Significant Data Fiduciary Under Section 10 of the DPDP Act: Obligations, Triggers, and What to Prepare
Significant Data Fiduciary Under Section 10 of the DPDP Act: Obligations, Triggers, and What to Prepare
Most DPDP obligations apply to every Data Fiduciary.
Section 10 creates a heavier tier: the Significant Data Fiduciary (SDF) — and if your organisation is notified into it, your compliance programme roughly doubles.
Here is what §10 actually says, who is likely to be covered, and what an SDF has to build.
Who Becomes a Significant Data Fiduciary?
You do not self-declare as an SDF. The Central Government notifies a Data Fiduciary, or a class of Data Fiduciaries, as significant — based on an assessment of factors the Act lists:
- The volume and sensitivity of personal data processed
- The risk to the rights of Data Principals
- The potential impact on the sovereignty and integrity of India
- Risk to electoral democracy
- Security of the State and public order
In practice: large consumer platforms, BFSI, healthcare, telecom, and any business processing sensitive data at scale should plan as if notification is a matter of when, not if. Our industry guides for BFSI and hospitals cover the sector angles.
The Four Extra Obligations of an SDF
1. A Data Protection Officer, Based in India
An SDF must appoint a DPO who represents it under the Act, is based in India, is responsible to the board of directors (or equivalent governing body), and acts as the point of contact for grievance redressal under §13.
What that job looks like day to day: why DPOs choose ProtectComply.
2. An Independent Data Auditor
SDFs must appoint an independent data auditor to evaluate compliance with the Act. That means your evidence has to survive someone whose job is to find the gaps — see our DPDP audit guide.
3. Periodic Data Protection Impact Assessments
DPIAs stop being optional good practice and become a recurring statutory exercise. Full guide: DPIA under the DPDP Act — who must do one and how.
4. Periodic Audits and Other Prescribed Measures
Beyond the DPIA, §10 requires periodic audit and leaves room for further measures to be prescribed under the Rules — which is why SDF programmes need machinery, not one-time projects. The phasing of these obligations follows the DPDP Rules 2025 timeline.
What to Prepare Before You Are Notified
- A current RoPA — every SDF obligation assumes you know what you process and why
- A named DPO candidate and reporting line to the board
- A repeatable DPIA method, not a one-off document
- Audit-ready evidence generated continuously, not reconstructed annually
ProtectComply maps each of these to a workflow — see how ProtectComply maps every DPDP Act section to a workflow, or start with a free readiness assessment.