Heightened SDF Obligations
Section 10 of the DPDP Act empowers the Central Government to designate any Data Fiduciary — or class of Data Fiduciaries — as a Significant Data Fiduciary (SDF). Designation triggers four additional, non-trivial obligations.
First, appointment of a Data Protection Officer based in India, who is an employee of the SDF and reports to the board or a designated director. This is a full-time senior role, not a hat worn by the general counsel.
Second, appointment of an independent Data Auditor to evaluate compliance with the Act, with results reportable to the Board.
Third, periodic Data Protection Impact Assessments for any new processing activity that presents elevated risk to Data Principals.
Fourth, periodic independent audits, algorithmic-fairness assessments where automated decision-making is used at scale, and any other measures the Central Government notifies.
Designation Factors
Designation is discretionary and is based on factors listed in Section 10(1): the volume and sensitivity of personal data processed; the risk to the rights of Data Principals; the potential impact on the sovereignty and integrity of India; risk to electoral democracy; security of the State; and public order.
In practice, early designations are likely to target large consumer internet platforms, telecom operators, financial services (banks, NBFCs, PA/PGs, wallets), health-tech, ed-tech with large minor user bases, and AI/ML platforms doing large-scale automated decision-making. Any business processing more than a few million Indian users' data should assume it is a candidate.
Why Adopt SDF-Grade Governance Early
Even without formal designation, adopting SDF-grade governance early is a strong signal to investors, enterprise buyers and regulators. A named DPO, a documented DPIA process, and an annual independent audit — mapped to ISO 27701 or BS 10012 — are increasingly baseline requirements in enterprise procurement checklists and Series B+ diligence.
It is also materially cheaper than retrofitting. Building consent, rights-handling and audit trails into your data platform in the first two years costs a fraction of untangling a mature but non-compliant stack under regulator pressure.
If you receive a designation notice, you typically have a 90-day implementation window. Use the intervening months to run a mock designation exercise and identify gaps.
Putting DPDP on the Board Agenda
Quarterly board reporting should cover: personal data inventory changes, rights requests received and resolved, breaches and near-misses, vendor risk assessments completed, DPIA outcomes, training completion rates, and regulatory correspondence. This structure works whether you are an SDF or aspiring to that standard.
We help boards build this reporting cadence and act as an outsourced DPO for early-stage companies not yet ready to hire full-time. Book a consultation to discuss what a right-sized programme looks like for your business.
Have questions on this topic?
Book a confidential consultation with Vrushali Borade.
Book Consultation