Appointing a Data Protection Officer is an obligation of Significant Data Fiduciaries, not of every Data Fiduciary. Where an organisation is classified as a Significant Data Fiduciary, it must appoint a DPO who is based in India, is answerable to its board or equivalent governing body, and acts as the contact point for the grievance redressal mechanism.
The practical first task is therefore the classification itself. The Act allows the Central Government to notify a Data Fiduciary or class of them as Significant, taking into account factors such as the volume and sensitivity of personal data processed, the risk to data principals, and the potential effect on the sovereignty and integrity of India, electoral democracy, security of the State and public order.
Because that determination governs several other duties, it should be made deliberately and recorded — with the reasoning — rather than assumed. An organisation that has never asked the question cannot show why it concluded the obligations do not apply.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →