You do not grow into Significant Data Fiduciary status, and you do not self-declare it. The Central Government notifies a Data Fiduciary — or a class of them — under Section 10. Only then do the extra DPO, DPIA and audit duties switch on.
TL;DR
- Significant Data Fiduciary (SDF) status is conferred by the Central Government under Section 10 of the Digital Personal Data Protection Act, 2023, by notifying a Data Fiduciary or an entire class. It is not self-assessed and not triggered by headcount, AUM, bed count or “we’re health-tech now”.
- Section 10(2) extras — India-based DPO, independent data auditor — plus Rule 13 extras — twelve-month DPIA and audit with a Board report, algorithmic due diligence, specified-data transfer restriction — apply only after that notification. They are not duties of every Data Fiduciary, whatever a vendor deck told you.
- Until you are notified you are an ordinary Data Fiduciary and still owe Sections 4–9 and 11–14 in full by 13 May 2027. Skipping baseline because “we’re not an SDF” is the other failure mode.
- Breach handling runs on four lanes, cumulative: CERT-In (commonly 6 hours from awareness), Rule 7(1) affected Data Principals without delay, Rule 7(2)(a) initial intimation to the Data Protection Board without delay, Rule 7(2)(b) detailed Board report within 72 hours.
- The Act commenced via G.S.R. 843(E) dated 13 November 2025, with the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) phasing substantive fiduciary duties to 13 May 2027.
- Penalty ceilings sit in the Schedule: ₹250 crore for failure to take reasonable security safeguards (Section 8(5)); failure to intimate a breach is assessed separately (₹200 crore, Section 8(6)); and failure to meet the additional SDF obligations under Section 10 carries its own head at ₹150 crore (Schedule, Item 4). The Board applies these on facts — it is not an automatic invoice.
What is a Significant Data Fiduciary DPDPA designation — and who decides?
Section 10(1) of the DPDP Act, 2023 gives the Central Government the power to notify any Data Fiduciary, or any class of Data Fiduciaries, as a Significant Data Fiduciary. The notification is the trigger. There is no self-certification route in the Act, no application form, and no clause that converts you into an SDF because you crossed an internal milestone.
The Act says the Government may have regard to factors including the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, security of the State, public order, and the risk to electoral democracy. Read those as inputs to a government decision — not as a scorecard you can run in a spreadsheet to prove your own status.
The first sign may not be the Gazette notice. Rule 23 read with Seventh Schedule item 3 lets the Central Government, acting through a designated MeitY officer, call for information from a Data Fiduciary for the purpose of assessing it for SDF notification. Treat an information request as the start of an assessment, not as a courtesy questionnaire.
Section 10(2) attaches the consequences: an SDF shall appoint a Data Protection Officer based in India who represents the SDF and reports to its Board of Directors or similar governing body, appoint an independent data auditor to evaluate compliance, and undertake such other measures as prescribed. Rule 13 of the DPDP Rules, 2025 is where those “other measures” live.
If you want the shorter reference version, we keep one on the main site: Significant Data Fiduciary explainer and the baseline Data Fiduciary role.
Does every growing SMB become a Significant Data Fiduciary?
No. Growth is not a statutory trigger, and there are no published numeric thresholds — no user count, no turnover figure, no “all NBFCs” or “all hospitals” rule. Anyone selling you a threshold has invented it.
What is fair to say is that entities processing large volumes of financial or health-related personal data — an NBFC, a hospital group, a diagnostics chain — sit closer to the line than a 15-person distributor, and should prepare for the possibility of notification rather than assume immunity. “Closer to the line” is not “you are one”.
One contrast worth nailing down, because it causes the most confusion in Indian compliance calls: Section 10 lists sensitivity of the personal data processed as a notification factor, and that is all it does. It does not revive the old SPDI “sensitive personal data” category, and the DPDPA does not split ordinary fiduciary duties into sensitive and non-sensitive tiers the way GDPR Article 9 or the 2011 SPDI Rules did. We unpacked that copy-paste failure in DPDPA vs GDPR. Health data and financial data are personal data. The duties are the same duties.
Separately: Consent Manager registration under Rule 4 (live from 13 November 2026) is a licensed activity for entities that want to operate as Consent Managers. It is not an SDF test and has no bearing on whether you get notified.
What extra does Rule 13 require once you are notified as an SDF?
Section 10(2) is what switches on once you are notified: a DPO based in India, an independent data auditor, periodic DPIA and audit, and such other measures as prescribed. Rule 13 is those other measures. Notification starts a clock; it does not grant a grace period.
Five things, and they only start after notification:
- A Data Protection Officer based in India, representing the SDF and reporting to the Board of Directors or similar governing body (Section 10(2)(a)).
- An independent data auditor to evaluate compliance with the Act (Section 10(2)(b)).
- A Data Protection Impact Assessment and audit once every twelve months, with the clock running from the date of notification — and a report of significant observations furnished to the Board under Rule 13(2).
- Due diligence to verify that algorithmic software used to process personal data does not pose a risk to the rights of Data Principals (Rule 13(3)).
- Compliance with any restriction on transferring specified personal data outside India that the Central Government notifies (Rule 13(4)). Cross-border inventory itself is not SDF-only: Rule 15 applies to every Data Fiduciary.
Table A — Ordinary Data Fiduciary vs SDF
| Duty | Ordinary DF | SDF (after notification) |
|---|---|---|
| Section 5 notice (itemised, plain language, English or Eighth Schedule language) | Required | Required |
| Section 6 consent or Section 7 closed-list legitimate use | Required | Required |
| Section 8(2) written contract with every processor | Required | Required |
| Section 8(5) reasonable security safeguards | Required | Required |
| Section 8(9) published contact, read with Rule 9 + 8(10) grievance redressal | Required | Required |
| Breach intimation — four cumulative lanes (Rule 7 + CERT-In Directions) | Required | Required |
| Section 10(2) India-based DPO reporting to the Board | Not required | Required |
| Section 10(2) independent data auditor | Not required | Required |
| Rule 13 DPIA and audit every 12 months from notification, with Rule 13(2) Board report | Not required | Required |
| Rule 13 algorithmic due diligence | Not required | Required |
The pattern is worth saying out loud: nothing in the SDF column replaces the baseline column. Notification adds; it does not substitute.
How is an India-based DPO different from the Section 8(9) contact every company already needs?
Every Data Fiduciary must publish the contact details of a person able to answer a Data Principal’s questions about processing — that is Section 8(9), read with Rule 9 — and must have a grievance redressal mechanism under Section 8(10). That contact is a published business contact. It can be a named ops or legal lead. It does not have to report to your Board, and calling that person your “DPO” before you are notified creates a paper trail suggesting an SDF obligation you have not been given.
The Section 10(2) DPO is a different job: based in India, representing the SDF, reporting to the Board of Directors or similar governing body. Different appointment, different reporting line, different accountability.
While we are here: Rule 14(3)‘s 90 days is a ceiling for grievance redressal, not the service level for every rights request. Treating 90 days as your standard turnaround for an access or correction request is a bad look in front of anyone reading your logs. Our DPO checklist sets out what each role actually does.
What does SDF-grade evidence actually look like (DPIA, audit, algorithmic diligence)?
A DPIA and an audit are both evidence exercises. Someone independent asks what personal data you hold, on what ground, under which notice version, who touched it, and what happened when something went wrong — and then asks you to show it rather than describe it.
Table B — Evidence architecture
| Rule 13 / Section 8 artefact | What an auditor or Board actually asks for | What “evidence” looks like in operations |
|---|---|---|
| Annual DPIA (Rule 13) | Categories of personal data, purposes, retention, identified risks and mitigations | A current inventory generated from the system of record, not a Word doc last edited in 2024 |
| Periodic audit (Rule 13) | Independent verification against the Act, sampled and tested | Evidentiary-grade audit trail: who accessed what, when, under which purpose |
| Algorithmic due diligence (Rule 13) | Which models or automated software touch personal data, and what risk they pose to Data Principals | Logged data flows into and out of each automated component, with inputs traceable to a purpose |
| Section 6 consent, burden under 6(10) | Proof that consent was free, specific, informed, unconditional, unambiguous, by clear affirmative action | Append-only, tamper-evident consent records permitting point-in-time reconstruction of notice version and purposes |
| Section 8(5) safeguards, read with Rule 6(1) | Encryption, obfuscation, masking or virtual tokens mapped to personal data; access control on computer resources | A sealed vault holding identifying data separately, with the consent layer operating on tokens |
| Rule 7 breach lanes | Timestamped record of when you knew and whom you told | One incident log feeding all four lanes, not four reconstructions after the fact |
| Section 8(7) erasure, subject to retention required by law in force | Proof of deletion, and proof of why anything retained was retained | Deletion events written to the same immutable trail as consent events |
That is the architecture argument in one paragraph: a sealed PII vault, cryptographically immutable consent records and an evidentiary-grade audit trail exist so that when a DPIA or an auditor asks what you process and on what basis, the answer is a query rather than an archaeology project — and that architecture is aligned to Rule 6(1) whether or not you are ever notified. It is not a claim that software is your statutory independent data auditor, and it does not perform your Rule 13 DPIA. Those remain people, appointed by you, after notification. (Platform overview; if you are comparing architectures rather than feature lists, there is an architecture comparison.)
What should a non-SDF still have in place before 13 May 2027?
Baseline, in full. Sections 4–9 and 11–14 do not wait for a notification that may never come.
| Area | Owner | Status ☐ |
|---|---|---|
| Confirm SDF status by watching the Gazette / MeitY notifications under Section 10 — do not self-score | Founder / CEO | ☐ |
| Named, published Section 8(9) contact, read with Rule 9 (not titled “DPO”) | Ops lead | ☐ |
| Processor contract pack under Section 8(2), signed with every vendor touching personal data | Legal / counsel | ☐ |
| Consent and notice artefacts under Sections 5 and 6, retrievable per Section 6(10) burden | Product / Eng | ☐ |
| Saturday four-lane breach drill: CERT-In, Rule 7(1), Rule 7(2)(a), Rule 7(2)(b) | Security lead | ☐ |
| Do not buy a Rule 13 audit package unless and until you are notified | Finance | ☐ |
The sequencing is in our 90-day DPDPA readiness roadmap, and the wider 2027 picture is in DPDPA compliance for Indian SMBs.
Closing
Three things to do this month:
- Write one line in your risk register: SDF status is conferred by Central Government notification under Section 10; we monitor the Gazette; we do not self-assess. That line ends most vendor conversations.
- Publish your Section 8(9) contact, read with Rule 9, and check it is a real inbox with a real owner. Do not title that person DPO.
- Run the four-lane breach drill once, on a Saturday, with a stopwatch. Six hours arrives faster than anyone expects.
If you are later notified, the extras are an India-based DPO, an independent data auditor, a twelve-month DPIA and audit with a Rule 13(2) Board report, and algorithmic due diligence. The architecture that makes those survivable — identifying data sealed and tokenised per Rule 6(1), consent records append-only and tamper-evident, an audit trail an outsider can inspect — is worth building now, because it is the same evidence a Board asks for whether or not a notification ever lands.
Book a 30-minute DPDPA discovery call
Frequently asked questions
Is my company a Significant Data Fiduciary under the DPDPA before the government notifies me?
No. Under Section 10 of the DPDP Act, 2023, SDF status is conferred when the Central Government notifies a Data Fiduciary or a class of Data Fiduciaries. Until that notification, you are an ordinary Data Fiduciary and owe Sections 4–9 and 11–14 in full.
Are Rule 13 audits mandatory for every Data Fiduciary?
No. Rule 13 of the DPDP Rules, 2025 — the twelve-month DPIA and audit, the Board report of significant observations, and algorithmic due diligence — applies only to entities notified as Significant Data Fiduciaries under Section 10. Ordinary Data Fiduciaries are not required to buy an annual statutory audit.
Does every company need a Data Protection Officer under DPDPA?
No. Every Data Fiduciary must publish a contact under Section 8(9), read with Rule 9, who can answer questions about processing, and run grievance redressal under Section 8(10). The India-based DPO reporting to the Board is a Section 10(2) duty that follows SDF notification.
Does holding financial or health data automatically make us an SDF?
No. Section 10 lists sensitivity of the personal data processed as one factor the Central Government may consider, alongside volume, risk to Data Principals and impact on the sovereignty and integrity of India. It is not an automatic trigger, and the DPDPA does not retain the old sensitive personal data category.
What is the penalty if a Significant Data Fiduciary fails its Section 10 obligations?
Up to ₹150 crore under Item 4 of the Schedule to the DPDP Act, 2023 — a separate head from the ₹250 crore Section 8(5) security ceiling and the ₹200 crore Section 8(6) breach-intimation ceiling. The Board sets quantum on the facts.
Which companies have been notified as Significant Data Fiduciaries in India?
As at 24 August 2026, no Data Fiduciary or class of Data Fiduciaries has been notified as a Significant Data Fiduciary under Section 10. Any list circulating that names specific SDFs is speculation. Monitor the Gazette and MeitY notifications rather than vendor claims.
Sources
- Digital Personal Data Protection Act, 2023, MeitY — Section 10 and Section 10(2): https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- DPDP Act commencement, G.S.R. 843(E), 13 November 2025, MeitY: https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY — Rules 9, 13, 15 and 23, and Seventh Schedule item 3: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
- PIB — Digital Personal Data Protection Act background: https://pib.gov.in/PressReleseDetail.aspx?PRID=1947264
- CERT-In Directions under Section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022 — https://www.cert-in.org.in/Directions70B.jsp — cited for the 6-hour cyber-incident reporting clock.
Privigo is not a law firm. Nothing here is a determination of whether any named entity is, or will be, a Significant Data Fiduciary. This is general information, not legal advice — consult qualified Indian counsel on your specific facts.


