Pricoris

What Is a Significant Data Fiduciary Under the DPDP Act? Criteria, Duties and Readiness

A significant data fiduciary is a data fiduciary, or a class of data fiduciaries, that the Central Government has notified as significant under Section 10(1) of the DPDP Act. The status cannot be self-assessed and is not triggered by size alone: until a notification names your organisation or your class, you are an ordinary data fiduciary, however much data you hold. Once notified, the duties change sharply: an India based Data Protection Officer, an independent data auditor, and a Data Protection Impact Assessment and audit every twelve months, with the further requirements of Rule 13 of the DPDP Rules, 2025.

The category exists because the Act is graduated. Every data fiduciary carries the core duties of notice, consent, security, breach reporting and erasure. A small number whose processing carries wider consequences carry more. Which organisations those are is a decision the Act leaves to the Government, and no list had been made public when this article was last reviewed.

The six factors in Section 10(1)

The Government may notify a data fiduciary or a class of data fiduciaries as significant after assessing factors that include:

  1. the volume and sensitivity of the personal data processed;
  2. the risk to the rights of data principals;
  3. the potential impact on the sovereignty and integrity of India;
  4. the risk to electoral democracy;
  5. the security of the State;
  6. public order.

The Act sets no numerical thresholds, and the Rules add none. The factors are weighed together, and a notification can name a single organisation or an entire class, such as a category of platform or a sector.

What changes once you are notified

ObligationSourceWhat it means in practice
Appoint a Data Protection OfficerSection 10(2)(a)An individual based in India, responsible to the board or equivalent governing body, and the point of contact for grievances
Appoint an independent data auditorSection 10(2)(b)An auditor independent of the team that runs the programme, to evaluate compliance with the Act
Carry out a Data Protection Impact Assessment and an audit every twelve monthsSection 10(2)(c) and Rule 13A recurring annual cycle counted from the date of notification, with significant observations reported to the Data Protection Board
Verify algorithmic softwareRule 13Due diligence that technical measures, including algorithms used to process personal data, are not likely to pose a risk to data principals’ rights
Keep specified data in IndiaRule 13Personal data the Government specifies on a committee’s recommendation, with related traffic data, must not be transferred outside India

Failure to meet these additional obligations carries a penalty of up to INR 150 crore.

Where things stand

No list of significant data fiduciaries had been published when this article was last reviewed. The Section 10 duties and Rule 13 are due to take effect with the rest of the Act’s substantive obligations on 13 May 2027, eighteen months after the DPDP Rules were notified. In a January 2026 consultation, MeitY proposed bringing the significant data fiduciary provisions forward and notifying designations sooner. That proposal had not been notified at the time of writing, so check the current position before relying on either date.

Commentators most often expect large social media and consumer platforms, banks and payment companies, health services and telecom operators to feature in early notifications. That is informed expectation, not law.

How to prepare without over-preparing

If you are a startup or a mid-sized business, the right preparation is none. The duties attach only on notification, and the money is better spent on the security and breach readiness that carry the largest penalties for every data fiduciary.

If you are a large platform, bank, insurer, hospital group or telecom operator, a proportionate readiness plan is sensible, because the first annual cycle runs from the date of notification:

  • identify who could serve as Data Protection Officer, and how the role will report to the board;
  • list the algorithms and automated systems that act on personal data, since Rule 13 asks for due diligence on them;
  • decide how you would select an independent data auditor, and agree a method for your impact assessments;
  • map which personal data leaves India today, in case a localisation requirement reaches it.

None of this needs a full audit before notification. It shortens the distance between a notification and a compliant first cycle. For support with the Data Protection Officer function, see our DPO as a Service page. Our DPDP consulting page covers the wider programme.

Frequently asked questions

Can we decide for ourselves that we are a significant data fiduciary?

No. The status arises only when the Central Government notifies an organisation, or a class it belongs to, under Section 10(1). Until then, the additional duties do not apply.

Has the Government notified any significant data fiduciaries?

Not when this article was last reviewed. Check MeitY’s notifications for the current position.

What is the penalty for breaching significant data fiduciary obligations?

Up to INR 150 crore under the Schedule to the Act.

Must the Data Protection Officer be an employee?

The Act requires an individual, based in India, who is responsible to the board of directors or similar governing body. It does not expressly require employment, but that accountability points to a senior, dedicated individual. Take advice on the structure that suits you.

Does significant data fiduciary status restrict cross-border transfers?

It can. Rule 13 allows the Government to require that specified personal data and related traffic data stay in India. No such data had been specified at the time of writing.

Should a startup prepare for significant data fiduciary obligations?

No. A startup is very unlikely to be notified, and the duties apply only on notification. Its money is better spent on security safeguards and breach readiness.


Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that provides DPDP consulting. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top