Designation comes first
Under section 10, the Central Government may notify a Data Fiduciary or class as significant after considering factors such as volume and sensitivity, risk to Data Principals, sovereignty, electoral democracy, security and public order.
Do not present an assumed revenue, employee or record threshold as law unless it appears in a valid notification. Monitor official notifications and document the person responsible for evaluating them.
What the statutory DPO role requires
A Significant Data Fiduciary must appoint a Data Protection Officer based in India who represents the organisation under the Act, is responsible to its board or similar governing body, and serves as the contact point for grievance redressal.
The designation also brings a Data Protection Impact Assessment, periodic audit and other prescribed measures. The role therefore needs authority, access and operational support rather than a title alone.
Prepare accountability before designation
Organisations not designated as significant still need a published business contact capable of answering Data Principal questions and a grievance mechanism. Assigning privacy ownership can be sensible even where the statutory DPO title is not required.
Keep the distinction explicit in public statements and contracts. Claiming to have a statutory DPO can create confusion if the organisation has not been designated and the role does not meet section 10.
Sources and editorial review
Prepared by DPDP Academy Editorial (Legal education and implementation guidance). Reviewed by DPDP Academy Source Review using the sources below on 2 August 2026. Statutory text, notified Rules and practical interpretation are kept distinct. Educational content, not legal advice.