Skip to main content

Sources last verified on 27 August 2026. Methodology

Concept

Data Protection Officer

One named individual, and only a Significant Data Fiduciary has to appoint one. The definition does nothing on its own: it points at section 10(2)(a), which is where the duty and its 4 limbs live. Every other Data Fiduciary owes a different thing, publishing a contact under section 8(9) and Rule 9, with no appointment duty anywhere in either instrument.

Official requirement · verbatim

“Data Protection Officer” means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10

Read section 2 of the Act, where this term is defined →Rule 9 of the DPDP Rules 2025 →

Data Protection Officer under the DPDP Act: who must appoint one

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2(l), p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 17 August 2026