Significant Data Fiduciary: what changes if you are notified
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 4 min read
What is a Significant Data Fiduciary and is there a user or revenue threshold?
The short answer
A Significant Data Fiduciary is any Data Fiduciary or class the Central Government notifies as such under section 10 once that section is in force, on an assessment of such relevant factors as it may determine, including volume and sensitivity of data, risk to Data Principal rights, potential impact on sovereignty and integrity, risk to electoral democracy, security of the State and public order. No numeric threshold exists in the official text: the Act sets no user count, revenue figure or employee number for SDF status, and no Data Fiduciary or class had been notified as an SDF as of 23 August 2026. Vendor checklists quoting 50 lakh users or revenue triggers have no basis in the official text; the only registered user thresholds in the framework sit in the Third Schedule and govern retention clocks under Rule 8, not SDF status. Once notified, and from section 10's computed commencement date of 13 May 2027, interpretation until officially confirmed, an SDF must appoint an India based Data Protection Officer answerable to its board, appoint an independent data auditor, and run a Data Protection Impact Assessment and audit every 12 months.

Most obligations in the framework apply to every Data Fiduciary. This tier is different: it arrives by name. And because it arrives by name, the internet has filled the waiting period with invented thresholds. This article gives you the factors the Act actually lists, the numbers that actually exist in the framework, and what changes on the day a notification lands.
How you become one: factors, not thresholds
Section 10 lets the Central Government notify any Data Fiduciary or class as significant, on an assessment of factors the Act lists. The glossary entry for Significant Data Fiduciary carries the section 2(z) definition of the term with its citation. In the Act's own words:
"The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including— (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order."
Section 10(1) of the DPDP Act 2023.
Read that list again: not one factor has a number attached. No registered user count, no transaction volume, no revenue figure, no employee headcount. The government assesses; it does not measure you against a published scale. Until a notification names you or your class, the additional duties below do not attach, and there is nothing to self certify into or out of. As of 23 August 2026, no Data Fiduciary or class has been notified.
The thresholds you see quoted online, corrected
Compliance vendors publish SDF "risk checklists" with lines like 50 lakh registered users, ten million monthly transactions or Rs 250 crore revenue. None of those numbers appears in section 10 or anywhere else as an SDF criterion. Most of them are recycled from a real table that does something else entirely: the Third Schedule to the Rules, which fixes retention clocks, not significance.
| The number | Where it actually appears | What it actually does | SDF trigger? |
|---|---|---|---|
| 2 crore registered users (ecommerce entity) | Third Schedule, read with Rule 8 | Starts a 3 year retention clock: personal data is deemed no longer needed 3 years from the latest of the person last approaching the fiduciary, the person exercising her rights, or the commencement of the Rules | No |
| 50 lakh registered users (online gaming intermediary) | Third Schedule, read with Rule 8 | Same 3 year retention clock for gaming platforms | No |
| 2 crore registered users (social media intermediary) | Third Schedule, read with Rule 8 | Same 3 year retention clock for social media | No |
| Revenue, transaction or employee thresholds | Nowhere in the Act or the Rules | Nothing | No |
If your organisation crosses a Third Schedule threshold, you will owe the Rule 8 erasure clocks once Rule 8 commences with the 18 month group, including at least 48 hours notice to the person before erasure. That is a real, dated duty. It is not SDF status.
The numbers that do exist for SDFs
| Number | What it is | Source |
|---|---|---|
| 12 months | The DPIA and audit cycle: once in every period of 12 months from the notification naming you | Rule 13 |
| Rs 150 crore | The Schedule's penalty cap for breaching the section 10 obligations | The Schedule to the Act, read with section 33 |
| 13 May 2027 | Computed commencement of section 10 and Rule 13, interpretation until officially confirmed | G.S.R. 843(E) and Rule 1(4) |
What changes once notified
The Act requires three appointments and practices. A Data Protection Officer who represents you, is based in India, answers to your board of directors or equivalent, and is the contact point for grievance redressal. An independent data auditor who evaluates your compliance. And periodic Data Protection Impact Assessments and audits.
Rule 13 turns the periodic into a cycle: a DPIA and an audit once every 12 months from notification, with the person conducting them reporting significant observations to the Board. It adds due diligence that algorithmic software you use for processing does not risk Data Principal rights, and a localisation duty for any personal data the government specifies on a committee's recommendation, restricting transfer of that data and related traffic data outside India. The full duty list is unpacked here.
An honest self assessment
Since the factors carry no numbers, the useful question is not "are we over the line" but "would an assessor pause on us". As a practical recommendation, walk your data map against the 6 statutory factors:
- Volume and sensitivity. How many people, and does the data include financial, health or children's data?
- Risk to rights. Would a breach or misuse materially harm the people in your data?
- Sovereignty and integrity, security of the State. Do you hold data with national security relevance, such as critical infrastructure or defence adjacent data?
- Electoral democracy. Could your platform or data influence voters at scale?
- Public order. Could misuse of your service plausibly affect public order?
Several yes answers do not make you an SDF; they make early preparation rational, because the DPIA muscle, the audit trail and the board level reporting take quarters to stand up, not weeks.
What to do
The SDF cycle is a conditional action in the company plan, clearly marked as applying only if notified. The official texts live at Rule 13, the Third Schedule and the Act's section 10, and when a notification does land, the timeline will record it with the primary source the day we verify it.