At a glanceProbably not a statutory one. Under India’s DPDP Act, a mandatory Data Protection Officer — India-based and answerable to the board — is required only if you’re notified as a Significant Data Fiduciary (SDF), which most startups aren’t. But every business does have to publish a contact for data questions and run a grievance-redressal route. So the honest answer is: you likely don’t need a formal DPO yet, but you can’t skip having a named, reachable point of contact for privacy issues.
Educational resource only. This explains the Data Protection Officer (DPO) requirement under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
“Do we need to hire a Data Protection Officer?” is a common early-stage worry — and often an expensive misread. The DPDP Act does require a DPO, but only for a specific tier. Knowing whether you’re in it saves you either a needless hire or a real gap.
Who actually needs a mandatory DPO?
A statutory DPO is an obligation of Significant Data Fiduciaries — not of every business. The Act reserves the mandatory DPO for organisations the government notifies as SDFs (Section 10), based on factors like the volume and sensitivity of the data they handle and the risks involved. For an SDF, the DPO must be based in India, be answerable to the organisation’s board, and can’t be outsourced to a vendor.
Most startups aren’t SDFs — you’re an SDF only if the government notifies you or your class. So unless you’re operating at very large scale or handling especially sensitive data in volume, the mandatory-DPO rule likely isn’t yours yet.
What you need even if you’re not an SDF
Skipping the DPO doesn’t mean skipping accountability — every Data Fiduciary must be reachable and must handle grievances. The Act requires you to publish the contact details of a Data Protection Officer or another person who can answer questions about your processing, and to run an effective grievance-redressal mechanism. In plain terms: someone must be named and reachable for privacy questions and complaints, even if that person isn’t a formal, board-level DPO.
For a small team, that “someone” is often a founder or an ops lead — the point is that there’s a real, published point of contact, not that you’ve hired a specialist.
DPO vs a contact person vs a grievance officer
These get conflated, so it’s worth separating them.
- Statutory DPO — the formal role SDFs must appoint: India-based, board-answerable, non-outsourceable. Triggered by SDF notification.
- Published contact person — whom any Data Fiduciary must name and publish to answer processing questions. Not necessarily a “DPO.”
- Grievance handling — the route every business must offer so people can raise and resolve complaints.
A startup that isn’t an SDF still needs the second and third; it just doesn’t need the first.
What to put in place now
Do the reachable-and-responsive basics; scale to a formal DPO only if you grow into SDF territory.
- Name a point of contact for privacy/data questions and publish their business contact details where people can find them.
- Set up a grievance route — how someone raises a complaint and how you’ll respond, within a stated timeframe.
- Watch your scale. If you start handling data at very large volume or especially sensitive data, revisit whether SDF obligations (including a formal DPO) could apply.
- Don’t over-hire early. A dedicated DPO is an SDF requirement; for most startups a named, accountable contact is what the law actually asks for.
FAQ
Is a Data Protection Officer mandatory for every company under the DPDP Act?
No. A statutory DPO is mandatory only for Significant Data Fiduciaries. Other businesses must publish a contact person and run a grievance route, but don’t need a formal DPO.
When would my startup need a formal DPO?
If the government notifies you (or your class) as a Significant Data Fiduciary — typically tied to large data volume, sensitivity, and risk.
Can the contact person be a founder?
Yes. For a non-SDF, the required point of contact can be an existing team member; it doesn’t have to be a dedicated, board-level DPO.
What’s the difference between a DPO and a grievance officer?
A DPO is the formal SDF role; grievance handling is a route every business must provide. A non-SDF needs a published contact and a grievance route, not a statutory DPO.