You Do Not Become One. You Are Notified As One.
Significant Data Fiduciary is the only tier the DPDP Act creates, and it is not a threshold an organisation crosses by growing. The Central Government designates you, weighing factors that include risk to electoral democracy and the sovereignty of India alongside the volume of data you hold.
Six factors, and only one is about size
The list is expressly non-exhaustive: the Government assesses “such relevant factors as it may determine, including” these six. Note how much of it is about the State rather than about the individual.
Three obligations on top of everything else
Designation does not replace the ordinary duties in sections 4 to 9. It adds to them.
Read it verbatim: section 10 in full.
What the Rules turn “periodic” into
A great deal of published commentary says the Rules impose data localisation on Significant Data Fiduciaries. Read carefully, the obligation is narrower and conditional: it bites only on categories of personal data that the Central Government specifies, on the recommendation of a committee it constitutes. Until such a specification exists, there is nothing to localise under this head.
Everything outside any specified category continues under section 16, which permits transfer unless the Government notifies a country as restricted, and which expressly preserves stricter sectoral rules that already apply - the RBI's payment data requirements being the obvious example.
Section 10 is quoted from the Act as published in the Gazette. The obligations attributed to the Rules are consistent across published analyses, but those analyses do not agree on the rule number - some place them at Rule 12 and others at Rule 13. The substance is not in dispute; the citation is. Work from the Gazette text if you need to cite a rule.
Significant Data Fiduciaries, answered
How do I know if my company is a Significant Data Fiduciary?
You are one when the Central Government notifies you, or a class you belong to, as one. There is no threshold you cross automatically - no user count, no revenue line, no volume of records. Section 10(1) lists the factors the Government weighs, not a test you can apply to yourself.
Does the DPDP Act require Significant Data Fiduciaries to keep all data in India?
No, and this is the most commonly misstated part of the framework. The obligation is targeted: only categories of personal data specified by the Central Government are restricted from leaving India. All other personal data continues under section 16, which permits transfer by default.
Can our existing internal audit team do the data audit?
Section 10(2)(b) requires an independent data auditor. Whether an internal function is sufficiently independent is a judgement call that depends on reporting lines and on how the Board reads the requirement, and it is worth taking advice on rather than assuming.
Is the DPO the same as a GDPR DPO?
The duties rhyme but the trigger and the seniority differ. GDPR Article 37 keys off public authority status or large-scale monitoring or special-category processing, and applies to controllers generally. The DPDP DPO exists only for a Significant Data Fiduciary, must be in India, and must answer to the board of directors.
When do these obligations start?
Section 10 sits in the eighteen-month tranche of the commencement notification, which lands in mid-May 2027. Designation itself requires a Government notification, so no organisation is a Significant Data Fiduciary until one is issued.