DPDPAcademyKnow the law. Prove it.
Home/Significant Data Fiduciary
§ 10 · DPDP Rules, 2025

You Do Not Become One. You Are Notified As One.

Significant Data Fiduciary is the only tier the DPDP Act creates, and it is not a threshold an organisation crosses by growing. The Central Government designates you, weighing factors that include risk to electoral democracy and the sovereignty of India alongside the volume of data you hold.

Designation, not a thresholdCurrent as of 13 August 2026
Section 10(1)

Six factors, and only one is about size

The list is expressly non-exhaustive: the Government assesses “such relevant factors as it may determine, including” these six. Note how much of it is about the State rather than about the individual.

01The volume and sensitivity of personal data processed
02Risk to the rights of the Data Principal
03Potential impact on the sovereignty and integrity of India
04Risk to electoral democracy
05Security of the State
06Public order
Section 10(2)

Three obligations on top of everything else

Designation does not replace the ordinary duties in sections 4 to 9. It adds to them.

A Data Protection Officer, in IndiaNot merely a privacy lead. The DPO represents the Significant Data Fiduciary under the Act, must be based in India, must be an individual answerable to the board of directors or equivalent governing body, and is the contact point for grievance redressal.
An independent data auditorAppointed to carry out a data audit and evaluate the organisation's compliance with the Act. The Act requires independence, which rules out marking your own homework through an internal audit function alone.
Periodic DPIA and auditA Data Protection Impact Assessment describing the rights of Data Principals and the purpose of processing, then assessing and managing the risk to those rights. Plus a periodic audit, and whatever further measures the Rules prescribe.

Read it verbatim: section 10 in full.

DPDP Rules, 2025

What the Rules turn “periodic” into

Every twelve months, not merely periodicallyThe Act says periodic. The Rules put a number on it: the DPIA and the audit are each carried out once every twelve months from the date of designation.
The Board sees the findingsA report containing significant observations from the assessment and audit is furnished to the Data Protection Board. This is the part that changes the stakes - the regulator receives your own auditor's list of problems.
Algorithmic due diligenceAn obligation to verify that algorithmic software used to process personal data is not likely to pose a risk to the rights of Data Principals. Recommendation engines, ranking, content moderation and automated decisioning all fall inside this, and nothing comparable applies to an ordinary Data Fiduciary.
Targeted localisation, not blanket localisationCategories of personal data specified by the Central Government, on the recommendation of a committee it constitutes, must not be transferred outside India. Everything else continues to follow section 16, which permits transfer unless a country is notified as restricted.
The localisation claim, stated accurately

A great deal of published commentary says the Rules impose data localisation on Significant Data Fiduciaries. Read carefully, the obligation is narrower and conditional: it bites only on categories of personal data that the Central Government specifies, on the recommendation of a committee it constitutes. Until such a specification exists, there is nothing to localise under this head.

Everything outside any specified category continues under section 16, which permits transfer unless the Government notifies a country as restricted, and which expressly preserves stricter sectoral rules that already apply - the RBI's payment data requirements being the obvious example.

Sources, and one caveat

Section 10 is quoted from the Act as published in the Gazette. The obligations attributed to the Rules are consistent across published analyses, but those analyses do not agree on the rule number - some place them at Rule 12 and others at Rule 13. The substance is not in dispute; the citation is. Work from the Gazette text if you need to cite a rule.

FAQ

Significant Data Fiduciaries, answered

How do I know if my company is a Significant Data Fiduciary?

You are one when the Central Government notifies you, or a class you belong to, as one. There is no threshold you cross automatically - no user count, no revenue line, no volume of records. Section 10(1) lists the factors the Government weighs, not a test you can apply to yourself.

Does the DPDP Act require Significant Data Fiduciaries to keep all data in India?

No, and this is the most commonly misstated part of the framework. The obligation is targeted: only categories of personal data specified by the Central Government are restricted from leaving India. All other personal data continues under section 16, which permits transfer by default.

Can our existing internal audit team do the data audit?

Section 10(2)(b) requires an independent data auditor. Whether an internal function is sufficiently independent is a judgement call that depends on reporting lines and on how the Board reads the requirement, and it is worth taking advice on rather than assuming.

Is the DPO the same as a GDPR DPO?

The duties rhyme but the trigger and the seniority differ. GDPR Article 37 keys off public authority status or large-scale monitoring or special-category processing, and applies to controllers generally. The DPDP DPO exists only for a Significant Data Fiduciary, must be in India, and must answer to the board of directors.

When do these obligations start?

Section 10 sits in the eighteen-month tranche of the commencement notification, which lands in mid-May 2027. Designation itself requires a Government notification, so no organisation is a Significant Data Fiduciary until one is issued.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →