Readiness assessment
Share this section

Chapter II · Obligations of Data Fiduciary

Section 10: Significant Data Fiduciary

Section 10 creates a higher tier: the Government can designate a Significant Data Fiduciary, which then owes extra duties, an India-based DPO, an independent auditor, and periodic impact assessments and audits.

Official text
Section 10Significant Data Fiduciary
Chapter
Chapter II · Obligations of Data Fiduciary
Status
Enacted · phased commencement
Full compliance
13 May 2027
Applies to
Designated Fiduciaries
Official citation
DPDP Act, 2023, s.10
Reading time
5 min
Updated
August 2026

At a glance

Section 10 lets the Central Government designate a Data Fiduciary, or a class of them, as a Significant Data Fiduciary based on factors such as the volume and sensitivity of data, risk to Data Principals, and impact on the sovereignty, integrity, electoral democracy and security of India. A Significant Data Fiduciary must appoint an India-based Data Protection Officer, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits.

Applies to Designated (large / high-risk) FiduciariesChapter Chapter IIEffective 13 May 2027Read time 5 min

Key takeaways

  • The Government designates a Significant Data Fiduciary (SDF); you do not self-declare.
  • Designation weighs volume and sensitivity of data, risk to individuals, and national-interest factors.
  • An SDF must appoint a Data Protection Officer based in India, answerable to its board.
  • An SDF must appoint an independent data auditor.
  • An SDF must run periodic Data Protection Impact Assessments and audits.
  • Even if you are not designated, these duties are a good maturity target.

Who should read this

Read this if you process large volumes or sensitive categories of personal data, or operate at national scale, you are the most likely candidate for designation.

FoundersLegal / DPOCompliance leadsProduct / engineering

In plain language

Most obligations in the Act apply to every Data Fiduciary. Section 10 adds a higher tier for organisations whose processing carries greater risk. The Central Government may notify a Data Fiduciary, or a whole class, as a Significant Data Fiduciary. You do not choose this label, it is assigned.

The assessment looks at the volume and sensitivity of the personal data processed, the risk to the rights of Data Principals, and national-interest factors, the sovereignty and integrity of India, risk to electoral democracy, security of the State and public order.

Designation brings three concrete duties. Appoint a Data Protection Officer based in India, answerable to the board and acting as the contact for grievances. Appoint an independent data auditor. And carry out periodic Data Protection Impact Assessments and audits, plus any other measures the rules prescribe.

The text of the law

Section 10: Significant Data Fiduciary

10(1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary, on the basis of an assessment of relevant factors, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State and public order.

10(2)(a) A Significant Data Fiduciary shall appoint a Data Protection Officer who is based in India, is responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal.

10(2)(b) It shall appoint an independent data auditor to carry out data audit and evaluate compliance with the Act.

10(2)(c) It shall undertake periodic Data Protection Impact Assessment, periodic audit, and such other measures as may be prescribed.

Wording reproduced or summarised from the enacted Act. Always confirm against the official Gazette text for authoritative language.

What this means for you

Frequently asked questions

Who is a Significant Data Fiduciary?
A Data Fiduciary, or class of them, that the Central Government notifies as significant based on the volume and sensitivity of data, risk to individuals, and national-interest factors. It is assigned by designation, not self-declared.
What extra duties does an SDF have?
Appoint an India-based Data Protection Officer answerable to the board, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits.
Does the DPO have to be in India?
Yes. A Significant Data Fiduciary's Data Protection Officer must be based in India and responsible to the governing body.
How do I know if I will be designated?
There is no automatic threshold; designation is by Government notification. Large-volume or sensitive-data processors are the most likely candidates and should prepare early.

Sources

This is an educational explanation, not legal advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.

Start readiness assessment