DPDP Audits

Significant Data Fiduciary under DPDP: Criteria and Obligations

How an organisation is notified as a Significant Data Fiduciary under the DPDP Act, and the extra duties: India-based DPO, independent data auditor, DPIA and periodic audits.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 4 October 2026

Under the Digital Personal Data Protection Act 2023, the Central Government may notify any Data Fiduciary, or a class of them, as a Significant Data Fiduciary (SDF). SDFs carry extra obligations on top of the ones that apply to every Data Fiduciary.

How an organisation is notified as an SDF

The Government assesses factors set out in Section 10 of the Act, including:

There is no published list or turnover threshold. Large banks, NBFCs, insurers, health platforms, telecom and social media or e-commerce platforms with very large user bases are the likeliest candidates.

Additional obligations of an SDF

1. Data Protection Officer based in India

An SDF must appoint a Data Protection Officer who is based in India, represents the organisation under the Act, is answerable to its Board of Directors or similar governing body, and is the point of contact for the grievance redressal mechanism.

2. Independent data auditor

An SDF must appoint an independent data auditor to evaluate its compliance with the Act.

3. Data Protection Impact Assessment and periodic audit

An SDF must carry out a Data Protection Impact Assessment and a periodic audit, and the Rules require the findings to be reported to the Board. The Rules also add duties such as due diligence on algorithmic software used for processing, and restrictions on transferring specified personal data outside India.

Penalty exposure

Breaching the additional obligations of an SDF can attract a penalty of up to ₹150 crore. See DPDP Act penalties explained for the full schedule.

What to do before you are notified

  1. Assess honestly whether your scale and data sensitivity make notification likely.
  2. Identify who would be the India-based DPO, and where they would report.
  3. Build the independent audit and DPIA into your annual audit calendar.
  4. Run a gap assessment first, so the first formal audit is not also the first discovery of gaps.

DPDP Audits works as an independent auditor and, where a retainer is preferred, as a virtual DPO adviser. See the DPDP audit checklist for what is tested.

Frequently asked questions

What is a Significant Data Fiduciary under the DPDP Act?

A Data Fiduciary, or class of Data Fiduciaries, that the Central Government notifies as significant based on factors such as the volume and sensitivity of personal data, risk to Data Principals, and impact on the security of the State and public order.

What extra obligations does a Significant Data Fiduciary have?

It must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out a Data Protection Impact Assessment and periodic audits. The Rules add duties such as due diligence on algorithmic software and limits on transferring specified data outside India.

Is there a list of Significant Data Fiduciaries?

Notification is by the Central Government, and there is no published turnover or user threshold. Large banks, insurers, health platforms and big consumer platforms are the likeliest candidates.

What is the penalty for an SDF breaching its additional obligations?

Up to ₹150 crore under the Schedule to the Act.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.