Government may call for information, exercised through an officer in the Ministry of Electronics and Information Technology designated by the Secretary in charge (Seventh Schedule).

The three extra duties in the Act#

A Data Protection Officer based in India#

A Significant Data Fiduciary must appoint a Data Protection Officer, who must represent it under the Act, be based in India, be an individual responsible to the Board of Directors or similar governing body, and be the point of contact for the grievance redressal mechanism (section 10(2)(a)).

Three of those requirements are structural rather than administrative. The officer is an individual, not a team or a vendor; the officer answers to the board, not to an operational manager; and the officer sits in India, whatever the location of the parent company. The term "Data Protection Officer" is defined by reference to this appointment (section 2(l)), so an organisation that has not been designated may of course appoint someone in that role, but it is not a Data Protection Officer in the Act's sense.

An independent data auditor#

It must also appoint an independent data auditor to carry out a data audit, who evaluates the Significant Data Fiduciary's compliance with the Act (section 10(2)(b)). The Act does not prescribe qualifications, registration or a panel for such auditors, and neither do the Rules. The only stated requirement is independence.

Impact assessments, audits and anything else prescribed#

Three further measures are required (section 10(2)(c)): a periodic Data Protection Impact Assessment, a periodic audit, and such other measures as may be prescribed. The Act defines the impact assessment itself as "a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals", plus whatever else is prescribed about the process.

What the Rules add#

Rule 13 fills in the word "periodic" and adds three requirements of its own.

RequirementDetail
FrequencyA Data Protection Impact Assessment and an audit "once in every period of twelve months", counted from the date the organisation is notified as a Significant Data Fiduciary or included in a class notified as such
ReportingThe person carrying out the assessment and audit must furnish a report to the Board containing the significant observations from both
Algorithmic due diligenceDue diligence to verify that technical measures, including algorithmic software, used for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of the personal data it processes "are not likely to pose a risk to the rights of Data Principals"
Localisation of specified dataMeasures to ensure that personal data specified by the Central Government is processed subject to the restriction that the personal data, and the traffic data pertaining to its flow, is not transferred outside the territory of India

The last one needs reading carefully. The restriction bites only on personal data the Central Government specifies, and only after it does so on the recommendations of a committee it constitutes for the purpose. That committee must include officials from the Ministry of Electronics and Technology, as printed in the Rules, and may include officials from other ministries or departments (rule 13(5)). Until such a specification is issued, there is nothing for the restriction to attach to. The Rules as published do not name any category of data, and no such specification appears in the sources on this site.

This localisation duty sits alongside, and is separate from, the general position on transfers. Under rule 15, personal data processed by a Data Fiduciary may be transferred outside India subject to the Data Fiduciary meeting whatever requirements the Central Government specifies, by general or special order, about making that data available to any foreign State, or to any person or entity under the control of or any agency of such a State. Separately, the Central Government may by notification restrict transfer for processing to a notified country or territory (section 16(1)).

Also worth noting is what rule 13 does not say. It does not prescribe who may act as the independent data auditor, what form the impact assessment takes, or the deadline for filing the report with the Board. On those points the Rules are silent.

The penalty#

A "breach in observance of additional obligations of Significant Data Fiduciary under section 10" carries a penalty that "may extend to one hundred and fifty crore rupees" (the Schedule). That is the fourth of seven penalty entries, below the two hundred and fifty crore maximum for a failure of security safeguards and the two hundred crore maximum for failures on breach notification and children's data, and above the general fifty crore residual entry. A penalty is imposed by the Board only if it determines on conclusion of an inquiry that the breach is significant, and after giving the person an opportunity of being heard (section 33(1)).

Timing#

Section 10 comes into force eighteen months after 13 November 2025, which is 13 May 2027 (G.S.R. 843(E)). Rule 13 starts on the same day under rule 1(4). Because the twelve-month clock in rule 13 runs from the date of notification as a Significant Data Fiduciary rather than from commencement, the first assessment and audit fall due a year after designation, whenever that happens.

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.