← All posts

17 Aug 2026 · 6 min read

Significant Data Fiduciary Under Section 10 of the DPDP Act: Obligations, Triggers, and What to Prepare

Significant Data Fiduciary Under Section 10 of the DPDP Act: Obligations, Triggers, and What to Prepare

Most DPDP obligations apply to every Data Fiduciary.

Section 10 creates a heavier tier: the Significant Data Fiduciary (SDF) — and if your organisation is notified into it, your compliance programme roughly doubles.

Here is what §10 actually says, who is likely to be covered, and what an SDF has to build.


Who Becomes a Significant Data Fiduciary?

You do not self-declare as an SDF. The Central Government notifies a Data Fiduciary, or a class of Data Fiduciaries, as significant — based on an assessment of factors the Act lists:

In practice: large consumer platforms, BFSI, healthcare, telecom, and any business processing sensitive data at scale should plan as if notification is a matter of when, not if. Our industry guides for BFSI and hospitals cover the sector angles.


The Four Extra Obligations of an SDF

1. A Data Protection Officer, Based in India

An SDF must appoint a DPO who represents it under the Act, is based in India, is responsible to the board of directors (or equivalent governing body), and acts as the point of contact for grievance redressal under §13.

What that job looks like day to day: why DPOs choose ProtectComply.

2. An Independent Data Auditor

SDFs must appoint an independent data auditor to evaluate compliance with the Act. That means your evidence has to survive someone whose job is to find the gaps — see our DPDP audit guide.

3. Periodic Data Protection Impact Assessments

DPIAs stop being optional good practice and become a recurring statutory exercise. Full guide: DPIA under the DPDP Act — who must do one and how.

4. Periodic Audits and Other Prescribed Measures

Beyond the DPIA, §10 requires periodic audit and leaves room for further measures to be prescribed under the Rules — which is why SDF programmes need machinery, not one-time projects. The phasing of these obligations follows the DPDP Rules 2025 timeline.


What to Prepare Before You Are Notified

ProtectComply maps each of these to a workflow — see how ProtectComply maps every DPDP Act section to a workflow, or start with a free readiness assessment.