Readiness assessment

DPDP by role

DPDP Act for Significant Data Fiduciaries (SDF)

The Significant Data Fiduciary tier carries extra obligations under Section 10. Here is what changes.

At a glance

A Significant Data Fiduciary (SDF) is a Data Fiduciary designated by the Government based on data volume, sensitivity and risk. On top of the core duties, an SDF must appoint an India-based Data Protection Officer who reports to the board, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits under Section 10.

What the DPDP Act means for you

If your organisation is designated a Significant Data Fiduciary, or is large, high-risk, or handles sensitive or children's data at scale and may be, you face a higher bar. Beyond the core Data Fiduciary duties, Section 10 adds governance: a senior India-based DPO, an independent audit, and periodic impact assessments. Building this programme takes time, so start before any formal designation.

Your priorities

India-based DPO

Appoint a Data Protection Officer based in India who reports to the board or governing body.

Independent audit

Appoint an independent data auditor to evaluate your DPDP compliance.

Periodic DPIA

Run Data Protection Impact Assessments and periodic reviews of high-risk processing.

Governance

Put the oversight in place to hold the programme together and evidence it.

Where to start

Confirm your status

Assess whether you are, or are likely to be, designated an SDF.

Appoint the roles

An India-based DPO reporting to the board, and an independent auditor.

Run a DPIA

Assess your high-risk processing and document mitigations.

Operate the cycle

Schedule periodic audits and reviews.

Tools and help

Move fast with ready-made resources, or get expert help where it matters:

Frequently asked questions

Who becomes a Significant Data Fiduciary?
The Government designates SDFs based on the volume and sensitivity of data processed and the risks involved. Large or high-risk processors should prepare even before any designation.
What extra obligations does an SDF have?
Under Section 10: an India-based DPO reporting to the board, an independent data auditor, and periodic Data Protection Impact Assessments and audits, on top of the core duties.
Should we prepare before being designated?
Yes. The SDF programme takes time to build, so large or high-risk organisations should not wait for a formal designation.

See where you stand

Take the free readiness assessment for a picture tailored to your organisation, then choose a tool or a partner.

Start free readiness assessmentSee the Compliance Toolkit

This page is educational and not legal advice. Confirm against the enacted Act and the DPDP Rules, or take professional advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.