Are You a Significant Data Fiduciary Under the DPDP Act? How Indian Companies Can Tell Before the Government Decides
The DPDP Act's toughest duties fall on Significant Data Fiduciaries, a category defined loosely enough that a fast-growing Indian startup could land inside it without picturing itself as a data giant. Here's how to tell where you stand before the government decides.
Most Indian businesses reading the DPDP Act assume the heavy obligations belong to someone else. The banks. The telecom giants. The social media platforms with hundreds of millions of accounts. For the top tier of duties, that instinct is roughly right. But the category that carries those duties, the Significant Data Fiduciary, is defined by criteria loose enough that a fast-growing fintech, a health-tech startup, or a mid-sized ad-tech firm could find itself inside it without ever picturing itself as a data giant. Working out whether you are a Significant Data Fiduciary, before the Central Government tells you, is now a planning question worth an afternoon.
What actually makes a company a Significant Data Fiduciary
The label does not attach automatically. Under Section 10 of the DPDP Act, 2023, a company becomes a Significant Data Fiduciary only when the Central Government notifies it, or notifies a whole class it belongs to. There is no revenue threshold and no user-count line written into the statute. Instead the government weighs a set of factors: the volume and sensitivity of the personal data you process, the risk your processing poses to the rights of individuals, and broader concerns like the sovereignty and integrity of India, risks to electoral democracy, the security of the State, and public order.
Read those criteria closely and one thing stands out. Volume and sensitivity sit right at the top. A company processing health records, financial details, precise location, or biometric data can clear the sensitivity bar at a far smaller scale than a company handling only names and email addresses. So the real question is not "are we big?" It is "how much do we hold, how sensitive is it, and what happens to real people if we get it wrong?"
The obligations that come with the label
Once designated, a Significant Data Fiduciary picks up duties that ordinary Data Fiduciaries do not carry. Rule 13 of the DPDP Rules, 2025 spells them out. You must appoint a Data Protection Officer based in India who reports to your board or governing body. You must engage an independent data auditor. And under Rule 12, you must run a Data Protection Impact Assessment and a data protection audit at least once every twelve months, then furnish a report of the significant findings to the Data Protection Board of India.
There is also algorithmic due diligence. If your product uses automated decision-making or algorithms that touch personal data, an SDF is expected to verify that those systems do not create risks to data principals. For any company building recommendation engines, credit-scoring models, or automated screening, that becomes a standing governance commitment, not a one-time form. Breaching the additional SDF obligations carries a penalty of up to Rs 150 crore per instance under the Act's Schedule, so this is not a paperwork tier.
Why this matters even if you are never designated
Here is the practical part. Notification of SDFs is expected to come in phases, and the substantive obligations across the DPDP framework take full effect around 13 May 2027. You may never receive an SDF notice. But two things make the SDF playbook worth borrowing anyway.
First, the DPIA. A Data Protection Impact Assessment is a structured review of what data you collect, why, where it flows, and what could go wrong. Even if Rule 12 never binds you, running one surfaces the exact gaps that ordinary compliance also requires you to close: consent you cannot evidence, retention with no end date, vendors with no signed contract. A DPIA is among the cheapest diagnostics you can run, and it doubles as your paper trail if the Board ever asks questions. Our note on privacy impact assessments walks through how to scope one for a small team.
Second, designation can arrive on a class basis. The government can notify an entire category at once. If a future notification covers all data fiduciaries in a high-risk sector above a certain processing threshold, a company that spent 2026 treating SDF duties as someone else's problem would be starting from zero. Building the muscle early, a functioning DPO function and a repeatable audit rhythm, is far easier than assembling it under a deadline.
A short self-check for Indian SMEs
You do not need a law firm to make a first pass. Sit with your team and answer honestly. Do you process sensitive categories at scale, whether health, finance, children's data, biometrics, or precise location? Would a breach of your database put real people at genuine risk of fraud, discrimination, or harm? Do you make automated decisions about individuals that affect their access to money, services, or opportunities? Are you growing fast enough that your data volumes eighteen months from now will look nothing like today's?
Answer yes to two or more, and you should treat SDF-grade practices as a live possibility rather than a distant hypothetical. That does not mean rushing to appoint an auditor tomorrow. It means running a DPIA, mapping your data, and knowing where you would stand if a notice landed on your desk.
Where to start this quarter
The sensible sequence is unglamorous. Map your data first, so you actually know what you hold and where it goes. Run a DPIA against that map. Fix the obvious gaps: missing notices, stale retention, uncontracted vendors. Decide who owns privacy internally, even informally, before Rule 13 forces the question. If the honest answer to "who is our DPO?" is nobody, that is the first thing to change, and our DPO services exist for exactly that gap.
None of this requires you to be certain you are a Significant Data Fiduciary. It requires you to stop assuming you are not. For a wider view of how these pieces fit together, the DPDP Act compliance overview sets out the full obligation map, and our compliance checklist turns it into concrete steps.
This article is general guidance, not legal advice; your specific obligations depend on your facts. If you would like help figuring out where your business stands, start with our checklist or get in touch.
Get help implementing this
Turn this reading into a compliance plan.
Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.
Book a free 30-minute consultation