Confidential Dispatch

Are you a Significant Data Fiduciary? How to tell if your company qualifies

4 min readUpdated 2026-07-04
On this page
  1. 01What makes a fiduciary “significant”?
  2. 02You don’t opt in — the government notifies you
  3. 03The extra obligations if you’re named
  4. 04Could your company realistically qualify?
  5. 05FAQ
At a glance

You become a Significant Data Fiduciary (SDF) only when the central government notifies you — or your class of business — as one. You don’t self-declare into it. The government weighs factors like the volume and sensitivity of the data you handle and the risks it poses. If you’re notified, heavier duties follow: an India-based Data Protection Officer, independent audits, and impact assessments. Most small and mid-sized businesses won’t cross the line — but if your scale and data are large, it’s worth knowing where the bar sits.

Educational resource only. This explains the Significant Data Fiduciary category under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.

The starting point

Every Significant Data Fiduciary is first an ordinary Data Fiduciary — “significant” is a higher tier layered on top, reserved for the businesses whose data footprint carries outsized risk. So this only matters once you’ve established you’re a Fiduciary at all; the question here is whether you’re in the heavier bracket.

What makes a fiduciary “significant”?

It’s about risk and scale — the government looks at how much and how sensitive your data is, and what could go wrong. The Act lets the central government designate a Fiduciary, or a whole class of them, as an SDF (Section 10) by weighing factors such as:

  • the volume and sensitivity of personal data processed;
  • the risk to the rights of individuals;
  • potential impact on the sovereignty and integrity of India;
  • risk to electoral democracy;
  • security of the State; and
  • public order.

The common thread is consequence: the more people, the more sensitive the data, and the greater the potential harm, the more likely a business sits in this bracket.

You don’t opt in — the government notifies you

There’s no self-registration and no self-assessment that makes you an SDF; designation comes from the government. Unlike being a Fiduciary (which simply follows from what you do), the SDF label attaches only when the government notifies you or your class. So you can’t accidentally “become” one by growing, and you can’t volunteer in. What you can do is watch whether your sector or scale is the kind the government is likely to notify, and be ready.

The extra obligations if you’re named

An SDF carries a heavier compliance load on top of the ordinary Fiduciary duties. In outline, a notified SDF must:

  • Appoint a Data Protection Officer who is based in India and answerable to its board — a role it can’t outsource to a vendor;
  • Get an independent data audit of its compliance;
  • Run a Data Protection Impact Assessment and audit periodically (once every twelve months from notification);
  • Exercise due diligence over its algorithms where they could harm individuals’ rights; and
  • Observe any data-localisation restriction the government specifies for certain data.

This is the summary; the dedicated pillar on SDF obligations walks through each in depth.

Could your company realistically qualify?

For most businesses the honest answer is “not yet, and probably not” — but a few signals mean you should pay attention. If you’re a clinic, an agency, a shop, or a mid-market SaaS, you’re very likely an ordinary Fiduciary and not an SDF. Consider whether you’re plausibly in scope if you: handle personal data at very large scale (millions of individuals); process especially sensitive data (financial, health, children’s) in volume; or operate infrastructure with national-level reach or impact. Even then, it’s the government’s notification that decides — but businesses with these traits should build as if the heavier bar could apply, so a future notification isn’t a scramble.

FAQ

How do I know if I’m a Significant Data Fiduciary?

You’re an SDF only if the government notifies you or your class as one, based on factors like data volume, sensitivity and risk. There’s no self-declaration.

Does my business become an SDF automatically once it’s large?

No. Scale makes designation more likely, but the status attaches only on government notification — not automatically by crossing a size.

What’s different about an SDF’s duties?

On top of the ordinary Fiduciary duties: an India-based DPO answerable to the board, independent audits, periodic impact assessments, algorithmic due diligence, and any specified data-localisation limits.

Should a mid-sized company prepare for SDF status?

Only if its scale or the sensitivity of its data is unusually high. Most won’t qualify — but those that plausibly might should build toward the higher bar in advance.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →