Significant Data Fiduciaries Under the DPDP Act: When Scale Becomes a Liability

Significant Data Fiduciaries Under the DPDP Act: When Scale Becomes a Liability

Does your company qualify as a significant data fiduciary under DPDP Act? Discover the Section 10 triggers, DPO mandates, and DPIA compliance requirements.

Priyanka Choudhury

Written by

Priyanka Choudhury

Date

Read time

5 min

There is a comforting assumption circulating among organisations trying to decode India’s data privacy law requirements: that the Digital Personal Data Protection Act (DPDP Act) treats everyone equally.

It doesn’t.

The law introduces a special, heavier tier of compliance reserved for a category called Significant Data Fiduciaries (SDFs). These are not just large companies. These are organisations whose data practices have crossed a threshold where a failure stops being a corporate problem and starts being a societal one. For large digital platforms, financial institutions, and technology companies, the pressing question is no longer whether the DPDP Act applies. It is whether the government is about to classify you as a significant data fiduciary under the DPDP Act.

What the Law Says

The concept of the significant data fiduciary under the DPDP Act lives in Section 10. Under this section, the central government holds the power to notify certain Data Fiduciaries as “Significant” based on a specific set of triggers.

If you are wondering who is a significant data fiduciary, the government looks at several factors:

  • Volume and sensitivity of personal data processed
  • Risk to the rights of Data Principals
  • Potential impact on the sovereignty and integrity of India
  • Risk to electoral democracy
  • Security of the State
  • Public order

The underlying logic is straightforward: if your data practices have the potential to cause large-scale collateral damage, your governance standards must match that blast radius.

Factors government look for significant data fiduciary

What This Means in Practice

To understand how this abstract criteria translates to reality, consider a few real-world scenarios.

Example 1: Large Social Media Platforms

A social media platform operating in India processes the personal data of tens of millions of users: names, contact details, location signals, behavioural patterns, and private messaging interactions. That is not routine data handling. That is infrastructure. The sheer scale, combined with the influence such platforms have over information flows, makes them the most obvious candidates for SDF designation. Standard compliance was never going to be enough here.

Example 2: Digital Payment Platforms

A major payment app processing millions of daily transactions sits on financial transaction records, device identifiers, and bank-linked mobile numbers. This is not just sensitive data. It is the kind of data that, if mishandled, can quietly devastate someone’s financial life before they notice. The government recognises that. The SDF framework reflects it.

Example 3: Large E-commerce Platforms

An e-commerce marketplace serving millions of customers collects addresses, purchase history, payment information, and behavioural data for recommendations. At scale, this data builds a consumer portrait far more detailed than most users realise they have handed over. That portrait, in the wrong hands or under weak governance, becomes a liability the law is no longer willing to ignore.

In all these cases, the government’s position is the same: standard compliance is a baseline, not a ceiling.

Additional Obligations for Significant Data Fiduciaries

Once an organisation is designated as a Significant Data Fiduciary, Section 10 stops asking nicely. You are no longer just protecting data. You are proving it through mandatory governance mechanisms that have real teeth.

1. Appointment of a Data Protection Officer

Significant Data Fiduciaries must appoint a dedicated Data Protection Officer who must be based in India and who reports directly to the Board of Directors or an equivalent governing body. This is not a title you hand to an existing legal counsel on a Friday afternoon. The DPO serves as the named point of contact for both Data Principals and the Data Protection Board of India for grievance redressal and compliance matters. For a large fintech operating nationwide, this means a senior compliance leader with actual authority and clear accountability to the organisation’s highest governance level.

2. Appointment of an Independent Data Auditor

Significant Data Fiduciaries must also appoint an independent external data auditor to periodically evaluate whether the organisation is complying with the provisions of the DPDP Act. This is a distinct, separately named obligation under Section 10(2)(b). The internal audit function does not satisfy this requirement. The auditor must be genuinely independent of the SDF, with no conflicts of interest. Under Rule 13 of the DPDP Rules, 2025, the auditor must submit their report, including significant observations and a remediation plan, to the Board. This external check exists because self-assessment is not accountability.

3. Data Protection Impact Assessments

Significant Data Fiduciaries are required to conduct data protection impact assessments periodically, including before deploying high-risk processing activities. The operative word is before. Not after a product launches. Not after a regulator asks questions. A company planning to introduce an AI system that analyses user behaviour for personalisation must evaluate the privacy implications of that system before a single user touches it. DPIAs exist to catch governance failures at the design stage, where fixing them is cheap, not at the enforcement stage, where fixing them is not.

4. Periodic Audits

The law also mandates periodic audits of data processing practices. These are not internal self-assessments dressed up in formal language. They are structured evaluations of whether the organisation’s data governance systems actually comply with legal requirements or just look good on paper. For large enterprises handling massive datasets, these audits become the mechanism that keeps accountability from becoming theoretical.

Periodic Audits

Why the Government Introduced the SDF Category

The DPDP Act recognises a fundamental truth of the digital economy: not all organisations pose the same level of risk.

A small startup collecting customer emails for a newsletter does not carry the same societal weight as a platform managing data of hundreds of millions of users. By introducing the Significant Data Fiduciary category, the law concentrates stronger obligations where the potential impact on individuals and society is greatest. It is the same logic used in financial regulation, where systemically important institutions face requirements that smaller players do not.

What Companies Should Be Thinking About

For large enterprises, the possibility of being classified as a Significant Data Fiduciary raises important governance questions. Waiting for an official notification before acting is a gamble you cannot afford. Start building your DPDP Act compliance checklist now.

Companies should consider:

  • The scale of personal data they process
  • Whether they handle sensitive or high-risk datasets
  • How their services could affect large populations

Organisations that fall into these categories should begin strengthening their data governance frameworks even before formal designation. Preparing early makes it easier to adapt if the government notifies them as Significant Data Fiduciaries, turning a potential operational crisis into a simple administrative update.

A Governance Wake-Up Call for Large Data Platforms

The introduction of Significant Data Fiduciaries signals that India’s data protection regime is not purely one-size-fits-all.

Large organisations processing massive volumes of personal data are expected to demonstrate higher levels of responsibility, transparency, and oversight. For many enterprises, this will require formalising privacy governance, conducting regular risk assessments, and ensuring that leadership understands the regulatory expectations around data.

The scale of your data processing is your choice. The governance standards that come with it are not. And the bill for getting that wrong will be proportionate to exactly how much data you were sitting on when it arrived.

When your data footprint grows, so does your regulatory exposure. Regodit helps you stay ahead of both.

Disclaimer: The views and explanations shared in this blog are based on our team's understanding of the relevant compliance frameworks. While every effort has been made to ensure accuracy, readers are encouraged to refer to the original legal provisions and official notifications for authoritative guidance. Please reach out to us at connect@solsphere.ai.

Keep reading

All blogs →