← All posts

25 Aug 2026

Data Protection Officer DPDP Act: Who Must Appoint One

The most common question we get from Indian compliance teams is also the one most articles answer badly: do we have to appoint a Data Protection Officer under the DPDP Act?

Who must appoint a Data Protection Officer under DPDP Act Section 10: mandatory for Significant Data Fiduciaries, grievance contact still required for others
The DPO duty attaches to Significant Data Fiduciaries under Section 10; every fiduciary still needs a grievance route.

For most organisations, the legal answer is no. The practical answer is that you still have to name someone, publish their contact details, and be able to answer for your processing when a Data Principal or the Board asks. Those are two different obligations, and conflating them leads companies either to over-hire or to miss a requirement that applies to everyone.

Quick answer

Who needs a Data Protection Officer under the DPDP Act?

Only Significant Data Fiduciaries do — so the question becomes what makes you one. SDF status is not self-assessed and it is not a size threshold you cross automatically. The Central Government notifies a Data Fiduciary, or a class of them, based on factors set out in Section 10(1):

In practice, the classes most likely to be notified are large consumer platforms, major BFSI entities, telecom operators, large healthcare networks, and companies processing children’s data or biometrics at scale. If you are in one of those categories, plan for SDF obligations rather than waiting for the notification. Our explainer on Significant Data Fiduciary status under Section 10 goes through the criteria in detail.

Data Protection Officer under the DPDP Act: what the role requires

The Act is short on the role and specific on three structural points. The DPO must be:

  1. Based in India. A group DPO sitting in Singapore, London or Dublin does not satisfy Section 10(2)(a). A multinational with an Indian SDF entity needs an India-based appointee, whatever the global reporting line.
  2. The published point of contact for both Data Principals exercising their rights and for the Data Protection Board.
  3. Reporting to the board of directors or similar governing body. This is a governance requirement, not a job title. A DPO buried three levels under the CISO, with no route to the board, is a structural non-compliance even if the person is excellent.

Alongside the DPO, Section 10(2) requires SDFs to appoint an independent data auditor to carry out a data audit, and to conduct periodic Data Protection Impact Assessments. Those two obligations consume more DPO time than anything else in the first year. See DPIA under the DPDP Act and PIA vs DPIA for the distinction that trips most teams up.

What everyone else has to do instead

This is the part that gets skipped. Rule 9 applies to every Data Fiduciary, regardless of size, sector or SDF status. You must:

Separately, Section 13 requires you to provide a readily available means of grievance redressal, and to respond within the prescribed period. The named contact and the grievance channel are related but not identical: one is a person, the other is a process with a clock on it.

The lightweight version of compliance here is a named privacy contact, a monitored inbox, a published response commitment, and a log. The failure version is [email protected] forwarding to a shared support queue nobody owns.

DPO vs privacy contact vs grievance officer

 Data Protection OfficerRule 9 contact personGrievance redressal
Who needs itSignificant Data Fiduciaries onlyEvery Data FiduciaryEvery Data Fiduciary
SourceSection 10(2)(a)Rule 9Section 13
LocationMust be based in IndiaNot specifiedNot specified
Reporting lineBoard of directorsNot prescribedNot prescribed
Can it be outsourced?Contested — see belowYes, if genuinely able to answerYes, with owned SLAs

Can you outsource the DPO role?

The Act does not expressly permit or prohibit an external DPO, and the market has filled that silence with “virtual DPO” and “DPO-as-a-service” offerings. A defensible reading is this: the statutory requirements are that the DPO is based in India, is the published contact, and reports to the board. An external appointee can satisfy all three if the engagement is structured properly — a named individual rather than a firm, a formal appointment, board access in writing, and enough retained hours to actually discharge the role.

An engagement that fails those tests — a logo on a website, a shared mailbox, four hours a month, no board line — is unlikely to survive scrutiny after an incident. If you go external, treat it as an appointment with governance, not a subscription.

Indicative Indian market pricing, based on published rates:

Those numbers sit inside a wider budget picture we break down in DPDP compliance cost in India.

What the DPO’s first year actually looks like

Whether the role is in-house or external, the workload in year one is dominated by building the evidence base, not by advising:

  1. Data inventory and RoPA. You cannot govern what you have not mapped. Start with data discovery and build the records of processing activities.
  2. Lawful basis and notice review. Every processing purpose needs a defensible basis and a standalone notice.
  3. Consent architecture. Purpose-level capture, evidence-grade records, withdrawal parity — see our guide to choosing a DPDP consent management platform.
  4. Rights and grievance workflows with SLA timers, covering access, correction, erasure and nomination. See Data Principal rights.
  5. Breach response. The clock is unforgiving — read our guide to DPDP breach notification.
  6. Vendor and processor diligence. You remain accountable for your processors. See vendor risk management under DPDP.
  7. Retention and deletion. Covered in our DPDP data retention policy guide.
  8. DPIA and independent audit if you are an SDF.

Nearly all of that is evidence production. A DPO with no system underneath spends the year building spreadsheets that go stale, which is why the role and the platform decision are usually made together — see our comparison of the best DPDP platform in India.

The penalty context

Breach of SDF obligations under Section 10 — which includes failing to appoint a compliant DPO — attracts a penalty of up to ₹150 crore. Failure to implement reasonable security safeguards attracts up to ₹250 crore, and failure to notify a breach up to ₹200 crore. Because these are separate defaults, a single incident can trigger more than one. Full breakdown in DPDP Act penalties explained.

A practical decision path

Work through this once a year, and again whenever your processing volumes or sectoral classification change.

  1. Are you likely to be notified as an SDF? If yes, appoint an India-based DPO with a board reporting line now, and budget for DPIA and independent audit.
  2. If no, name a Rule 9 contact person today, publish it prominently, and wire it into every rights response.
  3. Either way, put the grievance process behind an SLA and log every request. That log is your defence.
  4. Re-test annually. SDF designation can arrive by class notification, and your data volumes change.

What to look for when hiring a DPO in India

The Act prescribes no qualification, which means the market is unregulated and the CV signals are noisy. A workable competency profile has four legs:

Common substitutes that underperform: a company secretary with no data literacy, a security engineer with no statutory grounding, and an external counsel who advises quarterly but owns nothing.

What a DPO should put in front of the board

Section 10(2)(a) makes board reporting a legal characteristic of the role, so make the reporting substantive. A quarterly pack that works:

  1. Rights requests — volume, breakdown by type, SLA performance, and any breached deadlines with reasons.
  2. Grievances — open, closed, ageing, and escalation patterns.
  3. Consent health — coverage by purpose, withdrawal rates, and any purposes running without a defensible basis.
  4. Incidents — including near misses, with time-to-awareness measured. Time-to-awareness is the metric that determines whether you can meet Rule 7 at all.
  5. Vendor position — processors under contract with compliant clauses, versus processors without.
  6. DPIA and audit status — findings open, overdue, and accepted as risk.
  7. Top three exposures with an owner and a date against each.

Boards respond to trend lines and overdue counts. They do not respond to a maturity score with no denominator. Our note on the difference between a maturity model and a gap assessment covers why the second is more useful in year one.

SDF readiness: a twelve-month plan

If you expect to be notified, or your sector makes it likely, the sequencing that works:

QuarterFocusEvidence produced
Q1Appoint DPO, complete data discovery, draft RoPAAppointment letter, board minute, data inventory
Q2Notice and consent rebuild, rights and grievance workflowsVersioned notices, consent records, SLA logs
Q3DPIAs on high-risk processing, vendor remediationDPIA reports, revised processor contracts
Q4Independent data audit, breach tabletop, board reviewAudit report, exercise findings, remediation plan

Note that the independent auditor must be independent of whoever built the programme. If your consultant implements and then audits their own work, the audit is not worth filing. Our DPDP compliance audit guide covers what that separation looks like in practice.

In-house or outsourced Data Protection Officer under the DPDP Act

 In-house DPOFractional / virtual DPO
Cost₹25–60 lakh per year plus overheads₹9 lakh–₹36 lakh per year typical
AvailabilityFull time, present during incidentsRetained hours — check incident response terms
ContextDeep knowledge of your systems and politicsBroader cross-sector pattern recognition
Board accessStructuralMust be contractually engineered
RiskSingle point of failure, attritionThin engagement that fails scrutiny after an incident
Best forLarge SDFs, regulated sectorsNewly notified SDFs, first 12–18 months

A common and sensible pattern is an external DPO for the first year while the programme is built, transitioning to an internal appointment once there is enough operational load to justify the headcount.

Frequently asked questions

Is a Data Protection Officer under the DPDP Act mandatory for all companies?

No. Only Significant Data Fiduciaries notified by the Central Government under Section 10 must appoint a DPO. Every other Data Fiduciary must still publish a contact person under Rule 9.

Can our global DPO cover India?

Not for an SDF. Section 10(2)(a) requires the DPO to be based in India. A global DPO can retain oversight, but the appointed Indian DPO must be the published point of contact.

Does the DPO need a legal qualification?

The Act prescribes no qualification. In practice the role needs a working command of the Act and Rules, information security literacy, and enough seniority to be heard at board level.

Can the same person be DPO and CISO?

Nothing prohibits it, but consider the conflict: the DPO may need to report to the board on failures in controls the CISO owns. Separate the roles where you can.

Who is an SDF in India right now?

No organisations have been publicly notified as Significant Data Fiduciaries to date. Designation is by government notification, and can apply to a class of Fiduciaries rather than a single company.

What happens if we appoint no one?

If you are an SDF, that is a Section 10 default carrying up to ₹150 crore. If you are not, failing to publish a Rule 9 contact still leaves you unable to service rights requests within the prescribed period, which becomes a Section 13 problem.


Need the evidence base a Data Protection Officer under the DPDP Act can actually work from? Run a free DPDP readiness assessment or talk to our team about what SDF readiness looks like for your sector.