What is a Significant Data Fiduciary?

A Significant Data Fiduciary (SDF) is a Data Fiduciary that the Central Government has specifically designated under Section 10 of the Digital Personal Data Protection Act 2023. The designation places a second, more demanding compliance layer on top of the standard obligations every Data Fiduciary already carries.

Section 10(1) of the DPDP Act states that the Central Government may, by notification, designate any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciaries, having regard to:

  • The volume and sensitivity of personal data processed
  • The risk to the rights of Data Principals
  • Potential impact on the sovereignty and integrity of India or national security
  • Risk to electoral democracy or maintenance of public order
  • Risk to the rights of children
The plain test

If a breach of your data, or misuse of your platform, could affect hundreds of thousands of people — or pose a systemic risk to society — you are in SDF territory. The government has broad discretion under Section 10; the five factors above are a guide, not an exhaustive checklist.

Data Fiduciary vs Significant Data Fiduciary

Every SDF is a Data Fiduciary, but not every Data Fiduciary is an SDF. The difference between a Data Fiduciary and a Significant Data Fiduciary is designation: SDFs are specifically identified by the government and notified. All other Data Fiduciaries — including small businesses and startups — carry the standard obligations but not the additional SDF layer.

DimensionData FiduciarySignificant Data Fiduciary
Who they areAny org that determines purpose & means of processing personal dataA Data Fiduciary specifically designated by the Central Govt under Section 10
Consent & noticeRequiredRequired
Data Principal rightsMust honourMust honour
Security safeguardsRequiredRequired
Breach notificationRequiredRequired
Data Protection OfficerNot requiredMandatory — must be India-based
Data Protection Impact AssessmentNot requiredMandatory — periodic
Independent auditNot requiredMandatory — by accredited auditor
Additional Govt standardsNot applicableMust comply with any SDF-specific rules

The 5 criteria the government uses to designate SDFs

The Central Government has discretion under Section 10, but its decision will be informed by five concrete factors. Understanding these helps organisations assess their own risk of designation:

1. Volume of personal data processed

Organisations that process personal data of a very large number of users are natural SDF candidates. Think platforms with tens of millions of active Indian users: major social media apps, large e-commerce marketplaces, ride-hailing platforms, and UPI payment apps. The Act does not specify a numeric threshold — the government will make designation decisions based on overall risk, not just raw numbers.

2. Sensitivity of personal data

Processing sensitive personal data — health records, biometric data, financial data, precise geolocation, data about children — raises the SDF risk significantly. A health platform processing 5 million patient records carries a fundamentally different risk profile than a B2B SaaS product processing employee names and work emails.

3. Risk to Data Principals

The government will assess what harm could result if personal data processed by your organisation was breached, misused, or manipulated. If the answer is "significant financial loss," "physical harm," or "discrimination affecting large numbers of people," SDF designation becomes more likely.

4. National security and sovereignty

Organisations that handle data about critical infrastructure, government employees, defence contractors, or that hold data that foreign governments might seek access to are priority candidates. Telecom operators and cloud providers serving government departments are explicitly in scope here.

5. Risk to electoral democracy and children

Social media platforms, news aggregators, and OTT platforms that could influence public opinion or political participation are explicitly contemplated by Section 10. Similarly, platforms with large numbers of child users are elevated risk for SDF designation.

Who is likely to be designated first

The government has not yet published the official SDF notification list. Based on the Section 10 criteria, these categories are the most likely first designees:

Social Media
Platforms with 100M+ Indian users — Meta, Google, Snapchat, ShareChat
Volume + democracy risk + children's data → high SDF probability
Fintech / Payments
UPI apps, lending platforms, insurance aggregators processing financial data at scale
Sensitivity (financial data) + volume → very high probability
E-commerce
Large marketplaces — Flipkart, Amazon India, Meesho — with millions of customers
Volume + financial data + geolocation → moderate-high probability
Healthcare
Hospital chains, health super-apps, diagnostic chains processing patient records
Sensitivity (health data) → high probability regardless of scale
Telecom
Jio, Airtel, Vi — processing call records, location, identity for entire subscriber bases
Volume + sensitivity + national security → near-certain SDF designation
EdTech
Platforms with large numbers of child users — BYJU'S, PhysicsWallah, Unacademy
Children's data → elevated SDF risk even at moderate scale

Mid-size B2B SaaS companies, HR platforms, and internal enterprise tools are significantly less likely to be designated SDFs — unless they process data categories that trigger the sensitivity or national security factors.

The 4 additional obligations of a Significant Data Fiduciary

Section 10(2) of the DPDP Act specifies exactly what additional obligations SDFs must fulfil. Every Data Fiduciary's standard obligations — consent, notice, rights, security, breach notification — continue to apply. SDFs must additionally comply with all four of the following:

  • 01
    Appoint a Data Protection Officer (DPO)

    The DPO must be an individual based in India and must be a key managerial personnel or hold an equivalent position within the organisation. The DPO is responsible for ensuring the SDF's compliance with the DPDP Act, acts as the primary point of contact for Data Principals exercising their rights, and is the contact point for the Data Protection Board of India. Critically, the DPO's appointment, functions, and removal must be reported to the Board. The DPO must have sufficient authority, resources, and independence to perform this function — a compliance title with no real power does not satisfy this obligation.

  • 02
    Appoint an independent data auditor

    SDFs must engage an independent data auditor — accredited for this purpose — to evaluate compliance with the DPDP Act's provisions. The audit must assess the SDF's processing activities, consent mechanisms, Data Principal rights infrastructure, security safeguards, and breach notification processes. The auditor must be genuinely independent; an internal audit team or a firm with a significant commercial relationship with the SDF will not satisfy this requirement. Audit findings must be addressed, and the process is expected to be periodic — at least annually.

  • 03
    Conduct periodic Data Protection Impact Assessments (DPIAs)

    A DPIA is a structured process for identifying and assessing the privacy risks of a data processing activity before and during the activity. SDFs must conduct DPIAs for all current and new processing activities — not just for high-risk projects. The DPIA must document: what personal data is processed, for what purpose, what risks are posed to Data Principals, and what measures are in place to mitigate those risks. DPIAs are both a compliance requirement and a governance tool: they create a documented basis for processing decisions and demonstrate that privacy was considered systematically.

  • 04
    Comply with additional SDF-specific standards

    Section 10(2)(d) gives the Central Government authority to specify additional standards and conditions for SDFs beyond the base Act. These are expected to include: algorithmic transparency requirements for platforms making automated decisions affecting individuals; additional obligations around cross-border data transfers; stricter data retention limits; and additional consent requirements for profiling or behavioural advertising. These additional standards have not yet been notified but are expected as part of subordinate legislation in 2026–27.

How to prepare before designation arrives

The government is expected to notify the first batch of SDFs in 2026. If your organisation meets any of the Section 10 criteria — large user base, sensitive data categories, children's data — do not wait for the formal notification to begin preparing. Designation may come with a grace period, but DPO appointment, DPIA processes, and audit readiness each require months of preparation.

Steps to take now if you may be designated

  • Assess your SDF risk: Use the five Section 10 criteria as a self-assessment framework. If three or more factors apply to your organisation, treat SDF designation as a near-certainty and plan accordingly.
  • Identify your DPO candidate: DPO appointment is the most visible SDF obligation. The DPO must be India-based and senior enough to have real authority. Identify the role, draft the job description, and begin the recruitment or internal appointment process.
  • Start your DPIA programme: Build a DPIA template and process for all new data processing initiatives. Run retrospective DPIAs on your highest-risk existing activities — this both prepares you for compliance and surfaces risks you may not have documented.
  • Begin auditor selection: Independent data auditors for DPDP are still an emerging category in India. Begin identifying and evaluating candidates early — the best auditors will have full calendars once the SDF notification is published.
  • Document everything: The combination of DPO, DPIA, and independent audit creates a documentation requirement that is very different from standard DPDP compliance. Your data inventory, processing records, consent logs, and security assessments must all be audit-ready.
  • Brief your board: The DPO reports to the Board of Directors. This means your Board needs to understand what DPDP compliance means for the organisation and what SDF designation implies. A board briefing now avoids a crisis briefing after notification arrives.

Designation as a Significant Data Fiduciary is not a sanction — it is a recognition that your organisation processes data at a scale and sensitivity that warrants additional accountability. The best response is to treat it as a governance upgrade, not a compliance burden.

Significant Data Fiduciary vs GDPR — the closest comparison

For organisations already familiar with GDPR, the SDF concept is most analogous to GDPR's mandatory DPO requirement — which applies when processing is carried out at large scale, involves special categories of data, or involves systematic monitoring of individuals. The DPDP Act's SDF framework is arguably more structured: rather than self-assessment, the Central Government makes the designation call, which removes ambiguity for organisations wondering whether they trigger the threshold.

The DPIA obligation also has a direct GDPR parallel in Article 35, which requires DPIAs for high-risk processing. The DPDP Act's SDF version is broader — it applies to all processing by designated SDFs, not just high-risk activities. The independent audit requirement has no direct GDPR equivalent for most organisations, though it resembles obligations that apply to some regulated sectors under GDPR national implementations.

DPDP compliance guide

For the full picture of DPDP Act obligations — including all six standard Data Fiduciary obligations, the penalty structure, and the compliance timeline — see our DPDP Act compliance guide and our free DPDP compliance checklist.