Significant Data Fiduciary (SDF): Section 10 Obligations and Are You One?
The DPDPA creates a tier of businesses facing the heaviest compliance obligations. Understanding whether you are, or are at risk of being classified as a Significant Data Fiduciary is urgent.

Organisations that process significant volumes of personal data in India should assess your exposure to the Significant Data Fiduciary framework. Under Section 10 of the DPDPA, the Central Government may notify a Data Fiduciary, or a class of Data Fiduciaries, as a Significant Data Fiduciary based on specified factors. An SDF designation carries additional obligations, which makes early assessment and preparation useful for organisations with large or sensitive data operations.
The DPDPA, 2023 establishes different obligations for Data Fiduciaries based on their designation under the Act. Every Data Fiduciary is subject to baseline obligations, regardless of scale. Significant Data Fiduciaries are subject to additional governance and compliance requirements on top of those baseline duties. For organisations with large-scale or sensitive data operations, understanding the criteria and preparing for potential designation can be an important part of DPDPA planning.
As the DPDPA framework develops, organisations should monitor regulatory developments and assess whether their activities may fall within the SDF framework.
How Is a Significant Data Fiduciary Designated?
Section 10 of the DPDPA gives the Central Government authority to designate a Data Fiduciary as a Significant Data Fiduciary based on specified factors. The factors considered include the volume and sensitivity of personal data processed, the risk to Data Principals, the potential impact on India's sovereignty and integrity, any risk to electoral democracy, security of the State, and public order.
The Act does not set a numerical threshold at which an organisation automatically becomes an SDF. Designation is made by the Central Government based on the factors above. Your organisation can use those factors as a readiness and risk-assessment framework, applied to your own data operations, instead of treating them as a self-certification test.
Organisations should monitor official notifications from the Central Government regarding SDF designations and the specific criteria that will be applied.
Which Organisations May Be Considered for SDF Designation?
The following types of organisations may have stronger reasons to assess their exposure to the SDF framework, depending on the nature and scale of their processing:
Examples of organisations whose activities may warrant closer assessment include:
Large consumer internet platforms with significant user bases
Banks and NBFCs handling substantial volumes of financial data
Healthcare platforms maintaining extensive patient records
Social media companies and digital content platforms
Loyalty programme operators running multi-brand databases with millions of members
Fintech platforms that process alternative data at scale
Organisations operating in these areas may benefit from assessing their data processing activities against the SDF designation criteria.
What Changes After SDF Designation?
SDF designation introduces additional governance and compliance obligations under Section 10 of the DPDPA, with the DPIA and audit cycle further detailed under Rule 13 of the DPDP Rules, 2025. Designated organisations are required to:
Appoint a Data Protection Officer based in India, who is responsible to the Board of Directors or equivalent governing body
Engage an independent Data Auditor to conduct periodic data audits, producing the kind of audit trail that DPDPA compliance audit trail software is designed to generate and preserve
Carry out a Data Protection Impact Assessment and an audit once every twelve months from the date of SDF notification, as required under Rule 13 of the DPDP Rules, 2025, with a report of significant observations submitted to the Data Protection Board
Organisations that may be subject to these obligations should understand how a Data Protection Impact Assessment (DPIA) works in practice and how it can be integrated into existing governance processes. Reviewing data protection impact assessment software India options at this stage can help organisations plan the DPIA and audit workflow before designation becomes a compliance deadline.
Conduct due diligence on algorithmic software used to process personal data, to verify it does not pose a risk to the rights of Data Principals
Observe any restrictions on transferring specified personal data, and related traffic data, outside India, where the Central Government designates particular categories of data for this treatment under Rule 13(4) of the DPDP Rules, 2025. This applies to specified categories only, not to all personal data an SDF processes.
Comply with additional requirements that the Central Government may prescribe from time to time
These requirements create ongoing governance and accountability responsibilities, not one-time compliance activities. The exact scope of each obligation should be verified against the current text of the Act and applicable Rules.
To understand this furthur, read this blog: Data Protection Impact Assessment (DPIA)
The DPO Requirement
The Data Protection Officer (DPO) requirement is an important part of the SDF governance framework. Organisations that may fall within the SDF framework should also understand the practical responsibilities, reporting structure and appointment requirements associated with a DPO under the DPDPA.
The DPO role requires an appropriate level of seniority, authority and access to senior management to perform the responsibilities established under the DPDPA. The DPO should have sufficient authority and organisational access to oversee data protection responsibilities, raise concerns and advise the organisation on compliance matters. The DPO is required to be responsible to the Board of Directors or equivalent governing body, as specified under the Act.
Read more about Data Protection Officer (DPO) under the DPDPA.
How Organisations Can Prepare Before SDF Designation
Organisations may therefore benefit from assessing their readiness before formal designation, particularly where their processing activities involve significant volumes or sensitive personal data. Organisations can begin strengthening the governance capabilities that may be required if they are designated as an SDF.
Specific actions organisations may consider include:
Establishing a DPO-equivalent privacy governance function with appropriate seniority and authority
Conducting periodic data governance or compliance assessments to identify potential gaps
Performing risk assessments on data-intensive processing activities to understand potential impacts on Data Principals
Building reporting structures and internal processes that would support SDF obligations
Establishing these capabilities in advance can reduce the operational burden associated with responding to new compliance requirements after designation.
Preparing for SDF Designation
SDF designation can introduce significant governance and compliance responsibilities for an organisation. Establishing appropriate data governance, accountability structures, audit processes and privacy expertise in advance, supported where useful by DPDPA data fiduciary compliance software, can help organisations respond more effectively if they are designated.
The key consideration for organisations with large-scale or sensitive data operations is to assess their position against the SDF criteria and prepare appropriate governance capabilities where necessary.
How OneConsent Supports SDF Readiness and Data Fiduciary Compliance
Organisations preparing for potential SDF designation need consent records, data-rights requests, DPIA documentation and audit evidence to stay organised across one traceable system, instead of scattered spreadsheets and email threads. OneConsent, a DPDPA consent management platform, helps organisations maintain structured consent records, manage related workflows, and keep compliance evidence audit-ready as governance obligations scale.
Request a demo today to see how OneConsent supports SDF readiness.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.