Skip to main content

Sources last verified on 20 August 2026. Methodology

Additional obligations of a Significant Data Fiduciary: DPO, auditor, DPIA

Compliance

By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 6 min read

The short answer

Section 10(2) adds three duties once the Central Government notifies a Data Fiduciary or class as significant. First, appoint a Data Protection Officer who represents the organisation, is based in India, is responsible to the board of directors or similar governing body, and is the contact point for grievance redressal. Second, appoint an independent data auditor to evaluate compliance with the Act. Third, undertake periodic Data Protection Impact Assessments and periodic audits. Rule 13 turns periodic into a cycle of once every twelve months from notification, requires the person conducting the DPIA and audit to report significant observations to the Data Protection Board, adds due diligence over algorithmic software, and enables localisation of specified personal data. No Significant Data Fiduciary has been notified as of 23 August 2026.

Every Data Fiduciary carries the general obligations of the DPDP Act. Significant Data Fiduciary status is a tier above that, and it arrives only by name: the Central Government notifies a Data Fiduciary or a class of them, and section 10(2) then attaches three additional duties that no one else carries. This article walks through those duties exactly as the Gazette text states them, what Rule 13 adds on top, and the honest state of play: as of 23 August 2026, nobody has been notified.

How an organisation becomes a Significant Data Fiduciary

Section 2(z) defines the term completely: a Significant Data Fiduciary is "any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10". There is no self assessment, no registration and no threshold you can compute for yourself. Section 10(1) sets the mechanics: the government notifies "on the basis of an assessment of such relevant factors as it may determine", including six the Act names verbatim:

  1. the volume and sensitivity of personal data processed
  2. risk to the rights of Data Principal
  3. potential impact on the sovereignty and integrity of India
  4. risk to electoral democracy
  5. security of the State
  6. public order

Two consequences are worth spelling out. First, the factors guide the government's assessment; they are not a scoring formula an organisation can apply to conclude it is or is not significant. Second, notification can name a single fiduciary or an entire class, so a sector wide notification is as possible as a company specific one. Until a notification covers you, the duties below do not attach.

The three obligations in section 10(2)

1. A Data Protection Officer based in India

Section 10(2)(a) requires the Significant Data Fiduciary to appoint a Data Protection Officer who shall "represent the Significant Data Fiduciary under the provisions of this Act", "be based in India", "be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary", and "be the point of contact for the grievance redressal mechanism under the provisions of this Act".

Read those four limbs together and the shape of the role is clear: an identified individual, physically in India, with a reporting line to the highest governing body, who fronts the organisation both toward the law and toward aggrieved Data Principals. The Act ties the defined term to this tier: section 2(l) defines Data Protection Officer as "an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10". Other Data Fiduciaries may choose to appoint someone with that job title, but the statutory office exists only for notified fiduciaries.

2. An independent data auditor

Section 10(2)(b) requires the Significant Data Fiduciary to "appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act". The text asks for two things at once: independence, and an evaluation measured against the Act itself rather than against internal policy.

3. Periodic DPIA and periodic audit

Section 10(2)(c) requires the Significant Data Fiduciary to undertake a "periodic Data Protection Impact Assessment", a "periodic audit", and "such other measures, consistent with the provisions of this Act, as may be prescribed". The Act defines the DPIA as a process comprising "a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals", plus other prescribed matters. Note that this is broader than a security review: the unit of analysis is the rights of the people whose data you process, not your infrastructure.

The word "periodic" and the phrase "as may be prescribed" are the hooks the Rules hang on. For the assessment itself, what it must contain, what has not been prescribed and how it differs from a GDPR style DPIA, see DPIA under the DPDP Act.

What Rule 13 adds

Rule 13 of the DPDP Rules 2025, headed Additional obligations of Significant Data Fiduciary, turns the Act's outline into a schedule and adds two duties the Act only hinted at.

An annual cycle. Rule 13(1) requires the DPIA and the audit "once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such". The clock starts at notification, not at a calendar year end.

A report to the Board. Rule 13(2) requires the Significant Data Fiduciary to cause the person carrying out the DPIA and audit "to furnish to the Board a report containing significant observations". The findings do not stay internal; the Data Protection Board of India sees them.

Algorithmic due diligence. Rule 13(3) requires due diligence to verify that "technical measures including algorithmic software" adopted for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data "are not likely to pose a risk to the rights of Data Principals". This is the only provision in the Act or the Rules that expressly names algorithmic software, and it applies to Significant Data Fiduciaries alone.

Conditional localisation. Rule 13(4) requires measures to ensure that personal data specified by the Central Government, on the recommendation of a committee it constitutes, is processed "subject to the restriction that the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India". No such specification exists yet; the restriction becomes real only when the committee route produces one. For precision: the printed Gazette text of the committee provision in Rule 13(5) reads "Ministry of Electronics and Technology", and the corrigendum G.S.R. 892(E) corrected only "Department" to "Departments" in that sub rule, leaving the ministry name as printed.

When these obligations commence

The definitions in section 2, including Significant Data Fiduciary and Data Protection Officer, have been in force since 13 November 2025. The obligations themselves have not: notification G.S.R. 843(E) places section 10 in the group that comes into force eighteen months from publication of the commencement gazette, and Rule 1(4) places Rule 13 in the matching eighteen month group of the Rules. Both compute to 13 May 2027, which is interpretation until officially confirmed.

Has any Significant Data Fiduciary been notified?

No. As of the 23 August 2026 verification, the dpdprules.org source registry and timeline record no notification of any Data Fiduciary or class as significant. Any list of named companies you see elsewhere is prediction, not law. What the factors in section 10(1) do tell you is the direction of travel: organisations processing personal data at high volume or high sensitivity should treat notification as plausible and read what changes if you are notified, because a board level DPO, an audit relationship and a working DPIA process take quarters to stand up, not weeks.

What to do now

Start by confirming what you are: the role tool walks the statutory definitions. Then generate your obligations with the company compliance plan, where the Significant Data Fiduciary cycle appears as conditional actions clearly marked as applying only if notified. The official texts live at section 10 and Rule 13, each with its Gazette citation.

Section 10, official textRule 13, official textSignificant Data Fiduciary: what changes if you are notified

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 10: notification of Significant Data Fiduciaries on the listed factors, and the additional obligations in section 10(2). Section 10 begins on Gazette page 8 and concludes on page 9.
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2, p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 2(l) defines Data Protection Officer as an individual appointed by the Significant Data Fiduciary under section 10(2)(a); section 2(z) defines Significant Data Fiduciary as any Data Fiduciary or class notified under section 10. Section 2 begins on Gazette page 2 and concludes on page 3; clause (l) appears on page 2 and clause (z) on page 3.
  3. [3]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 13: the twelve month DPIA and audit cycle, the report of significant observations to the Board, algorithmic due diligence, and the localisation restriction for personal data specified on a committee recommendation. The printed text of sub rule (5) reads "Ministry of Electronics and Technology" and is reproduced as printed.
  4. [4]Corrigenda to the Digital Personal Data Protection Rules, 2025 (G.S.R. 892(E)), (ii), p. 1. Published 11 December 2025. Official source ↗ · Official requirement · Verified 23 August 2026Corrigendum G.S.R. 892(E) item (ii) corrects "Department" to "Departments" in Rule 13(5) at Gazette page 29 line 44.
  5. [5]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The statement that Rule 13(3) is the only provision expressly naming algorithmic software reflects the dpdprules.org provision registry, which ingests the full Gazette texts of the Act and the DPDP Rules 2025 as corrected: the word algorithmic appears nowhere else in either text, as of the 23 August 2026 verification.
  6. [6]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Notification G.S.R. 843(E) names section 10 in the group that comes into force eighteen months from the date of publication of the notification gazette.
  7. [7]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 1(4) places Rule 13 in the group of rules that come into force eighteen months after publication.
  8. [8]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 May 2027 for section 10 is computed from the publication date printed on Gazette issue No. 757 and is presented as interpretation until officially confirmed.
  9. [9]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 May 2027 for Rule 13 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.
  10. [10]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The statement that no Significant Data Fiduciary has been notified reflects the dpdprules.org source registry and timeline, which record no such notification as of the 23 August 2026 verification. Under sections 2(z) and 10(1), the status exists only by Central Government notification.

significant data fiduciarydata protection officerdpiaauditrule 13

Share this: