Rule 12Significant Data Fiduciary Obligations
Data Protection Impact Assessment and audit
What the Rule sets out
Requires a Significant Data Fiduciary to conduct a Data Protection Impact Assessment and an independent data audit at least annually, covering the proportionality of processing to the stated purpose, and to report significant observations to the Board.
What this means in practice
- Build an annual DPIA/audit cycle into your compliance calendar now if you're a plausible SDF candidate — waiting for formal notification leaves too little runway.
Summarised for practical use from the publicly notified DPDP Rules, 2025. Confirm exact clause text against the official Gazette notification before relying on it for compliance decisions.