Significant Data Fiduciary (SDF) Explained: Criteria, Obligations and Penalties Under DPDP
Who gets notified, what changes, and how to prepare under Section 10 of the DPDP Act and Rule 13 of the DPDP Rules 2025.
What is a Significant Data Fiduciary?
Why SDF status matters
SDF designation is the DPDP Act's mechanism for scaling obligations by risk. A standard Data Fiduciary needs consent, notice, security and rights handling. An SDF needs all of that plus a governance layer that resembles a regulated-entity regime: a board-reporting DPO, an annual independent audit, DPIAs and possibly restrictions on where data can be stored. Non-compliance with SDF-specific obligations carries a penalty of up to INR 150 crore per instance, on top of the general penalties.
As at August 2026, the Central Government has not published the final list or criteria. MeitY has signalled that financial services, healthcare, telecom, e-commerce, social media, search engines and AI-driven platforms are likely candidates. Businesses in these sectors should prepare on the assumption that they will be notified.
Significant Data Fiduciary: Key Terms
There is no GDPR counterpart to this tier — DPDP vs GDPR: key differences sets out where the two regimes scale obligations differently.
- Significant Data Fiduciary
- Section 2(z): any Data Fiduciary or class of Data Fiduciaries notified by the Central Government under Section 10.
- Data Protection Officer (DPO)
- An individual based in India, appointed by an SDF, who represents the SDF under the Act, reports to the board of directors or similar governing body, and is the point of contact for grievance redressal.
- Independent data auditor
- A person appointed by an SDF to evaluate its compliance with the Act; must be independent of management.
- Data Protection Impact Assessment (DPIA)
- A process comprising a description of the rights of Data Principals and the purpose of processing, an assessment and management of risk to those rights, and any other prescribed matters.
- Algorithmic due diligence
- Rule 13 duty to verify that technical measures, including algorithmic software, used for processing are not likely to pose a risk to the rights of Data Principals.
- Data localisation (SDF-specific)
- The Central Government may specify personal data, and traffic data pertaining to its flow, that an SDF must not transfer outside India.
How the Government Decides Who Is a Significant Data Fiduciary
Section 10(1) lists the factors the Central Government must consider. No thresholds are fixed in the Act; notification is by discretion, either naming entities or classes.
| Factor | What it means in practice |
|---|---|
| Volume and sensitivity of personal data | Large customer or user bases; financial, health, biometric, location or children's data. |
| Risk to the rights of Data Principals | Profiling, credit decisions, insurance underwriting, health outcomes, employment screening. |
| Potential impact on sovereignty and integrity of India | Critical infrastructure, telecom, mapping, defence supply chain. |
| Risk to electoral democracy | Political advertising, large social and messaging platforms. |
| Security of the State | Data of government personnel, critical sector employees, national security relevance. |
| Public order | Platforms with mass reach and virality. |
| Any other factor the Government considers necessary | Open-ended; allows sector-wise notification (for example, all scheduled banks or all licensed insurers). |
Significant Data Fiduciary Obligations Under Section 10 and Rule 13
| Obligation | Requirement | Practical implication |
|---|---|---|
| Appoint a DPO | Individual based in India, representing the SDF, reporting to the board or governing body, and serving as grievance contact. | A senior hire or designation with board access; cannot be an overseas group DPO. |
| Appoint an independent data auditor | To evaluate compliance with the Act. | Select a firm free from management conflicts; scope, frequency and reporting line to the board. |
| Annual DPIA | Assess and manage risk to Data Principal rights for processing activities. | Build a DPIA register and methodology; integrate with change management. |
| Annual audit | Independent audit of compliance with the Act and Rules; significant observations reported to the Board. | Audit readiness: policies, consent records, logs, breach register, vendor contracts. |
| Algorithmic due diligence | Verify that algorithmic software does not pose a risk to Data Principal rights. | Model inventory, bias and impact testing, documentation for credit scoring, recommendation and fraud engines. |
| Data-transfer restrictions | Do not transfer specified personal data or traffic data outside India if the Central Government so directs. | Map cross-border flows now; prepare for localisation of specified categories. |
| Other measures | Any additional measure prescribed by the Government. | Monitor MeitY notifications. |
Significant Data Fiduciary vs Data Fiduciary: What Changes
| Requirement | Data Fiduciary | Significant Data Fiduciary |
|---|---|---|
| Consent and notice | Yes | Yes |
| Reasonable security safeguards | Yes | Yes, with audit evidence |
| Breach notification to Board and individuals | Yes | Yes |
| Grievance officer contact | Yes | Yes, through the DPO |
| Data Protection Officer in India | Not required | Mandatory, board-reporting |
| Independent data auditor | Not required | Mandatory |
| DPIA | Good practice | Mandatory, annual |
| Compliance audit | Good practice | Mandatory, annual, reported to Board |
| Algorithmic due diligence | Not required | Mandatory |
| Data localisation | General transfer rules only | Additional restrictions possible |
| Specific penalty for these duties | Not applicable | Up to INR 150 crore per instance |
Are You a Significant Data Fiduciary? Self-Assessment
Score one point for each "yes". Four or more points indicates you should prepare as if you will be notified.
- Do you process personal data of more than 50 lakh individuals?
- Do you process financial, health, biometric, precise location or children’s data at scale?
- Are you regulated by RBI, SEBI, IRDAI, PFRDA, TRAI or a health regulator?
- Do you make or materially influence automated decisions about individuals (credit, pricing, insurance, hiring)?
- Do you operate a platform with mass reach (social media, messaging, marketplace, search, gaming)?
- Do you transfer Indian personal data to group entities or vendors outside India?
- Would a breach at your organisation plausibly attract national media or government attention?
The SDF classifier runs the same seven factors in your browser and returns a scored result.
SDF Compliance Roadmap to May 2027
| Horizon | Actions |
|---|---|
| Now to November 2026 | Confirm likely SDF status; nominate an India-based DPO with board reporting; inventory processing activities and algorithms; map cross-border flows; select an independent auditor. |
| November 2026 to May 2027 | Complete first DPIA cycle; remediate high risks; run a readiness audit; finalise localisation options for specified data; document algorithmic due diligence. |
| From 13 May 2027 | Full compliance in force. Annual DPIA and audit cadence; audit findings reported to the Data Protection Board; continuous monitoring of Government notifications. |
Consent architecture is on the same clock, and may need to interoperate with a Consent Manager from 13 November 2026.
Frequently Asked Questions: Significant Data Fiduciary
Key takeaways
- SDF status is assigned by the Central Government, not self-declared, and the criteria are risk-based rather than numeric.
- SDFs must appoint an India-based board-reporting DPO and an independent auditor, and run annual DPIAs and audits.
- Algorithmic due diligence and potential data localisation are the two obligations with no GDPR parallel.
- Regulated financial, health, telecom and large digital platforms should prepare for notification ahead of 13 May 2027.