Significant Data Fiduciary under DPDP:
criteria and Rule 13 duties.
How the Central Government decides which companies are Significant Data Fiduciaries, and what they then owe: a DPO in India, an independent data auditor, a DPIA and audit every twelve months, algorithmic due diligence and possible data localisation.
Last updated Published by TryTrustableNot legal advice
What is a Significant Data Fiduciary under DPDP?
A Significant Data Fiduciary is a Data Fiduciary, or a class of them, that the Central Government has notified under section 10 of the DPDP Act after assessing the volume and sensitivity of its data and the risks its processing poses. Notification brings extra duties: a DPO in India, an independent data auditor, and periodic impact assessments and audits.
Section 10(1) lists the factors the Government may assess, including:
- the volume and sensitivity of personal data processed
- the risk to the rights of Data Principals
- the potential impact on the sovereignty and integrity of India
- the risk to electoral democracy
- security of the State
- public order
The list is open ("including"), there are no numeric thresholds, and the notification can name one company or a class. Three points follow. The Central Government designates, not the Data Protection Board. Nobody is an SDF by crossing a line; until notified, you are an ordinary Data Fiduciary. And the Government can gather what it needs first: under Rule 23 and item 3 of the Seventh Schedule, an officer of MeitY designated by its Secretary may call for information from any Data Fiduciary to assess whether it should be notified.
Reporting on MeitY's January 2026 consultation described large technology platforms, social media intermediaries, and most major banks, financial services and insurance companies as the expected focus. That is reporting, not a notification. Our Significant Data Fiduciary checker walks through the section 10 factors for your own processing.
What must a Significant Data Fiduciary do?
A Significant Data Fiduciary must appoint a Data Protection Officer based in India, appoint an independent data auditor, carry out a Data Protection Impact Assessment and an audit every twelve months and report the significant findings to the Board, check that its algorithms do not endanger Data Principals' rights, and keep any Government-specified data in India.
| Duty | Source | What it requires |
|---|---|---|
| Data Protection Officer | s.10(2)(a) | An individual who represents the SDF under the Act, is based in India, is responsible to the board of directors or similar governing body, and is the point of contact for grievance redressal. |
| Independent data auditor | s.10(2)(b) | Appointed to carry out a data audit evaluating the SDF's compliance with the Act. |
| DPIA | s.10(2)(c)(i), Rule 13(1) | Describes Data Principals' rights and the purpose of processing, and assesses and manages the risk to those rights. Once in every twelve months. |
| Periodic audit | s.10(2)(c)(ii), Rule 13(1) | An audit to ensure effective observance of the Act and Rules, on the same twelve-month cycle. |
| Report to the Board | Rule 13(2) | The person carrying out the DPIA and audit gives the Board a report containing its significant observations. |
| Algorithmic due diligence | Rule 13(3) | Verify that technical measures, including algorithmic software, used to host, display, upload, modify, publish, transmit, store, update or share personal data are not likely to pose a risk to Data Principals' rights. |
| Localisation of specified data | Rule 13(4)–(5) | Keep personal data specified by the Government, on a committee's recommendation, and the traffic data about its flow, inside India. |
From section 10 of the Act and Rule 13 of the DPDP Rules 2025. Rule 13 commences on 13 May 2027.
Everything that binds an ordinary Data Fiduciary still applies on top: notice, consent, security, breach intimation, retention, children's data and rights.
Is the SDF impact assessment and audit annual?
Yes, in effect. Rule 13(1) requires a Significant Data Fiduciary to undertake a Data Protection Impact Assessment and an audit once in every period of twelve months, counted from the date it was notified as an SDF or included in a notified class. The Act itself only says periodic; the Rule fixes the interval.
Three details shape how you run it. The clock runs from your notification date, not the financial year, so it will not line up with a statutory audit unless you make it. The report of significant observations goes to the Board from the person who did the work, which is a reason to use an auditor whose independence will stand up. And the DPIA content is set by section 10(2)(c)(i): the rights of Data Principals, the purposes of processing, and how risk to those rights is assessed and managed. Our DPIA template for DPDP and GDPR follows that structure.
An assessment that goes stale between cycles is the common failure. Tying it to live control state helps: our risk register recalculates residual risk from control results rather than storing the number somebody typed, and the evidence ledger keeps what the auditor saw.
What does algorithmic due diligence under Rule 13(3) mean?
Rule 13(3) requires a Significant Data Fiduciary to verify, with due diligence, that the technical measures and algorithmic software it uses to handle personal data are not likely to pose a risk to Data Principals' rights. It covers recommendation, ranking, moderation and similar systems, and it is a continuing duty, not a one-off review.
The Rule does not prescribe a method. A defensible approach, in our view, has four parts: an inventory of the algorithmic systems that touch personal data, a documented test of each against the rights the Act gives (access, correction, erasure, grievance, and the section 9 limits for children), records of what was found and changed, and a repeat whenever a system materially changes. If you already run an AI risk programme, the AI governance controls and ISO/IEC 42001 impact assessment can carry much of it.
When do SDF obligations apply?
Rule 13 commences on 13 May 2027, eighteen months after the DPDP Rules were published, and the twelve-month DPIA and audit cycle then runs from each SDF's notification date. No SDF notification had been found as of 28 September 2026, and a January 2026 proposal to bring SDF duties forward had not been notified.
According to Business Standard's report of 22 January 2026 and commentary on the consultation, MeitY proposed cutting the window for SDFs from eighteen months to twelve, which would mean 13 November 2026, and bringing forward the notification power in section 10(1). As of 28 September 2026 no amending notification has been published. A company that expects to be notified should plan for November 2026 regardless: appointing a DPO and an auditor takes longer than publishing a notification.
One more lever cuts the other way. Section 17(3) lets the Government exempt notified Data Fiduciaries, including startups, from sections 5, 8(3), 8(7), 10 and 11.
Breach of section 10 carries a ceiling of ₹150 crore per instance, under item 4 of the Schedule. The DPDP penalty schedule sets that against the other heads.
Related guides: children's data and verifiable parental consent, cross-border data transfer, data retention and erasure, how the Data Protection Board works and the dated DPDP regulatory tracker. The DPDP Act and Rules 2025 guide sets out the whole timetable, and the DPDP penalty schedule what each failure can cost.
The things people ask us
Who decides whether a company is a Significant Data Fiduciary?
The Central Government, by notification under section 10(1) of the DPDP Act. The Data Protection Board does not designate SDFs. The Government assesses factors including the volume and sensitivity of data, risk to Data Principals' rights, sovereignty, electoral democracy, security of the State and public order. A company is not an SDF until it, or its class, is notified.
Is there a user or revenue threshold for Significant Data Fiduciaries?
No. Section 10 lists factors, not numbers, and the Government may notify an individual company or a whole class. The Third Schedule's thresholds of two crore and fifty lakh registered users relate to data retention under Rule 8, not to SDF status, although the same large platforms are likely to be in both.
How often must a Significant Data Fiduciary do a DPIA and audit?
Once in every period of twelve months, counted from the date it is notified as an SDF or included in a notified class, under Rule 13(1). Each cycle covers a Data Protection Impact Assessment and an audit, and the person who carries them out must give the Board a report of the significant observations.
Does the Data Protection Officer have to be in India?
Yes. Section 10(2)(a) requires a Significant Data Fiduciary's DPO to be based in India, to represent the SDF under the Act, to be an individual responsible to its board of directors or similar governing body, and to be the point of contact for grievance redressal. Other Data Fiduciaries need only publish a contact under Rule 9.
What is the penalty for breaching SDF obligations?
Up to ₹150 crore per instance under item 4 of the Schedule to the Act, for breach of the additional obligations in section 10. Other heads still apply to an SDF: ₹250 crore for security safeguards, ₹200 crore for breach notification or children's data, and ₹50 crore for anything else.
Have any Significant Data Fiduciaries been notified?
We have found no notification under section 10 as of 28 September 2026. Rule 13 commences on 13 May 2027. January 2026 reporting described a MeitY proposal to shorten the window for SDFs to twelve months, which would move it to November 2026; that proposal had not been notified by 28 September 2026.
Start with what your own site collects.
An SDF's first DPIA begins with an inventory. The free scan gives you the part that lives on your website: every tracker, where it sends data, and whether it waits for consent.