Skip to main content

Sources last verified on 24 August 2026. Methodology

Data Protection Officer under the DPDP Act: who must appoint one

Compliance

By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 16 min read

The short answer

Only a Significant Data Fiduciary, notified by the Central Government under section 10, must appoint a Data Protection Officer. Section 10(2)(a) requires an individual who represents the fiduciary, is based in India, is responsible to its Board of Directors or similar governing body, and is the point of contact for grievance redressal. Every other Data Fiduciary owes, in place of any appointment duty, the section 8(9) and Rule 9 duty to publish the business contact information of a person able to answer questions about the processing. Nobody has been notified as of 24 August 2026, and section 10 commences on the computed date 13 May 2027, interpretation until confirmed.

TL;DR infographic answering: Who must appoint a Data Protection Officer under the DPDP Act?

Search for Data Protection Officer guidance in India and you get a job description written for Brussels: an independent expert, insulated from dismissal, free of conflicts, reporting to the highest management level and registered with the regulator. The DPDP Act builds the role from a much shorter list, hands it to a much smaller group, and leaves almost everyone else owing something quite different: a published contact person, not an officer. This article states who must appoint a Data Protection Officer, what section 10(2)(a) of the DPDP Act 2023 requires of that individual, what every other Data Fiduciary owes instead under section 8(9) of the Act and Rule 9 of the DPDP Rules 2025, and which GDPR habits have no basis in the Indian text, with every claim cited to the Gazette.

The answer in 2 tiers

Tier 1: notified Significant Data FiduciaryTier 2: every other Data Fiduciary
Must appoint a Data Protection Officer?Yes, section 10(2)(a)No appointment duty appears in the Act or in the Rules as corrected, checked on 24 August 2026
What the duty isappoint an individual satisfying 4 conditions in the textpublish the business contact information of a Data Protection Officer, if applicable, or a person able to answer questions about the processing, section 8(9)
Where the contact must be publishedwebsite or app, and in every rights response, Rule 9website or app, and in every rights response, Rule 9
How you enter the tiera Central Government notification under section 10(1)by being a Data Fiduciary at all
Penalty exposureentry 4 of the Schedule names section 10 expressly, up to Rs 150 croresection 8(9) is named in no entry, so this site reads it into residual entry 7, up to Rs 50 crore
In force?no, computed 13 May 2027no, computed 13 May 2027

Most organisations reading this page are in tier 2, and will stay there: tier 1 exists only by name. Section 2(z) defines a Significant Data Fiduciary as any Data Fiduciary or class notified by the Central Government under section 10, there is no threshold to compute, and as of 24 August 2026 no Data Fiduciary or class has been notified. So the practical position today is that no organisation in India carries a statutory duty to appoint a Data Protection Officer, and the duty every organisation will carry is the tier 2 contact person duty. How notification works, and what else it brings, is set out in what changes if you are notified and the Significant Data Fiduciary obligations guide.

What section 10(2)(a) actually requires

The whole appointment duty is 1 clause with 4 limbs. A Significant Data Fiduciary shall:

Official requirement · verbatim

"appoint a Data Protection Officer who shall— (i) represent the Significant Data Fiduciary under the provisions of this Act; (ii) be based in India; (iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and (iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act;"

Section 10(2)(a) of the DPDP Act 2023, Gazette page 9.

Read the limbs one at a time, because each is doing precise work.

Represents the fiduciary. Limb (i) makes the officer the organisation's face under the Act. This is the opposite of a watchdog posture: the officer speaks for the Data Fiduciary, not for the Data Principal and not for the regulator.

Based in India. Limb (ii) is the requirement with no counterpart in most privacy laws, and it is the one a foreign parent company most often gets wrong by naming a group privacy lead in London or Singapore. The expression "based in India" is used twice in the Act, here and in section 17(1)(d), and is defined in neither section 2 of the Act nor Rule 2 of the Rules, verified on 24 August 2026. So there is no residency test, citizenship test or minimum days in country to satisfy; there is a requirement whose content will be settled by practice.

An individual responsible to the governing body. Limb (iii) does 2 things. It rules out appointing a firm, a committee or a mailbox: the officer is an individual. And it fixes the accountability direction as upward, to "the Board of Directors or similar governing body". The decisive words are "of the Significant Data Fiduciary": the body in limb (iii) is the organisation's own, not the "Board" that section 2(c) defines as the Data Protection Board of India. The report that goes to the Data Protection Board under Rule 13(2) is the assessment and audit report, not anything from the officer.

Point of contact for grievance redressal. Limb (iv) wires the officer into the grievance machinery. Section 8(10) requires every Data Fiduciary to establish an effective grievance redressal mechanism, section 13 gives the Data Principal a right to readily available redressal and requires her to exhaust it before approaching the Board, and Rule 14(3) caps the published response period at 90 days. Section 13 itself names no officer; the connection is made from the section 10 end, and only for a notified fiduciary. The mechanics of that channel are covered in the grievance redressal guide.

That is the entire clause. What it does not carry is the subject of the next 2 sections.

Tier 2: the contact person duty almost everyone actually owes

Section 8 states the general obligations of every Data Fiduciary, with no significance condition attached. Section 8(9) is the one that matters here:

Official requirement · verbatim

"A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data."

Section 8(9) of the DPDP Act 2023, Gazette page 8.

Three things follow from that sentence. First, it applies to everyone, because section 8 does. Second, the words "if applicable" carry the tier split: section 2(l) defines Data Protection Officer as "an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10", and an organisation that has not been notified has no such officer to name. It publishes the alternative instead: a person able to answer questions about the processing. That reading of "if applicable" is this site's interpretation rather than printed text. It is the reading section 2(l) points to, though section 2 opens with the words "unless the context otherwise requires", so the definition is not formally sealed against a wider construction in section 8(9).

Third, and easy to miss: section 8(9) does not say appoint. It says publish. What the Act commands in tier 2 is that a contact who can answer be published, which assumes such a person exists but never creates an appointment duty, a title, or a set of conditions the person must satisfy. That too is a reading, and it is the reading that matters most for planning, because it means the tier 2 obligation is deliverable by a named person and a working mailbox rather than by an appointment process.

The manner of publication is not left open. Section 40(2)(h) gives the Central Government power to prescribe "the manner of publishing the business contact information of a Data Protection Officer under sub-section (9) of section 8", and Rule 9 exercises it in 1 sentence:

Official requirement · verbatim

"Every Data Fiduciary shall prominently publish on its website or app, and mention in every response to a communication for the exercise of the rights of a Data Principal under the Act, the business contact information of the Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary the questions of the Data Principal about the processing of her personal data."

Rule 9 of the DPDP Rules 2025, Gazette page 27.

So the duty has 2 places, not 1. A privacy page carrying the contact satisfies the first half. The second half is an operational requirement that reaches into every rights response your team sends: each reply to an access, correction, erasure or nomination request must itself carry the business contact information. A template change, not a policy change.

Nothing in Rule 9 touches appointment, qualifications or position either. The rule is about where the contact appears, and that is exactly the scope section 40(2)(h) permits.

Where the contact person shows up elsewhere

The tier 2 contact is not a single line on a privacy page. The same figure appears at 4 more points in the framework, in closely similar but not identical words, which is the practical reason to settle who it is early.

ProvisionGazette pageWhat it requires
Section 6(3)5every request for consent must provide "the contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond" to rights communications
Section 8(9)8publish the business contact information of the officer, if applicable, or a person able to answer processing questions
Rule 927the manner: prominently on the website or app, and in every rights response
Rule 7(1)(e)26every intimation of a personal data breach to an affected Data Principal must include the business contact information of "a person who is able to respond on behalf of the Data Fiduciary, to queries"
Second Schedule, item (g)(i)35for processing under section 7(b), the intimation to the Data Principal must give the business contact information of a person able to answer processing questions

Two patterns are worth noticing. Rule 7(1)(e) and the Second Schedule both name a person rather than an officer, so the breach notice and the section 7(b) intimation never depend on Significant Data Fiduciary status. And section 6(3) shows the same drafting choice as section 8(9): the officer first, "where applicable", with an authorised person as the general alternative.

The GDPR habits that do not carry

If your privacy programme grew up on Articles 37 to 39 of the GDPR, the left column below is the set of assumptions to check at the door. Those GDPR positions are practitioner habits formed under that Regulation and are offered as orientation pointers to the official EUR Lex text for separate review, not as restatements of EU law to rely on. The right column is the load bearing side: it is the DPDP text, verified against the Gazette texts of the Act and of the Rules as corrected on 24 August 2026.

GDPR DPO habitWhat the DPDP text says
The duty triggers on what you do: public authority status, large scale systematic monitoring, large scale special category dataThe duty triggers on who you are told you are. Only a Significant Data Fiduciary notified under section 10 must appoint, and nobody has been notified as of 24 August 2026
The officer must have expert knowledge of data protection law and practicesNo qualification, certification, experience or expertise standard appears anywhere in the Act or the Rules, verified 24 August 2026
The officer must be independent, must not be instructed on how to perform the role, and must not be dismissed or penalised for performing itNo independence clause, no protection from dismissal, no protection from penalty. Limb (i) of section 10(2)(a) points the other way: the officer represents the Significant Data Fiduciary
The officer must not hold a position causing a conflict of interestNo conflict of interest rule for the officer. The framework does impose such rules, on Consent Managers in items 9 and 10 of Part B of the First Schedule and on Board Members in item 8(1) of the Fifth Schedule. The words conflict of interest appear nowhere else in either text, checked on 24 August 2026
The officer reports to the highest management levelSection 10(2)(a)(iii) names one destination and is silent about everything else: an individual responsible to the Board of Directors or similar governing body. Reading that as excluding any other reporting line is this site's construction, not printed words
The officer may be a staff member or engaged under a service contractSilent. The text requires an individual and says nothing about employment, secondment or engagement, so the question is open
Contact details are communicated to the supervisory authorityNo filing, registration or intimation of the officer's identity to the Data Protection Board of India exists in either text, checked on 24 August 2026. The disclosures the text does require run to Data Principals, not to the regulator: publication under section 8(9) and Rule 9, and contact details in every consent request under section 6(3)
The officer's location is a practical arrangement"be based in India" is in the operative words of section 10(2)(a), the only geography condition in the clause
The officer owns the impact assessmentSection 10(2) creates the officer, the independent data auditor and the assessment as 3 parallel duties, and Rule 13(2) refers only to "the person carrying out the Data Protection Impact Assessment and audit". See DPIA under the DPDP Act

The single sentence version: the GDPR officer is designed for independence, the DPDP officer is designed for accountability. Importing the first design into an Indian appointment letter is not wrong, but nothing in the Act asks for it, and nothing in the Act protects an officer who relies on it.

What the text does not say

Stated as dated absences, verified against the full Gazette texts of the Act and the Rules as corrected on 24 August 2026. The expression "Data Protection Officer" appears 5 times in the Act, on Gazette pages 2, 5, 8, 9 and 18, and once in the English section of the Rules, in Rule 9 on page 27. Across those 6 appearances there is:

  • No qualification standard. Not a certification, not a number of years, not a field of study.
  • No independence, tenure or dismissal provision. The officer serves at the organisation's pleasure, as far as the Act is concerned.
  • No conflict of interest rule, in contrast to the Consent Manager and Board Member provisions in the Rules.
  • No periodicity for the officer. Rule 13 fixes a 12 month cycle, but it fixes it for the Data Protection Impact Assessment and the audit. Rule 13 does not mention the officer at all, and attributing an annual duty to the officer through section 10 is a mistake to avoid.
  • No registration or intimation duty. Nothing tells the Data Protection Board who your officer is.
  • No prescribed reporting line other than the governing body. Clause (h) of section 40(2) reaches only the manner of publishing contact information, and no clause from (a) to (y) names section 10(2)(a), while clauses (k) and (l) expressly serve section 10(2)(c). That asymmetry is why the assessment in section 10(2)(c) got Rule 13 and the officer got no rule. Whether the general power in section 40(1), or the residual clause (z), could carry future rules on the officer is a question this site does not answer. The dated absence is narrower: no such rule exists in the Rules as corrected, checked on 24 August 2026.
  • No alternative titles. The expressions "Grievance Officer", "privacy officer", "nodal officer" and "compliance officer" appear nowhere in either text. If you already run an IT Rules grievance officer, the DPDP framework neither recognises nor forbids the overlap.

Absences are not invitations to fill the gap and call the filling law. They are the reason a vendor template promising a "DPDP compliant DPO charter" cannot be measured against anything.

The numbers attached to getting it wrong

What is breachedWhere the Schedule puts itCap
Failing the section 10 duties, the officer, the auditor, the assessment and auditentry 4, named expresslyup to Rs 150 crore
Failing to publish the contact under section 8(9), or failing the Rule 9 mannerentry 7, breach of any other provision of the Act or the rulesup to Rs 50 crore

The Schedule, printed on Gazette page 21 under the reference to section 33(1), names sections 8(5), 8(6), 9, 10, 15 and section 32 undertakings in entries 1 to 6, and sweeps everything else into entry 7 at up to Rs 50 crore. Section 8(9) is not named in any specific entry, so placing it in the residual is this site's reading rather than a printed mapping. Either way the tier 2 duty is not unenforceable: it is a duty whose breach sits in the residual band, and the band is Rs 50 crore.

When any of this starts

Nothing in this article is in force yet, and 1 part of it already is.

The definitions commenced first. Paragraph (a) of notification G.S.R. 843(E) brought section 2 into force on the date of publication, printed as 13 November 2025, so the statutory definition of Data Protection Officer in section 2(l) has been law since then, while the duty it points at has not.

The duties commence together. Paragraph (c) of the same notification names "sections 7 to 10" and "sections 11 to 17" in the group that comes into force 18 months from publication, so sections 8, 10 and 13 all arrive at once. Rule 1(4) puts Rules 3, 5 to 16, 22 and 23 in the matching 18 month group, which covers Rules 7, 9, 13 and 14. All of it computes to 13 May 2027, a computed date that is interpretation until officially confirmed: the official texts state a period of eighteen months from publication, not a calendar date. The full sequence is on the timeline.

So the honest status on 24 August 2026 is 2 layered negatives. Section 10(2)(a) is not in force, and even when it is, it will reach only organisations the Central Government has notified, of which there are none.

Should you appoint one anyway?

Offered as this site's recommendation, not as law, and split by which tier you expect to be in.

If you expect to stay in tier 2, do not appoint a Data Protection Officer. Designate a contact person, publish business contact information that a real human monitors, and put that same contact into your consent requests, your rights response template and your breach notification template now, because Rule 9 will ask for it in 2 places and Rule 7(1)(e) in a third. Prefer a plainer title: section 2(l) reserves the expression Data Protection Officer for a section 10(2)(a) appointment, so publishing one at an organisation that was never notified names an office the Act does not recognise for it. Nothing in the Act or the Rules forbids the title, and an organisation with a GDPR programme may have good reasons to keep it, so treat this as a clarity preference rather than a rule.

If notification looks plausible for you, on the volume and sensitivity of what you process rather than on any threshold, the part of section 10(2)(a) that takes longest to build is limb (iii). A reporting line into the board, with a standing agenda item and a record of what was reported, is a governance change measured in quarters. Naming an individual based in India is the easy half.

What to do now

Confirm what you are with the role tool, then generate your obligation set with the company compliance plan, where publishing the contact for processing questions appears as an action for every Data Fiduciary and the Significant Data Fiduciary cycle appears as a conditional action clearly marked as applying only if notified. The official texts live at section 8, section 10, Rule 9 and Rule 13, each with its Gazette citation.

Section 10, official textSection 8, official textRule 9, official textRule 13, official textAdditional obligations of a Significant Data Fiduciary: DPO, auditor, DPIASignificant Data Fiduciary: what changes if you are notifiedDPIA under the DPDP Act

data protection officersection 10rule 9significant data fiduciarygdpr comparison

Share this: