What is a Data Protection Officer (DPO)?
A Data Protection Officer (DPO) is the senior person a Significant Data Fiduciary must appoint to lead its data-protection compliance — based in India and answerable to the business’s board. The DPO is also the point of contact for people’s grievances and for the regulator.
Educational resource only — not legal advice.
Under India’s Digital Personal Data Protection Act, 2023 (DPDP Act), appointing a DPO is a specific obligation of a Significant Data Fiduciary (SDF) — the higher-risk businesses the government designates — not of every Data Fiduciary. The DPO must be based in India and report to the governing body, giving the organisation one accountable person for how it meets the Act.
Why it matters to you. If your business is designated an SDF, a compliant DPO is mandatory. For most businesses, which aren’t SDFs, having someone own data protection is good practice but not a legal requirement.
What it is not. A DPO is not required of every business under the DPDP Act — the hard obligation attaches to Significant Data Fiduciaries.
Collecting personal data from your own customers?
These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.
Run the compliance self-check →