Free SDF checker

Significant Data Fiduciary checker
for the DPDP Act, section 10.

Designation as a Significant Data Fiduciary is made by Central Government notification, not by any test you can run. What you can do is see how the section 10(1) factors read for you, and decide how much to prepare. This tool shows its reasoning and sends nothing anywhere.

Volume · s.10(1)(a)

Customers, users and anyone else whose personal data you hold. The Act sets no threshold; the bands are ours.
Sector is not a factor in the Act, but it is how designations are expected to be drawn.

Sensitivity · s.10(1)(a)

Risk to Data Principals · s.10(1)(b)

National factors · s.10(1)(c)–(f)

Read the SDF guide
Worked example: a digital lender with 80 lakh borrowers

How the factors read

This tool cannot determine whether you are a Significant Data Fiduciary. Only a Central Government notification under section 10(1) can. The indication is our reading of the factors, not a prediction of any decision.
ModerateIndication only: 7 points on our scale. Some factors point towards designation; none decides it.
Indication on our 0–20 scale7
Volume: 50 lakh to 2 crore people in India+3
Sensitive data: Financial or credit data, Government identity numbers+2
Risk to rights: Automated decisions about access to credit, insurance, jobs or services+2
National factors: none selected+0
Sector: Other+0

Prepare as if designation were possible: the duties below take longer than a notification takes to publish.

01

What is a Significant Data Fiduciary under the DPDP Act?

A Significant Data Fiduciary is a Data Fiduciary, or class of them, that the Central Government notifies under section 10 of the DPDP Act after assessing factors such as the volume and sensitivity of the data, risk to people's rights, and national concerns. Designation adds duties: a DPO in India, an independent data auditor, and an annual DPIA and audit.

The definition is in section 2(z) of the Act, and the only route to the status is section 10(1): the government may notify any Data Fiduciary or class of Data Fiduciaries, on the basis of an assessment of such relevant factors as it may determine. There is no application, no self-designation and no numeric threshold. A company can process data about crores of people and never be notified; a smaller one can be, if it falls in a notified class.

02

What factors decide Significant Data Fiduciary status?

Section 10(1) lists six factors the government may assess: the volume and sensitivity of personal data processed, the risk to Data Principals' rights, potential impact on India's sovereignty and integrity, risk to electoral democracy, security of the State, and public order. The list is not closed; the government may weigh other relevant factors too.

FactorSectionHow this checker reads it
Volume of personal data10(1)(a)Four bands of people in India. The top band starts at two crore, the number the Rules use for large e-commerce and social media platforms in the Third Schedule
Sensitivity of personal data10(1)(a)The DPDP Act has no special-category list, so we count the categories most regimes treat as sensitive, up to three
Risk to the rights of Data Principals10(1)(b)Automated decisions, profiling, onward sharing and public content, two points each
Sovereignty and integrity of India10(1)(c)Government, defence or critical infrastructure data
Risk to electoral democracy10(1)(d)Political advertising, voter data, election discourse at scale
Security of the State10(1)(e)Telecom, payments and critical infrastructure operators
Public order10(1)(f)Platforms where content spreads quickly between many users

Factors from section 10(1) of the DPDP Act. The points and bands are this tool's heuristic, not anything in the Act or the Rules.

Sector is not a statutory factor, and it is scored lightly for that reason. It is included because designations are expected to be drawn by class, and the classes most discussed, including in MeitY's January 2026 consultation on bringing the May 2027 date forward for the largest companies, are large platforms, banks and insurers. As of 28 September 2026 that proposal has not been notified.

03

What extra duties does a Significant Data Fiduciary have?

A Significant Data Fiduciary must appoint a Data Protection Officer based in India and answerable to the board, appoint an independent data auditor, carry out a Data Protection Impact Assessment and an audit every twelve months, report their significant observations to the Board, check its algorithmic software for risk to people's rights, and keep government-specified data in India.

DutySourceWhat it takes
Data Protection Officer, based in India, responsible to the board, the grievance contacts.10(2)(a)A named individual with authority, not a shared inbox
Independent data auditors.10(2)(b)An auditor who evaluates compliance with the Act
DPIA and audit once every twelve monthss.10(2)(c), Rule 13(1)Counted from the date of notification. A DPIA template is a starting point
Report significant observations to the BoardRule 13(2)The DPIA and audit findings go to the regulator
Due diligence on algorithmic softwareRule 13(3)Evidence that the technical measures, not only the policies, do not put rights at risk
Localisation of specified dataRule 13(4)Personal data the government specifies, and its traffic data, stays in India
Penalty for failing these dutiesSchedule, item 4Up to ₹150 crore per instance

Rule 13 of the DPDP Rules 2025 commences on 13 May 2027.

04

Why prepare before you are notified

Every duty above takes longer to stand up than a notification takes to publish. Finding a DPO with the standing to report to a board, contracting an independent auditor and running a first DPIA across real systems is months of work, and the twelve-month clock in Rule 13 starts on the date of notification, not on the date you are ready. If the indication above is moderate or higher, the defensible position is to have the DPIA method, the audit scope and the DPO candidate decided in advance.

The preparation is not wasted if you are never designated. A DPIA is the cheapest way to find out what you actually process, and it is the document enterprise buyers' security reviews ask for. The Significant Data Fiduciary guide covers the duties in depth, the DPDP compliance checklist lists them alongside every ordinary duty, and the DPDP penalty calculator prices the section 10 entry with the rest. Our risk register recalculates residual risk from live control results, which is what keeps an annual DPIA from going stale in between.

Questions

The things people ask us

How does a company become a Significant Data Fiduciary?

Only by notification. Section 10(1) lets the Central Government notify a Data Fiduciary, or a class of them, as significant after assessing factors including volume, sensitivity, risk to rights and national interests. There is no application or self-designation, so check the Gazette and MeitY's notifications for any that name you or a class you belong to.

Is there a user threshold for Significant Data Fiduciary status?

No. Neither the Act nor the Rules set a number. The Rules use two crore registered users for the Third Schedule retention rule for large e-commerce and social media platforms, and this checker borrows that figure for its top volume band, but it is not an SDF test. Designation turns on the government's assessment.

When do Significant Data Fiduciary duties start?

Rule 13 of the DPDP Rules 2025 commences on 13 May 2027, with the other substantive rules. For a notified entity the DPIA and audit then run once every twelve months from the date of notification. MeitY consulted in January 2026 on an earlier date for large companies; that change had not been notified as of 28 September 2026.

Does a Significant Data Fiduciary need a DPO in India?

Yes. Section 10(2)(a) requires a Data Protection Officer who represents the SDF under the Act, is based in India, is an individual responsible to the board of directors or similar governing body, and is the point of contact for grievance redressal. Other Data Fiduciaries only need to publish a contact who can answer questions.

What is the penalty for failing Significant Data Fiduciary duties?

Up to ₹150 crore per instance, under the Schedule to the Act. The Board fixes the actual amount after an inquiry, weighing the nature, gravity and duration of the breach, whether it was repeated and what was done to mitigate it. Security failures are a separate entry, capped at ₹250 crore.

Can this tool tell me whether I will be designated?

No, and nothing can until a notification is published. The tool reads your answers against the section 10(1) factors and gives an indication with its reasoning, so you can decide how much to prepare. The points and bands are our own heuristic, not a test in the Act or the Rules.

Book a walkthrough

Designation is a date. The DPIA is a system.

An annual DPIA written from memory is out of date the week after it is signed. The platform keeps the risk picture tied to live control results, so the next assessment starts from what is true today.