Confidential Dispatch

Significant Data Fiduciary obligations under DPDP, explained

5 min readUpdated 2026-07-02
On this page
  1. 01What is a Significant Data Fiduciary?
  2. 02How does the government decide who’s an SDF?
  3. 03What extra obligations does an SDF carry?
  4. 04Are you likely to be one?
  5. 05What’s the penalty, and when does it apply?
  6. 06FAQ
At a glance

A Significant Data Fiduciary (SDF) is a higher-risk business the government specifically names under the DPDP Act — usually because of the scale or sensitivity of the data it handles. On top of every ordinary duty, an SDF must appoint an India-based Data Protection Officer, run independent audits and an annual Data Protection Impact Assessment, exercise algorithmic due diligence, and keep certain data inside India. Most businesses are not SDFs.

Educational resource only. This explains the additional obligations of a Significant Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and its Rules; it is not formal legal advice.

What is a Significant Data Fiduciary?

An SDF is not something you become by ticking a box — it’s a designation the Central Government applies to specific businesses or classes it judges higher-risk. Every organisation that decides why and how personal data is processed is a Data Fiduciary. A Significant Data Fiduciary is a subset of those: the ones the government notifies as significant under Section 10 of the DPDP Act, because their data processing carries greater risk to people or to the country.

The key point is direction: you don’t self-declare as an SDF, and you don’t opt in. The government names you — individually or as a class. Until it does, you carry the ordinary Data Fiduciary duties, not the extra SDF ones.

How does the government decide who’s an SDF?

The designation is a risk judgment, based on a defined set of factors — scale and sensitivity of data, and the wider stakes. The Act lists what the Central Government weighs when deciding whether to notify a Data Fiduciary as significant:

  • the volume and sensitivity of personal data it processes;
  • the risk to the rights of Data Principals;
  • potential impact on the sovereignty and integrity of India;
  • risk to electoral democracy;
  • security of the State; and
  • public order.

Read together, these point at large-scale processors and platforms whose data — or whose influence over people — is consequential at a national level. It’s a targeted net, not a general one.

What extra obligations does an SDF carry?

On top of every ordinary Data Fiduciary duty, an SDF takes on a heavier accountability layer — split between the Act and the Rules. From the Act itself:

The DPDP Rules (Rule 13) sharpen these into concrete duties:

  • Undertake a DPIA and audit every 12 months, and furnish a report of the significant observations to the Data Protection Board.
  • Algorithmic due diligence — verify that the software and algorithms used to process personal data are not likely to pose a risk to Data Principals’ rights. This is a notable first: an explicit legal duty to check your algorithms.
  • Data localisation — ensure that categories of personal data (and the traffic data about their flow) specified by the government are not transferred outside India.

A DPIA, in plain terms, is a structured review of what data a processing activity uses, why, the risks to people, and how those risks are managed — done before and during high-risk processing, not after something goes wrong.

Are you likely to be one?

Almost certainly not — SDF is the high-risk exception, not the rule, and no SDFs have been named yet. If you run a clinic, an agency, a coaching class, a shop, or a small SaaS, you are a Data Fiduciary with the ordinary obligations — but you are very unlikely to be designated significant. The SDF tier is aimed at large platforms and high-stakes processors, and designation only happens when the government actually notifies you.

That said, it’s worth a self-assessment if you process personal data at genuine scale or handle especially sensitive categories — because the factors above are the government’s lens, and the extra duties are substantial enough that you’d want to see them coming. For most readers, though, the ordinary Data Fiduciary duties are the ones to focus on.

What’s the penalty, and when does it apply?

Failing an SDF obligation carries a penalty of up to ₹150 crore, and the duties become binding on 13 May 2027. The DPDP Act’s Schedule places a breach of the additional SDF obligations in the up-to-₹150 crore band — a tier that exists only for designated significant fiduciaries. Like the other substantive obligations, the SDF duties come into force 18 months after the Rules were notified, on 13 May 2027. No businesses have been notified as SDFs yet, so this is a duty to prepare for if you’re in scope, not one already live.

FAQ

Do I decide if I’m a Significant Data Fiduciary?

No. The Central Government designates SDFs, individually or by class. You don’t self-declare or opt in — until you’re notified, you carry the ordinary Data Fiduciary duties.

What are the main extra duties of an SDF?

An India-based Data Protection Officer, an independent auditor, an annual Data Protection Impact Assessment and audit reported to the Board, algorithmic due diligence, and localisation of specified data within India.

Does a small business need to worry about SDF rules?

Very unlikely. SDF is aimed at large-scale or high-sensitivity processors. Most businesses are ordinary Data Fiduciaries and should focus on those obligations.

What’s the penalty for an SDF failure?

Up to ₹150 crore, under the DPDP Act’s Schedule — a tier specific to Significant Data Fiduciaries.

Reviewed by Confidential Dispatch Editorial Team
Last updated 2 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →