Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Compare terms

Data Fiduciary vs Significant Data Fiduciary

Every Significant Data Fiduciary is first a Data Fiduciary. The 'significant' label is added by the Central Government for higher-risk fiduciaries, and it brings extra obligations.

Data Fiduciary
Significant Data Fiduciary
Who it is
Any person deciding the purpose and means of processing.
A fiduciary notified as higher-risk under Section 10.
Statutory reference
Section 2(i)
Section 2(z) / Section 10
How the role arises
By determining purpose and means.
By Central Government notification, on risk factors.
Data Protection Officer
Not mandatory.
Mandatory, India-based (Section 10(2)(a)).
Independent data auditor
Not required.
Required (Section 10(2)(b)).
Impact assessment and audit
Not required.
Periodic DPIA and audit required (Section 10(2)(c)).

Why the distinction matters

The ‘significant’ label is not cosmetic: it layers on heavier duties. A Significant Data Fiduciary must appoint an India-based Data Protection Officer, engage an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits under Section 10, along with the additional obligations in Rule 13. Those requirements carry real cost and governance overhead.

When each applies

Every organisation that decides the purpose and means of processing is a Data Fiduciary from day one. It becomes a Significant Data Fiduciary only when the Central Government notifies it as one. Section 10(1) lists the factors the Government weighs: the volume and sensitivity of personal data, risk to the rights of Data Principals, and risks to India's sovereignty and integrity, electoral democracy, security of the State and public order.

There is no self-assessed threshold that flips the switch automatically — the designation comes by notification.

Common confusions to avoid

“We're large, so we must be an SDF.” Size alone doesn't decide it; it is a Government notification weighing several factors, not a headcount or turnover test.

Confusing the SDF's DPO with the general contact duty. Every fiduciary must publish a contact for answering rights questions (Section 8(9) and Rule 9). Only an SDF must appoint a dedicated, India-based DPO (Section 10(2)(a)).

Assuming the duties already bite. Section 10 commences with the main obligations on 13 May 2027.

Related glossary terms

Frequently asked questions

What makes a fiduciary 'significant'?

A Central Government notification under Section 10, based on data volume and sensitivity and risks to rights, sovereignty, security and public order.

What extra duties apply?

An India-based DPO, an independent data auditor, and periodic impact assessments and audits.