Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Significant Data Fiduciary: what changes if you are notified

Compliance

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 4 min read

What is a Significant Data Fiduciary and is there a user or revenue threshold?

The short answer

A Significant Data Fiduciary is any Data Fiduciary or class the Central Government notifies as such under section 10 once that section is in force, on an assessment of such relevant factors as it may determine, including volume and sensitivity of data, risk to Data Principal rights, potential impact on sovereignty and integrity, risk to electoral democracy, security of the State and public order. No numeric threshold exists in the official text: the Act sets no user count, revenue figure or employee number for SDF status, and no Data Fiduciary or class had been notified as an SDF as of 23 August 2026. Vendor checklists quoting 50 lakh users or revenue triggers have no basis in the official text; the only registered user thresholds in the framework sit in the Third Schedule and govern retention clocks under Rule 8, not SDF status. Once notified, and from section 10's computed commencement date of 13 May 2027, interpretation until officially confirmed, an SDF must appoint an India based Data Protection Officer answerable to its board, appoint an independent data auditor, and run a Data Protection Impact Assessment and audit every 12 months.

More answered questions →

Summary infographic headed 'If you are a Significant Data Fiduciary: what changes if you are notified'
The infographic states that the status comes by Central Government notification and is not automatic, that it reflects higher volume, sensitivity or risk in the processing, that the extra duties typically include a Data Protection Officer in India, a data auditor, a Data Protection Impact Assessment and periodic audits, and that tighter governance, documentation and oversight follow. An arrow marked government notification points at an organisation, from which those 4 duties branch.

Most obligations in the framework apply to every Data Fiduciary. This tier is different: it arrives by name. And because it arrives by name, the internet has filled the waiting period with invented thresholds. This article gives you the factors the Act actually lists, the numbers that actually exist in the framework, and what changes on the day a notification lands.

How you become one: factors, not thresholds

Section 10 lets the Central Government notify any Data Fiduciary or class as significant, on an assessment of factors the Act lists. The glossary entry for Significant Data Fiduciary carries the section 2(z) definition of the term with its citation. In the Act's own words:

DPDP Act 2023, s. 10 · Additional obligations of Significant Data Fiduciary · verbatim

"The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including— (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order."

Section 10(1) of the DPDP Act 2023.

Read that list again: not one factor has a number attached. No registered user count, no transaction volume, no revenue figure, no employee headcount. The government assesses; it does not measure you against a published scale. Until a notification names you or your class, the additional duties below do not attach, and there is nothing to self certify into or out of. As of 23 August 2026, no Data Fiduciary or class has been notified.

The thresholds you see quoted online, corrected

Compliance vendors publish SDF "risk checklists" with lines like 50 lakh registered users, ten million monthly transactions or Rs 250 crore revenue. None of those numbers appears in section 10 or anywhere else as an SDF criterion. Most of them are recycled from a real table that does something else entirely: the Third Schedule to the Rules, which fixes retention clocks, not significance.

The numberWhere it actually appearsWhat it actually doesSDF trigger?
2 crore registered users (ecommerce entity)Third Schedule, read with Rule 8Starts a 3 year retention clock: personal data is deemed no longer needed 3 years from the latest of the person last approaching the fiduciary, the person exercising her rights, or the commencement of the RulesNo
50 lakh registered users (online gaming intermediary)Third Schedule, read with Rule 8Same 3 year retention clock for gaming platformsNo
2 crore registered users (social media intermediary)Third Schedule, read with Rule 8Same 3 year retention clock for social mediaNo
Revenue, transaction or employee thresholdsNowhere in the Act or the RulesNothingNo

If your organisation crosses a Third Schedule threshold, you will owe the Rule 8 erasure clocks once Rule 8 commences with the 18 month group, including at least 48 hours notice to the person before erasure. That is a real, dated duty. It is not SDF status.

The numbers that do exist for SDFs

NumberWhat it isSource
12 monthsThe DPIA and audit cycle: once in every period of 12 months from the notification naming youRule 13
Rs 150 croreThe Schedule's penalty cap for breaching the section 10 obligationsThe Schedule to the Act, read with section 33
13 May 2027Computed commencement of section 10 and Rule 13, interpretation until officially confirmedG.S.R. 843(E) and Rule 1(4)

What changes once notified

The Act requires three appointments and practices. A Data Protection Officer who represents you, is based in India, answers to your board of directors or equivalent, and is the contact point for grievance redressal. An independent data auditor who evaluates your compliance. And periodic Data Protection Impact Assessments and audits.

Rule 13 turns the periodic into a cycle: a DPIA and an audit once every 12 months from notification, with the person conducting them reporting significant observations to the Board. It adds due diligence that algorithmic software you use for processing does not risk Data Principal rights, and a localisation duty for any personal data the government specifies on a committee's recommendation, restricting transfer of that data and related traffic data outside India. The full duty list is unpacked here.

An honest self assessment

Since the factors carry no numbers, the useful question is not "are we over the line" but "would an assessor pause on us". As a practical recommendation, walk your data map against the 6 statutory factors:

  1. Volume and sensitivity. How many people, and does the data include financial, health or children's data?
  2. Risk to rights. Would a breach or misuse materially harm the people in your data?
  3. Sovereignty and integrity, security of the State. Do you hold data with national security relevance, such as critical infrastructure or defence adjacent data?
  4. Electoral democracy. Could your platform or data influence voters at scale?
  5. Public order. Could misuse of your service plausibly affect public order?

Several yes answers do not make you an SDF; they make early preparation rational, because the DPIA muscle, the audit trail and the board level reporting take quarters to stand up, not weeks.

What to do

The SDF cycle is a conditional action in the company plan, clearly marked as applying only if notified. The official texts live at Rule 13, the Third Schedule and the Act's section 10, and when a notification does land, the timeline will record it with the primary source the day we verify it.

Rule 13, official text →The SDF duties in detail →

Significant Data FiduciaryDPIARule 13Thresholds

Share this: