Additional obligations of Significant Data Fiduciary
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, having regard to relevant factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
A Significant Data Fiduciary shall appoint a Data Protection Officer based in India, who shall be responsible to the Board of Directors or similar governing body and shall be the point of contact for grievance redressal.
A Significant Data Fiduciary shall appoint an independent data auditor to carry out data audits, and undertake periodic Data Protection Impact Assessments and other prescribed measures.
- SDF status is a designation applied by notification, not self-assessed — but the listed factors (scale, sensitivity, risk to democracy/security) give a strong signal of who is likely to be named.
- An SDF's DPO must sit in India and report to the top of the organisation, not to a regional compliance function abroad.
- Independent audits and DPIAs move an SDF from 'policy on paper' to demonstrable, periodically tested compliance.
Reconstructed for readability from the publicly notified DPDP Act, 2023. Always verify exact wording against the official Gazette of India before relying on this for legal or compliance decisions.