/The Rules · 2025
Rule 13: Additional obligations of Significant Data Fiduciary
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. Comes into force on 13 May 2027.
- Provision
- Rule 13 of The Digital Personal Data Protection Rules, 2025
- Status
- Comes into force on 13 May 2027 (phase 3)
- Made under
- s. 10 Additional obligations of Significant Data Fiduciary
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
A Significant Data Fiduciary shall, once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder.
A Significant Data Fiduciary shall observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals.
A Significant Data Fiduciary shall undertake measures to ensure that personal data specified by the Central Government, on the basis of the recommendations of a committee constituted by it, is processed subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India.
In this rule, “committee” means a committee constituted by the Central Government for the purpose of this rule, which shall include officials from the Ministry of Electronics and Technology and may include officials from other Ministries or Department of the Central Government.
- in page 29, line 44, for “Department”, read “Departments”;
Rule 13 sets out extra duties for a Significant Data Fiduciary, which is a Data Fiduciary (an entity determining the purpose and means of processing personal data) that the government has specifically notified. Once every twelve months from the date it is notified, a Significant Data Fiduciary must conduct a Data Protection Impact Assessment and an audit. This ensures it is effectively following the Act and its rules. The Significant Data Fiduciary must ensure that the person conducting the assessment and audit sends a report to the Board. This report must contain any significant observations found during the process. The rule also requires the Significant Data Fiduciary to use due diligence regarding its technical measures, including algorithmic software. It must verify that the systems used to host, display, upload, modify, publish, transmit, store, update, or share personal data do not pose a risk to the rights of Data Principals (the individuals to whom the data relates). Finally, the Central Government can specify certain personal data that cannot leave India. This decision is based on recommendations from a specific government committee, which includes officials from the Ministry of Electronics and Information Technology. If data is specified under this rule, the Significant Data Fiduciary must ensure that both the personal data and the traffic data related to its flow are not transferred outside the territory of India.
Key points
- A Significant Data Fiduciary must conduct a Data Protection Impact Assessment and an audit every twelve months from its notification date (1).
- The person performing the assessment and audit must submit a report of significant observations to the Board (2).
- The Significant Data Fiduciary must verify that its technical measures and algorithmic software do not risk the rights of Data Principals (3).
- The Central Government, guided by a committee, can specify certain personal data that must not be transferred outside India (4).
- The committee making these recommendations must include officials from the Ministry of Electronics and Information Technology (5).
Common misreadings
- Assuming the Significant Data Fiduciary submits the audit report directly to the Board, whereas the rule requires the person carrying out the audit to furnish the report.
- Believing all personal data is blocked from transfer outside India, when this restriction only applies to specific data designated by the Central Government.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.