DPDPA Section 10: Additional Obligations and Designation of Significant Data Fiduciaries

DPDPA Section 10: Additional Obligations and Designation of Significant Data Fiduciaries

Navigate the strict significant data fiduciary criteria under DPDPA Section 10. Prepare your organization for mandatory DPOs, DPIAs, and independent audits.

Sahil Pugalia

Written by

Sahil Pugalia

Date

Read time

6 min

Most compliance laws apply equally to everyone. DPDPA Section 10 does not. It exists specifically to set a higher, heavier bar for entities that handle massive volumes of personal data or present heightened systemic risks. Under the law, these organizations are designated as Significant Data Fiduciaries (SDFs).

If standard compliance is a baseline fitness test, Section 10 is the professional league. It dictates how an entity becomes an SDF and, more importantly, the operational weight that drops on your shoulders once you are designated.

Who can be designated as a Significant Data Fiduciary

You do not self-identify as an SDF. You do not opt in. The Central Government must notify a data fiduciary,or an entire class of data fiduciaries,as SDFs after assessing the landscape.

Illustration showing the Central Government designating a data fiduciary as a Significant Data Fiduciary.

The statute lists specific significant data fiduciary criteria for this assessment, including:

  • Volume and sensitivity of personal data processed
  • Risk to the rights of Data Principals
  • Potential impact on the sovereignty and integrity of India
  • Risk to electoral democracy
  • Security of the State
  • Public order

The law leaves room for other factors to be prescribed, but the focus is clear: scale, sensitivity, systemic impact, and national interest concerns. If your sector or class is notified, the obligations apply to you immediately.

The practical boundary is simple: until the government issues a notification for your organization or your class of organizations, you are not an SDF. That said, if you sit squarely in a high-scale, high-risk bracket, waiting for the official letter is a mistake. The ramp-up is not a weekend exercise.

What an SDF must do

Once designated, the abstract idea of compliance becomes a rigid operational mandate. An SDF must implement five core measures. Some specifics are in the Act; others are clarified in applicable rules.

Illustration showing the five core compliance measures required for a Significant Data Fiduciary under DPDPA Section 10.

1) Appoint a Data Protection Officer (DPO)

  • Must be based in India.
  • Must be an individual responsible to the Board of Directors or a similar governing body.
  • Represents the SDF under the Act and before the Data Protection Board.
  • Acts as the point of contact for the grievance redressal mechanism and for Data Principals.
  • The DPO’s business contact information must be published so people can reach them.

What this means in practice: You cannot outsource this role to a global compliance desk in another time zone. Physical presence in India is mandatory. Put the DPO in a governance line that is independent of commercial functions,direct reporting to the Board or equivalent is expected. Publish their name, email, phone, and office address in India in a place that is easy to find, such as your privacy notice and website footer.

2) Appoint an independent data auditor

You must engage an external auditor to evaluate your compliance under the Act. Independence is critical. Avoid firms with conflicts such as recent employment ties, concurrent consulting on the same controls, or financial dependence. Rules referenced in the input call for annual audits, submission timelines, and public summaries. Treat this as a standing program, not a one-off check.

3) Conduct periodic Data Protection Impact Assessments (DPIAs)

A DPIA is not a theoretical document. It is a documented process describing the rights of Data Principals, the purposes of processing, risks to those rights, and exactly how those risks are assessed and managed. It must be conducted periodically and in accordance with any prescribed requirements.

Triggers under the Rules include new large-scale or high-risk processing, technology changes such as AI or biometrics, purpose changes, and periodic reviews even without change. The rule is simple: do the DPIA before launch, not after the code ships.

4) Run periodic audits

Beyond the independent data audit, Section 10 expects ongoing periodic audits. Integrate legal, technical, and process controls into the audit scope. Close audit findings with documented remediation.

5) Implement any other prescribed measures

The Act leaves room for additional measures to be prescribed over time. Monitor new rules and notifications, then update your controls and documentation accordingly.

Key roles and expectations

Data Protection Officer

The legal minimums are clear: India-based, Board-level reporting line, representative to the Board, point of contact for grievances and Data Principals, and contact details published. But the practical expectation is independence in function. The DPO must have the ability to advise on DPIAs and controls, and the authority to monitor compliance. Avoid tying DPO performance to commercial outcomes that can compromise their independence.

Independent data auditor

Independence is non-negotiable. Set and enforce conflict checks. Do not hire the same firm to design and then audit your controls. Expect intense scrutiny of your data inventory, consent and notice practices, security measures, retention and deletion, rights handling, grievance redressal, children’s data protections, and DPIA execution.

How Section 10 changes day-to-day operations

Governance gets formal

Establish a documented DPO charter. Define their access to leadership, decision rights on high-risk processing, and minimum involvement in project reviews. Build a compliance calendar covering DPIAs, annual audits, and periodic reviews.

Risk assessment becomes pre-emptive

DPIAs move risk assessment to the design phase. High-risk use cases like profiling, automated decisions, and biometric processing face extra scrutiny. If your DPIA cannot justify the processing or show adequate mitigation, do not proceed without reworking the design. Document the rationale.

Transparency is enforced

Publish DPO contacts clearly. Maintain a working grievance redressal mechanism that links to the DPO where required. Keep documentation current and discoverable. Your auditor and the Board will ask for it.

Vendors and affiliates feel the effect

Independence rules limit who can audit you. If you rely on a large consulting partner for implementation, you likely cannot use them for the independent audit. Furthermore, high-risk processing outsourced to partners still requires your DPIA and oversight. Contractual controls must match your SDF duties.

A concise SDF readiness plan

Week 1 to 4

  • Confirm SDF status or likelihood based on notifications and risk profile.
  • Appoint an India-based DPO with a Board reporting line. Publish contact details.
  • Stand up a register of processing activities with data flows, purposes, and legal bases.

Week 5 to 8

  • Select an independent data auditor. Run formal independence checks.
  • Identify high-risk processing. Complete your first DPIA for the highest risk item. Implement mitigation measures.

Week 9 to 12

  • Complete your first independent audit. Present findings to the Board. Begin remediation and track to closure.
  • Create an audit and DPIA calendar. Define documentation standards and internal escalation paths.

Common mistakes to avoid

  • Waiting for a name-and-shame list. If your class is notified, you are in scope even if not individually named.
  • Appointing a DPO outside India or burying their contact information in dense policies.
  • Assigning the DPO under a commercial function that can override risk calls.
  • Hiring an auditor with conflicts or delaying the annual audit because delivery teams are busy.
  • Treating DPIAs as a formality. Do them before launch and act on the findings.
  • Ignoring audit and DPIA recommendations or failing to document remediation.

What to watch for

  • Government notifications defining SDF classes and any additional factors or measures.
  • Prescribed details under rules on audit frequency, DPIA triggers, submission timelines, and publication requirements.
  • Sector-specific guidance if you operate in areas that implicate sovereignty, electoral integrity, or critical infrastructure.

The Reality of Execution

Getting Section 10 right is about structure and discipline. The designation triggers real oversight and real timelines. You have to build a program that can produce evidence on demand.

Real execution is where teams struggle. Appointing a DPO is easy on paper. Designing DPIAs that actually change product decisions, enforcing auditor independence, and keeping remediation on schedule is operationally hard.

At Regodit, we built our platform because obligations need to be translated into trackable plans. We give you a structured way to run this program end to end,with owners, evidence, and timelines you can actually show to auditors and the Board. If you are close to SDF designation or already notified, schedule a discussion to pressure-test your plan and identify gaps before they become findings.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →