Summary

  • Significant Data Fiduciaries (SDFs) are entities having additional obligations under the DPDP Act because they handle large volumes of personal data, or process sensitive personal data. For example: banks, health tech companies, large social media platforms.
  • SDFs have these additional obligations: appointing a Data Protection Officer, appointing an independent data auditor, and running an annual Data Protection Impact Assessment and audit.
  • The DPDP Rules requires SDFs to undertake algorithmic due diligence, and a data-localisation restriction for data categories the government specifies.
  • SDFs are classified and notified by the Central Government, based on data volume, sensitivity, risk to individuals, and impact on national interests.
  • The penalty for breaching SDF obligations runs up to ₹150 crore per instance.
Close Button

Significant Data Fiduciary under DPDP Act

Anahad Narain

Founder's Office
August 21, 2026

Summary

  • Significant Data Fiduciaries (SDFs) are entities having additional obligations under the DPDP Act because they handle large volumes of personal data, or process sensitive personal data. For example: banks, health tech companies, large social media platforms.
  • SDFs have these additional obligations: appointing a Data Protection Officer, appointing an independent data auditor, and running an annual Data Protection Impact Assessment and audit.
  • The DPDP Rules requires SDFs to undertake algorithmic due diligence, and a data-localisation restriction for data categories the government specifies.
  • SDFs are classified and notified by the Central Government, based on data volume, sensitivity, risk to individuals, and impact on national interests.
  • The penalty for breaching SDF obligations runs up to ₹150 crore per instance.

Summary

  • Significant Data Fiduciaries (SDFs) are entities having additional obligations under the DPDP Act because they handle large volumes of personal data, or process sensitive personal data. For example: banks, health tech companies, large social media platforms.
  • SDFs have these additional obligations: appointing a Data Protection Officer, appointing an independent data auditor, and running an annual Data Protection Impact Assessment and audit.
  • The DPDP Rules requires SDFs to undertake algorithmic due diligence, and a data-localisation restriction for data categories the government specifies.
  • SDFs are classified and notified by the Central Government, based on data volume, sensitivity, risk to individuals, and impact on national interests.
  • The penalty for breaching SDF obligations runs up to ₹150 crore per instance.

The DPDP Act creates a category for organisations that process data at a scale or sensitivity that carries national consequences — the Significant Data Fiduciary (SDF).

If your business handles the personal data of millions of users, processes financial or health records, or runs a platform that shapes public discourse, the government can notify you as an SDF. The penalties for SDFs are also higher - upto ₹150 crore for any breaching SDF obligations.

This blog explains: 

  • Who will be classified as a SDF? 
  • What are the obligations of SDFs under the Act and the DPDP Rules, 2025? 
  • What is the penalty for a breach by an SDF? 
  • How should SDFs prepare for DPDP compliance?

From breaches that affect millions to privacy violations that undermine national security, the stakes with SDFs are enormous.

Who will be classified as a 'Significant Data Fiduciary'?

Under Section 10 of the DPDP Act, the Central Government can notify a Data Fiduciary, or a class of Data Fiduciaries, as an SDF. 

Classification is based on the following factors:

  • Volume and sensitivity of personal data processed: Organisations handling vast amounts of data, or particularly sensitive data like financial, health, or biometric records, are prime candidates. 

Example: A health tech company processing patients' medical records, test results, and treatment plans processes highly sensitive data — another likely candidate.

  • Risk to the rights of Data Principals: Where processing by the organisation exposes individuals to heightened risk of harm. 

Example: A large bank storing the account balances, transaction history, and loan records of millions of customers holds data whose breach could cause widespread harm is a likely SDF candidate.

  • Risk to electoral democracy.

Example: A large social media platform can influence public discourse and electoral processes through the data it holds and the content it distributes — which is why platforms at scale are likely to be notified.

  • Potential impact on the sovereignty and integrity of India.
  • Security of the State.
  • Public order.

SDFs under GDPR

There is no direct equivalent to SDFs in the GDPR. 

However, under the GDPR high-risk processing is regulated i.e. the Data Protection Impact Assessments and appointment of Data Protection Officers are mandated for organisations handling sensitive data at scale. On the other hand, the DPDP Act regulates this on an organisation level by allowing the government to formally designate specific entities as SDFs. 

We cover the full comparison in DPDP vs GDPR.

‍

What are the Significant Data Fiduciary obligations?

Every Data Fiduciary must meet the general obligations under the Act - consent, notice, security safeguards, breach reporting, and Data Principal rights. (For the full list, see our DPDP Compliance Checklist.)

An SDF must meet these plus the following additional obligations:

1. Appointing a Data Protection Officer

An SDF must appoint a Data Protection Officer (DPO) who is 

  1. based in India and 
  2. is responsible to the Board of Directors or an equivalent governing body. 

The DPO is the point of contact for the grievance redressal mechanism under the Act, and represents the SDF for the purposes of the law. (Section 10(2)(a), DPDP Act)

2. Appoint an independent data auditor

An SDF must appoint an independent data auditor to carry out a data audit and evaluate the SDF's compliance with the Act. (Section 10(2)(b), DPDP Act)

3. Conduct an annual DPIA and audit

Under Rule 13 of the DPDP Rules, an SDF must undertake a Data Protection Impact Assessment (DPIA) and an audit once in every twelve-month period, counted from the date it is notified as an SDF. 

As per Section 10(2)(c) of the DPDP Act, a DPIA must: 

  • describe the rights of Data Principals and purpose of processing, and
  • assess and manage the risks that processing poses to those rights.

The SDF must ensure that a report of significant observations in the DPIA and audit are furnished to the Data Protection Board.

4. Carry out algorithmic due diligence

Under Rule 13(3), an SDF must observe due diligence to verify that the technical measures it uses - including algorithmic software - for hosting, display, uploading, modification, publishing, transmission, storage, updating, or sharing of personal data are not likely to pose a risk to the rights of Data Principals.

Practical implication: if you use algorithmic systems anywhere in your data processing pipeline, you need a documented process to periodically review them against the risk they pose to Data Principals' rights.

5. Observe the data-localisation restriction

Under Rule 13(4), the Central Government can specify categories of personal data that an SDF must not transfer outside India.

Practical implication: this is a hard localisation restriction for the specific data categories notified, and is separate from the general cross-border rule under Section 16 of the Act.

What is the penalty for an SDF breach?

Breach of the SDF obligations under Section 10 attracts a penalty of up to ₹150 crore per instance, imposed by the Data Protection Board following an inquiry. For the full breakdown, see our blog on penalties under the DPDP Act.

How to prepare for SDF-level compliance

If you suspect that you may be classified as an SDF, here are some steps you can take to prepare yourself:

  • Conduct a gap analysis: Conduct a gap analysis of your current data management practices against the DPDP Act and rules. This is the first step to getting compliant.
  • Appoint the right DPO early: The role is a legal requirement, but it also needs someone with the authority to monitor compliance across functions, handle breaches, and engage with the Board. Appoint them before you're notified.
  • Build the DPIA and audit into an annual cycle: The obligation is annual and recurring, so treat it as a standing process with defined owners, and keep the significant observations report ready for the Board.
  • Separate research and analytics data from operational systems: This keeps your algorithmic due diligence tractable and prevents research outputs from driving individual-level decisions. (See our blog on the research exception.)
  • Map your cross-border data flows now: You need to know which categories of data leave India, and where, so you can act quickly if the government specifies a localisation restriction.
  • Ensure your consent records are right: Consent is the foundation of DPDP compliance, and the volume of consent an SDF manages makes manual tracking untenable. Your system needs to record and track consent in a way that is verifiable and auditable. See how Consent.in handles this.

Compliance starts with understanding the law. If you're building your DPDP foundation, start with our DPDP Compliance Checklist.

Frequently Asked Questions (FAQs)

What is a Significant Data Fiduciary under the DPDP Act?
A Significant Data Fiduciary (SDF) is a Data Fiduciary, or class of Data Fiduciaries, notified as such by the Central Government under Section 10 of the DPDP Act. Classification is based on factors like data volume, sensitivity, and risk to Data Principals or national interests.

What is the difference between a Data Fiduciary and a Significant Data Fiduciary?
Every organisation that determines the purpose and means of processing personal data is a Data Fiduciary, and must meet the Act's general obligations. A Significant Data Fiduciary is a subset of Data Fiduciaries that the government formally notifies based on data volume, sensitivity, or risk, and must meet additional compliance requirements on top of the general ones.

Who decides which organisations are classified as SDFs?
The Central Government classifies and notifies SDFs, based on the volume and sensitivity of personal data processed, risk to the rights of Data Principals, and potential impact on electoral democracy, sovereignty, security of the State, or public order.

What are the Significant Data Fiduciary obligations under the DPDP Act?
An SDF must appoint a Data Protection Officer based in India, appoint an independent data auditor, conduct an annual DPIA and audit, carry out algorithmic due diligence, and observe any data-localisation restrictions specified by the government.

Who is the DPO of an SDF responsible to?
The DPO is responsible to the Board of Directors or an equivalent governing body of the SDF, and acts as the point of contact for the Act's grievance redressal mechanism.

How often must an SDF conduct a DPIA and audit?
Under Rule 13 of the DPDP Rules, an SDF must conduct a DPIA and audit once every twelve months, counted from the date it is notified as an SDF.

What is the penalty for an SDF breaching its obligations?
Breach of SDF obligations under Section 10 attracts a penalty of up to ₹150 crore per instance, imposed by the Data Protection Board following an inquiry.

Is there an equivalent to SDFs under the GDPR?
No. The GDPR regulates high-risk processing through requirements like DPIAs and DPOs, but doesn't have a mechanism for formally designating specific entities the way the DPDP Act does with SDFs.

 Note: This article is for informational purposes only and does not constitute legal advice. Consult your legal counsel for advice specific to your situation.

Explore Leegality Consent Manager for your Business

Schedule a Demo Call

Compliance Deadline:

0 weeks away