Significant Data Fiduciaries
The Central Government may notify a Data Fiduciary or class as a Significant Data Fiduciary (SDF) after assessing factors including data volume/sensitivity, risk to Principal rights, sovereignty and integrity, electoral democracy, State security and public order. Volume or brand size alone does not create legal SDF status.
No SDF class notification was located in the primary-source pass ending 29 July 2026. The product
may show readiness_candidate; only a captured notification can set legally_designated.
Obligations
Section titled “Obligations”Section 10 requires:
- a Data Protection Officer who represents the SDF, is based in India, reports to the board or similar governing body and is the grievance point of contact;
- an independent data auditor;
- periodic DPIAs, periodic audits and prescribed additional measures.
Rule 13 adds:
- DPIA and audit once in every twelve months from designation/inclusion;
- significant observations furnished to the Board;
- due diligence that technical measures, including algorithmic software used in processing, are not likely to risk Principal rights;
- restrictions on transfer outside India for personal data and related traffic data specified by the Central Government on committee recommendation.
Product record
Section titled “Product record”SdfDesignation tenant_id, entity_id, status notification_source_id, notified_class, effective_at dpo_person_id, india_location_evidence governing_body_route, independent_auditor_id annual_cycle_anchor, next_dpia_at, next_audit_at algorithmic_system_ids[], localisation_policy_ids[] significant_observation_reports[], reviewer_idDPIA minimum
Section titled “DPIA minimum”Describe the processing and Principal rights, assess necessity and risk, map data/recipients, identify child or vulnerable populations, evaluate safeguards, record residual risk and obtain accountable approval. A change to purpose, model, population, country, large-scale dataset or incident triggers reassessment rather than waiting for the annual cycle.
Algorithmic due diligence
Section titled “Algorithmic due diligence”Inventory models, decision rules, recommender systems and automated classifiers involved in hosting, display, upload, modification, publication, transmission, storage, update or sharing. Record purpose, training/input data, affected population, human review, security, bias/performance tests, explainability limits, drift and remediation. OpenDPDP does not certify a model as “safe.”
Localisation
Section titled “Localisation”Rule 13(4) is not a universal current localisation mandate. It depends on SDF designation and government-specified personal data. The control supports policy-as-code for storage, traffic data, keys, logs, support access and backup, but remains inactive until a source instrument and data scope are recorded. Sector localisation may already apply independently.
Acceptance tests
Section titled “Acceptance tests”- Given a large organisation without a notification, when an admin selects SDF, then the status is
readiness_candidate, notlegally_designated. - Given designation on 15 January, when the annual clock is configured, then DPIA/audit due dates anchor to that date and changes can trigger earlier review.
- Given no specified data notification, then the platform cannot assert a DPDP localisation scope.