DPDP Wiki Talk to us

/The Rules · 2025

Rule 13: Additional obligations of Significant Data Fiduciary

DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.

UpcomingOfficial textComes into force on 13 May 2027 (phase 3) · rule 1(4)
Provision
Rule 13 of The Digital Personal Data Protection Rules, 2025
Status
Comes into force on 13 May 2027 (phase 3)
Made under
s. 10 Additional obligations of Significant Data Fiduciary
Source
Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF

Rule 13. Additional obligations of Significant Data Fiduciary

Verbatim from the Gazette of India
(1)

A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder.

(2)

A Significant Data Fiduciary shall cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit.

(3)

A Significant Data Fiduciary shall observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals.

(4)

A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India.

(5)

In this rule, “committee” means a committee constituted by the Central Government for the purpose of this rule, which shall include officials from the Ministry of Electronics and Technology and may include officials from other Ministries or Department of the Central Government.

Corrected by G.S.R. 892(E) (10 December 2025). The text above is as first printed. The Ministry's corrigendum directs:
  • in page 29, line 44, for “Department”, read “Departments”;

Interpretation in plain English

Interpretation · not legal advice
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.
Significant Data FiduciaryBoardCentral GovernmentData Principal

Rule 13 sets out extra duties for a Significant Data Fiduciary, which is a Data Fiduciary (an entity determining the purpose and means of processing personal data) that the government has specifically notified. Once every twelve months from the date it is notified, a Significant Data Fiduciary must conduct a Data Protection Impact Assessment and an audit. This ensures it is effectively following the Act and its rules. The Significant Data Fiduciary must ensure that the person conducting the assessment and audit sends a report to the Board. This report must contain any significant observations found during the process. The rule also requires the Significant Data Fiduciary to use due diligence regarding its technical measures, including algorithmic software. It must verify that the systems used to host, display, upload, modify, publish, transmit, store, update, or share personal data do not pose a risk to the rights of Data Principals (the individuals to whom the data relates). Finally, the Central Government can specify certain personal data that cannot leave India. This decision is based on recommendations from a specific government committee, which includes officials from the Ministry of Electronics and Information Technology. If data is specified under this rule, the Significant Data Fiduciary must ensure that both the personal data and the traffic data related to its flow are not transferred outside the territory of India.

Key points

  • A Significant Data Fiduciary must conduct a Data Protection Impact Assessment and an audit every twelve months from its notification date (1).
  • The person performing the assessment and audit must submit a report of significant observations to the Board (2).
  • The Significant Data Fiduciary must verify that its technical measures and algorithmic software do not risk the rights of Data Principals (3).
  • The Central Government, guided by a committee, can specify certain personal data that must not be transferred outside India (4).
  • The committee making these recommendations must include officials from the Ministry of Electronics and Information Technology (5).

Common misreadings

  • Assuming the Significant Data Fiduciary submits the audit report directly to the Board, whereas the rule requires the person carrying out the audit to furnish the report.
  • Believing all personal data is blocked from transfer outside India, when this restriction only applies to specific data designated by the Central Government.

Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.

/MYND · DPDP practice

Putting this into practice?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.