Skip to main content
Significant Data Fiduciary Explained: DPDP Act Guide — page loaded
Explainer

Significant Data Fiduciary (SDF) Explained: Criteria, Obligations and Penalties Under DPDP

Who gets notified, what changes, and how to prepare under Section 10 of the DPDP Act and Rule 13 of the DPDP Rules 2025.

Section 01

What is a Significant Data Fiduciary?

Quick answer
A Significant Data Fiduciary (SDF) is a Data Fiduciary, or class of Data Fiduciaries, notified by India's Central Government under Section 10 of the DPDP Act 2023 based on the volume and sensitivity of personal data processed, risk to Data Principals, and impact on sovereignty, security, electoral democracy or public order. SDFs must appoint an India-based Data Protection Officer, an independent data auditor, conduct annual DPIAs and audits, and comply with algorithmic due diligence and any data-localisation restrictions.

Why SDF status matters

SDF designation is the DPDP Act's mechanism for scaling obligations by risk. A standard Data Fiduciary needs consent, notice, security and rights handling. An SDF needs all of that plus a governance layer that resembles a regulated-entity regime: a board-reporting DPO, an annual independent audit, DPIAs and possibly restrictions on where data can be stored. Non-compliance with SDF-specific obligations carries a penalty of up to INR 150 crore per instance, on top of the general penalties.

As at August 2026, the Central Government has not published the final list or criteria. MeitY has signalled that financial services, healthcare, telecom, e-commerce, social media, search engines and AI-driven platforms are likely candidates. Businesses in these sectors should prepare on the assumption that they will be notified.

Section 02

Significant Data Fiduciary: Key Terms

There is no GDPR counterpart to this tier — DPDP vs GDPR: key differences sets out where the two regimes scale obligations differently.

Significant Data Fiduciary
Section 2(z): any Data Fiduciary or class of Data Fiduciaries notified by the Central Government under Section 10.
Data Protection Officer (DPO)
An individual based in India, appointed by an SDF, who represents the SDF under the Act, reports to the board of directors or similar governing body, and is the point of contact for grievance redressal.
Independent data auditor
A person appointed by an SDF to evaluate its compliance with the Act; must be independent of management.
Data Protection Impact Assessment (DPIA)
A process comprising a description of the rights of Data Principals and the purpose of processing, an assessment and management of risk to those rights, and any other prescribed matters.
Algorithmic due diligence
Rule 13 duty to verify that technical measures, including algorithmic software, used for processing are not likely to pose a risk to the rights of Data Principals.
Data localisation (SDF-specific)
The Central Government may specify personal data, and traffic data pertaining to its flow, that an SDF must not transfer outside India.
Section 03

How the Government Decides Who Is a Significant Data Fiduciary

Section 10(1) lists the factors the Central Government must consider. No thresholds are fixed in the Act; notification is by discretion, either naming entities or classes.

Section 10(1) factors for Significant Data Fiduciary designation
FactorWhat it means in practice
Volume and sensitivity of personal dataLarge customer or user bases; financial, health, biometric, location or children's data.
Risk to the rights of Data PrincipalsProfiling, credit decisions, insurance underwriting, health outcomes, employment screening.
Potential impact on sovereignty and integrity of IndiaCritical infrastructure, telecom, mapping, defence supply chain.
Risk to electoral democracyPolitical advertising, large social and messaging platforms.
Security of the StateData of government personnel, critical sector employees, national security relevance.
Public orderPlatforms with mass reach and virality.
Any other factor the Government considers necessaryOpen-ended; allows sector-wise notification (for example, all scheduled banks or all licensed insurers).
Section 04

Significant Data Fiduciary Obligations Under Section 10 and Rule 13

SDF obligations under Section 10 of the DPDP Act and Rule 13 of the DPDP Rules 2025
ObligationRequirementPractical implication
Appoint a DPOIndividual based in India, representing the SDF, reporting to the board or governing body, and serving as grievance contact.A senior hire or designation with board access; cannot be an overseas group DPO.
Appoint an independent data auditorTo evaluate compliance with the Act.Select a firm free from management conflicts; scope, frequency and reporting line to the board.
Annual DPIAAssess and manage risk to Data Principal rights for processing activities.Build a DPIA register and methodology; integrate with change management.
Annual auditIndependent audit of compliance with the Act and Rules; significant observations reported to the Board.Audit readiness: policies, consent records, logs, breach register, vendor contracts.
Algorithmic due diligenceVerify that algorithmic software does not pose a risk to Data Principal rights.Model inventory, bias and impact testing, documentation for credit scoring, recommendation and fraud engines.
Data-transfer restrictionsDo not transfer specified personal data or traffic data outside India if the Central Government so directs.Map cross-border flows now; prepare for localisation of specified categories.
Other measuresAny additional measure prescribed by the Government.Monitor MeitY notifications.
Section 05

Significant Data Fiduciary vs Data Fiduciary: What Changes

What SDF designation adds to a standard Data Fiduciary's obligations
RequirementData FiduciarySignificant Data Fiduciary
Consent and noticeYesYes
Reasonable security safeguardsYesYes, with audit evidence
Breach notification to Board and individualsYesYes
Grievance officer contactYesYes, through the DPO
Data Protection Officer in IndiaNot requiredMandatory, board-reporting
Independent data auditorNot requiredMandatory
DPIAGood practiceMandatory, annual
Compliance auditGood practiceMandatory, annual, reported to Board
Algorithmic due diligenceNot requiredMandatory
Data localisationGeneral transfer rules onlyAdditional restrictions possible
Specific penalty for these dutiesNot applicableUp to INR 150 crore per instance
Section 06

Are You a Significant Data Fiduciary? Self-Assessment

Score one point for each "yes". Four or more points indicates you should prepare as if you will be notified.

  • Do you process personal data of more than 50 lakh individuals?
  • Do you process financial, health, biometric, precise location or children’s data at scale?
  • Are you regulated by RBI, SEBI, IRDAI, PFRDA, TRAI or a health regulator?
  • Do you make or materially influence automated decisions about individuals (credit, pricing, insurance, hiring)?
  • Do you operate a platform with mass reach (social media, messaging, marketplace, search, gaming)?
  • Do you transfer Indian personal data to group entities or vendors outside India?
  • Would a breach at your organisation plausibly attract national media or government attention?

The SDF classifier runs the same seven factors in your browser and returns a scored result.

Section 07

SDF Compliance Roadmap to May 2027

Significant Data Fiduciary readiness actions by horizon
HorizonActions
Now to November 2026Confirm likely SDF status; nominate an India-based DPO with board reporting; inventory processing activities and algorithms; map cross-border flows; select an independent auditor.
November 2026 to May 2027Complete first DPIA cycle; remediate high risks; run a readiness audit; finalise localisation options for specified data; document algorithmic due diligence.
From 13 May 2027Full compliance in force. Annual DPIA and audit cadence; audit findings reported to the Data Protection Board; continuous monitoring of Government notifications.

Consent architecture is on the same clock, and may need to interoperate with a Consent Manager from 13 November 2026.

Frequently Asked Questions: Significant Data Fiduciary

The Central Government, by notification under Section 10, considering the factors listed in the Act. The Data Protection Board does not designate SDFs.

Not as at August 2026. MeitY has indicated it intends to notify classes or criteria; check the latest Gazette notifications.

No. The Act requires the DPO to be an individual based in India.

Up to INR 150 crore per instance under the Schedule to the Act, in addition to other applicable penalties such as INR 250 crore for security-safeguard failures.

They combine GDPR-style DPO and DPIA duties with elements that GDPR does not have: mandatory annual external audit, algorithmic due diligence and Government-directed localisation.

No. Only Data Fiduciaries can be notified. A Processor serving an SDF will, however, face flowed-down contractual requirements.

Key takeaways

  • SDF status is assigned by the Central Government, not self-declared, and the criteria are risk-based rather than numeric.
  • SDFs must appoint an India-based board-reporting DPO and an independent auditor, and run annual DPIAs and audits.
  • Algorithmic due diligence and potential data localisation are the two obligations with no GDPR parallel.
  • Regulated financial, health, telecom and large digital platforms should prepare for notification ahead of 13 May 2027.