Skip to main content

Sources last verified on 20 August 2026. Methodology

Tag

audit

Compliance

Additional obligations of a Significant Data Fiduciary: DPO, auditor, DPIA

What section 10 of the DPDP Act adds once the Central Government notifies you as a Significant Data Fiduciary: an India based Data Protection Officer answerable to the board, an independent data auditor, and an annual DPIA and audit cycle under Rule 13, every claim cited to the Gazette text.

Compliance

DPIA under the DPDP Act: who must do one, what it contains, when it starts

Who must run a Data Protection Impact Assessment under India's DPDP Act: only notified Significant Data Fiduciaries, on the twelve month cycle in Rule 13, with a report of significant observations to the Data Protection Board. What section 10(2)(c) actually defines, what has not been prescribed, and the GDPR Article 35 habits that do not carry over, every DPDP claim cited to the Gazette text.