Chapter II · Obligations of Data Fiduciary
Section 10: Significant Data Fiduciary
Section 10 creates a higher tier: the Government can designate a Significant Data Fiduciary, which then owes extra duties, an India-based DPO, an independent auditor, and periodic impact assessments and audits.
- Chapter
- Chapter II · Obligations of Data Fiduciary
- Status
- Enacted · phased commencement
- Full compliance
- 13 May 2027
- Applies to
- Designated Fiduciaries
- Official citation
- DPDP Act, 2023, s.10
- Reading time
- 5 min
- Updated
- August 2026
At a glance
Section 10 lets the Central Government designate a Data Fiduciary, or a class of them, as a Significant Data Fiduciary based on factors such as the volume and sensitivity of data, risk to Data Principals, and impact on the sovereignty, integrity, electoral democracy and security of India. A Significant Data Fiduciary must appoint an India-based Data Protection Officer, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits.
Key takeaways
- The Government designates a Significant Data Fiduciary (SDF); you do not self-declare.
- Designation weighs volume and sensitivity of data, risk to individuals, and national-interest factors.
- An SDF must appoint a Data Protection Officer based in India, answerable to its board.
- An SDF must appoint an independent data auditor.
- An SDF must run periodic Data Protection Impact Assessments and audits.
- Even if you are not designated, these duties are a good maturity target.
Who should read this
Read this if you process large volumes or sensitive categories of personal data, or operate at national scale, you are the most likely candidate for designation.
In plain language
Most obligations in the Act apply to every Data Fiduciary. Section 10 adds a higher tier for organisations whose processing carries greater risk. The Central Government may notify a Data Fiduciary, or a whole class, as a Significant Data Fiduciary. You do not choose this label, it is assigned.
The assessment looks at the volume and sensitivity of the personal data processed, the risk to the rights of Data Principals, and national-interest factors, the sovereignty and integrity of India, risk to electoral democracy, security of the State and public order.
Designation brings three concrete duties. Appoint a Data Protection Officer based in India, answerable to the board and acting as the contact for grievances. Appoint an independent data auditor. And carry out periodic Data Protection Impact Assessments and audits, plus any other measures the rules prescribe.
The text of the law
Section 10: Significant Data Fiduciary
10(1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary, on the basis of an assessment of relevant factors, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State and public order.
10(2)(a) A Significant Data Fiduciary shall appoint a Data Protection Officer who is based in India, is responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal.
10(2)(b) It shall appoint an independent data auditor to carry out data audit and evaluate compliance with the Act.
10(2)(c) It shall undertake periodic Data Protection Impact Assessment, periodic audit, and such other measures as may be prescribed.
Wording reproduced or summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.
What this means for you
- If you process at scale or handle sensitive data, prepare as if you may be designated.
- Line up an India-based DPO answerable to your board.
- Plan for an independent data audit and periodic DPIAs.
- Read the Significant Data Fiduciary guide to prepare early.
Frequently asked questions
Who is a Significant Data Fiduciary?
What extra duties does an SDF have?
Does the DPO have to be in India?
How do I know if I will be designated?
Sources
- Digital Personal Data Protection Act, 2023Ministry of Electronics and IT (MeitY)
- DPDP Rules, 2025Notified 13–14 November 2025
This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.