All articles
Regulatory Update 7 min read 18 September 2026 Primitra

Do You Need a Data Protection Officer Under the DPDP Act? What Rule 13 Actually Says for Indian SMEs

Most Indian SMEs assume the DPDP Act requires a formal DPO the way GDPR does. It usually does not. Here is the difference between the Section 8(9) contact every business needs and the Rule 13 DPO that only Significant Data Fiduciaries must appoint.

Do You Need a Data Protection Officer Under the DPDP Act? What Rule 13 Actually Says for Indian SMEs

A question we hear almost every week from founders and operations heads goes something like this: "Our EU clients keep asking for our DPO. Do we legally need a Data Protection Officer under the DPDP Act too?" The short answer surprises most people. For the large majority of Indian small and mid-sized businesses, the DPDP Act does not require you to appoint a formal Data Protection Officer at all. It does require something, and confusing the two obligations is where companies either waste money or leave a real gap.

Here is what the law actually asks of you, and how to tell which side of the line your business sits on.

Two different obligations hiding under one job title

The DPDP Act, 2023 draws a distinction that GDPR does not.

First, Section 8(9) applies to every Data Fiduciary, whatever your size. You must publish the business contact information of a person who can answer a Data Principal's questions about how you process their personal data. Rule 9 of the DPDP Rules, 2025 spells out where this goes: prominently on your website or app, and in every reply you send when someone exercises a right. This person does not need a special title. A competent operations lead, a co-founder, or your grievance officer can hold the role, as long as they genuinely understand what data you collect and why.

Second, and separately, Section 10 read with Rule 13 requires a formal Data Protection Officer. This applies only to organisations the Central Government notifies as a Significant Data Fiduciary (SDF). As of 2026, no company or class of companies has been notified as an SDF. Categorisation is expected during the phased rollout, and it will turn on factors like the volume and sensitivity of the data you handle, risk to the sovereignty and integrity of India, and risk to public order.

So the practical reality for a 40-person SaaS company or a regional retail chain: you almost certainly need a named contact under Section 8(9), and you almost certainly do not need a Rule 13 DPO unless the government tells you otherwise.

What a Rule 13 DPO actually has to be

If your business does get designated an SDF, the requirements are specific and not cosmetic. The DPO must be an individual based in India. They must be responsible to the Board of Directors or an equivalent governing body, which makes this a governance role rather than a junior compliance seat. They act as the point of contact for the grievance redressal mechanism under the Act.

That designation comes bundled with the rest of Rule 13: an independent data auditor, a Data Protection Impact Assessment and audit once every twelve months counted from your notification date, due diligence on any algorithmic software you deploy, and adherence to any data-localisation directions the government issues. A DPO without those surrounding processes is a title with nothing behind it.

Why the GDPR comparison keeps tripping people up

Under GDPR, a DPO is mandatory in more situations, including for organisations whose core activities involve large-scale regular monitoring or large-scale processing of special category data, regardless of company size. Plenty of Indian vendors were told by European customers, correctly for that contract, to name a DPO. The mistake is assuming the Indian law mirrors it. The DPDP Act's DPO trigger is narrower and controlled by government notification, not by a self-assessment against processing thresholds.

The wider signal from Europe is still worth reading. Through the middle of 2026, GDPR regulators have kept up steady enforcement, with cumulative fines now past 7 billion euros, and a clear tilt toward accountability failures: weak technical and organisational measures, thin vendor oversight, and fuzzy lines of responsibility for who owns privacy inside a company. The takeaway for Indian firms is not "appoint a DPO to be safe." It is that regulators eventually ask a simple question after an incident: who inside this company was actually answerable for personal data? If the honest answer is "nobody in particular," that is your exposure, SDF or not.

What Indian SMEs should do before May 2027

The core substantive obligations of the DPDP framework are expected to take full effect around 13 May 2027, with no grace period built in. That gives you a real runway, and a short one. A sensible sequence looks like this.

Name your Section 8(9) contact now, and publish that contact somewhere a customer can find it in under a minute. Write down, even as a one-page internal note, what personal data you hold, where it lives, and who the responsible person is. Watch for SDF notifications; if your data volumes or your sector make designation plausible, start scoping a DPO appointment and an audit cadence early rather than scrambling after a notification lands. Fold the DPO question into your broader DPDP Act compliance work instead of treating it as a standalone box to tick.

Most SMEs finish this exercise realising they need a clear owner and a published contact, not a new senior hire. That is the right outcome, and it is a great deal cheaper than discovering during a Data Protection Board inquiry that nobody could say who was in charge.

If you are unsure whether your organisation is drifting toward SDF status, or you want help setting up a defensible contact-and-governance structure, our team can walk you through it. Look at our DPO advisory services, run your business through the DPDP compliance checklist, or get in touch for a scoped assessment.

This article is general guidance for Indian businesses and not legal advice. Your obligations depend on your specific data processing, sector, and any notifications issued under the DPDP Act. For a review of your situation, start with our checklist or contact us.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation