Readiness assessment

Role

Data Protection Officer

A Data Protection Officer (DPO) is the India-based individual a Significant Data Fiduciary must appoint to represent it and be the point of contact for grievances.

Defined inSection 2(l) / Section 10(2)(a)
CategoryPeople & Roles
Applies toSignificant Data Fiduciaries

What the Act says

DPDP Act 2023, Section 2(l)

"Data Protection Officer" means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10.

In plain language

The DPO is a mandatory role only for Significant Data Fiduciaries. Section 10(2)(a) requires the DPO to be based in India and answerable to the fiduciary's board.

The DPO represents the fiduciary under the Act and is the contact point for the grievance redressal mechanism, making them the human face of compliance.

Example

A notified SDF appoints a DPO in India whose contact details are published so Data Principals can raise questions and complaints.

Related terms

Related sections of the Act

Related Rules

Frequently asked questions

Does every organisation need a DPO?

No. Only Significant Data Fiduciaries must appoint one under Section 10(2)(a).

Must the DPO be in India?

Yes. The DPO must be based in India and responsible to the fiduciary's governing body.

Continue learning