Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsCompare terms
Every Significant Data Fiduciary is first a Data Fiduciary. The 'significant' label is added by the Central Government for higher-risk fiduciaries, and it brings extra obligations.
The ‘significant’ label is not cosmetic: it layers on heavier duties. A Significant Data Fiduciary must appoint an India-based Data Protection Officer, engage an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits under Section 10, along with the additional obligations in Rule 13. Those requirements carry real cost and governance overhead.
Every organisation that decides the purpose and means of processing is a Data Fiduciary from day one. It becomes a Significant Data Fiduciary only when the Central Government notifies it as one. Section 10(1) lists the factors the Government weighs: the volume and sensitivity of personal data, risk to the rights of Data Principals, and risks to India's sovereignty and integrity, electoral democracy, security of the State and public order.
There is no self-assessed threshold that flips the switch automatically — the designation comes by notification.
“We're large, so we must be an SDF.” Size alone doesn't decide it; it is a Government notification weighing several factors, not a headcount or turnover test.
Confusing the SDF's DPO with the general contact duty. Every fiduciary must publish a contact for answering rights questions (Section 8(9) and Rule 9). Only an SDF must appoint a dedicated, India-based DPO (Section 10(2)(a)).
Assuming the duties already bite. Section 10 commences with the main obligations on 13 May 2027.
What makes a fiduciary 'significant'?
A Central Government notification under Section 10, based on data volume and sensitivity and risks to rights, sovereignty, security and public order.
What extra duties apply?
An India-based DPO, an independent data auditor, and periodic impact assessments and audits.
Consultant-led and partner-backed.