Significant Data Fiduciary Notifications: Who's Likely to Be Named
Section 10 lets the government single out certain Data Fiduciaries for heightened obligations. The criteria are known; the actual list, at this stage, largely isn't.
The statutory test
Section 10 of the DPDP Act allows the central government to notify any Data Fiduciary, or class of Data Fiduciaries, as a Significant Data Fiduciary, having regard to relevant factors including the volume and sensitivity of personal data processed, the risk of harm to Data Principals, the potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the state, and public order. The test is deliberately multi-factor rather than a single bright-line threshold, such as a fixed user count or revenue figure.
This drafting choice gives the government considerable flexibility to designate fiduciaries based on the practical risk profile of their data processing rather than a mechanical size test, but it also means the designation is not fully predictable from the Act's text alone.
What the designation adds
A Significant Data Fiduciary faces obligations beyond the general baseline, including appointing a Data Protection Officer based in India who reports to the fiduciary's board or equivalent governing body, appointing an independent data auditor, and undertaking periodic data protection impact assessments and audits. Non-compliance specifically tied to the Significant Data Fiduciary obligations carries its own penalty ceiling in the Schedule, reported at up to roughly 150 crore, separate from the general non-compliance ceiling.
In effect, the designation converts a subset of the Act's obligations from optional good practice into mandatory, audited requirements, which is a meaningful step up in compliance cost and governance overhead for any organisation named.
Who is plausibly in scope, and the limits of forecasting this
Reading the statutory factors together, organisations that process very large volumes of personal data, operate platforms with significant reach among Indian users, process data with plausible implications for public order or state security, or sit in data-intensive sectors like large digital platforms, telecom, and certain financial services, are the kinds of entities most commonly discussed as likely candidates for Significant Data Fiduciary status. This is informed speculation grounded in the statutory criteria, not a confirmed list.
At the time of writing, no confirmed, finalised public list of Significant Data Fiduciary designations under the DPDP Act had been established with enough certainty to enumerate here, and any specific claim about which named companies have been designated should be treated with caution until confirmed through an official MeitY notification. Organisations that plausibly meet the statutory factors would be well served by preparing for the added obligations proactively rather than waiting for a notification to force the issue.
Where to go next
Use the Applicability Checker to see whether your organisation's data volume and risk profile plausibly falls within the Section 10 factors, and track confirmed designations through the notification-monitoring approach described in the companion guide on tracking MeitY notifications.