Skip to content

Significant Data Fiduciaries

DPDP — designation-dependent and not yet effective

The Central Government may notify a Data Fiduciary or class as a Significant Data Fiduciary (SDF) after assessing factors including data volume/sensitivity, risk to Principal rights, sovereignty and integrity, electoral democracy, State security and public order. Volume or brand size alone does not create legal SDF status.

No SDF class notification was located in the primary-source pass ending 29 July 2026. The product may show readiness_candidate; only a captured notification can set legally_designated.

Section 10 requires:

  • a Data Protection Officer who represents the SDF, is based in India, reports to the board or similar governing body and is the grievance point of contact;
  • an independent data auditor;
  • periodic DPIAs, periodic audits and prescribed additional measures.

Rule 13 adds:

  • DPIA and audit once in every twelve months from designation/inclusion;
  • significant observations furnished to the Board;
  • due diligence that technical measures, including algorithmic software used in processing, are not likely to risk Principal rights;
  • restrictions on transfer outside India for personal data and related traffic data specified by the Central Government on committee recommendation.
SdfDesignation
tenant_id, entity_id, status
notification_source_id, notified_class, effective_at
dpo_person_id, india_location_evidence
governing_body_route, independent_auditor_id
annual_cycle_anchor, next_dpia_at, next_audit_at
algorithmic_system_ids[], localisation_policy_ids[]
significant_observation_reports[], reviewer_id

Describe the processing and Principal rights, assess necessity and risk, map data/recipients, identify child or vulnerable populations, evaluate safeguards, record residual risk and obtain accountable approval. A change to purpose, model, population, country, large-scale dataset or incident triggers reassessment rather than waiting for the annual cycle.

Inventory models, decision rules, recommender systems and automated classifiers involved in hosting, display, upload, modification, publication, transmission, storage, update or sharing. Record purpose, training/input data, affected population, human review, security, bias/performance tests, explainability limits, drift and remediation. OpenDPDP does not certify a model as “safe.”

Rule 13(4) is not a universal current localisation mandate. It depends on SDF designation and government-specified personal data. The control supports policy-as-code for storage, traffic data, keys, logs, support access and backup, but remains inactive until a source instrument and data scope are recorded. Sector localisation may already apply independently.

  • Given a large organisation without a notification, when an admin selects SDF, then the status is readiness_candidate, not legally_designated.
  • Given designation on 15 January, when the annual clock is configured, then DPIA/audit due dates anchor to that date and changes can trigger earlier review.
  • Given no specified data notification, then the platform cannot assert a DPDP localisation scope.