Under the Digital Personal Data Protection Act 2023, the Central Government may notify any Data Fiduciary, or a class of them, as a Significant Data Fiduciary (SDF). SDFs carry extra obligations on top of the ones that apply to every Data Fiduciary.
How an organisation is notified as an SDF
The Government assesses factors set out in Section 10 of the Act, including:
- The volume and sensitivity of the personal data processed
- The risk to the rights of Data Principals
- The potential impact on the sovereignty and integrity of India
- The risk to electoral democracy
- The security of the State and public order
There is no published list or turnover threshold. Large banks, NBFCs, insurers, health platforms, telecom and social media or e-commerce platforms with very large user bases are the likeliest candidates.
Additional obligations of an SDF
1. Data Protection Officer based in India
An SDF must appoint a Data Protection Officer who is based in India, represents the organisation under the Act, is answerable to its Board of Directors or similar governing body, and is the point of contact for the grievance redressal mechanism.
2. Independent data auditor
An SDF must appoint an independent data auditor to evaluate its compliance with the Act.
3. Data Protection Impact Assessment and periodic audit
An SDF must carry out a Data Protection Impact Assessment and a periodic audit, and the Rules require the findings to be reported to the Board. The Rules also add duties such as due diligence on algorithmic software used for processing, and restrictions on transferring specified personal data outside India.
Penalty exposure
Breaching the additional obligations of an SDF can attract a penalty of up to ₹150 crore. See DPDP Act penalties explained for the full schedule.
What to do before you are notified
- Assess honestly whether your scale and data sensitivity make notification likely.
- Identify who would be the India-based DPO, and where they would report.
- Build the independent audit and DPIA into your annual audit calendar.
- Run a gap assessment first, so the first formal audit is not also the first discovery of gaps.
DPDP Audits works as an independent auditor and, where a retainer is preferred, as a virtual DPO adviser. See the DPDP audit checklist for what is tested.
