The Significant Data Fiduciary
One paragraph, one notice, and your compliance floor rises. Here is the six-factor test the Central Government applies, and what changes for you the day you are named.
01What Section 10 says
Section 10 empowers the Central Government to designate you a Significant Data Fiduciary. Designation is by notice and can target you individually or an entire class you belong to.
Your obligations under Section 10(2) begin from the date the notice specifies. The bar for designation is not a rupee figure or a user count. It is a factor test the Government applies at its discretion. Six factors are named in the Act. The Government reserves the right to weigh more.
02The Government weighs six factors, and none of them is a numeric threshold
Section 10(1) lists factors the Central Government must consider before designating you. The Act is careful not to set a rupee-turnover or user-count trigger. This is a discretionary designation, and MeitY has kept that discretion deliberately wide.
The volume and sensitivity factor is the most-cited but also the most-misread. A 200-million-user consumer app that only handles email addresses may not qualify. A 5-million-user app that handles biometric identifiers might. Category weighs heavier than raw scale.
The next factor is risk to Data Principal rights. This is aimed at the kinds of automated systems that can quietly deny a right without the person even knowing. Opaque credit scoring, algorithmic hiring filters, automated content-moderation stacks at platform scale.
Then comes impact on the sovereignty and integrity of India. Read this as a hook for foreign-owned data operators with big Indian user bases and for cross-border data brokers. It is broadly drafted on purpose.
Fourth, risk to electoral democracy. Political ad platforms and voter-data aggregators are the named examples in MeitY policy speeches going back to 2024. Expect early designations here once the Board is seated.
Fifth, risk to the security of the State. Telecom operators, critical-infrastructure data holders, and defence supply-chain aggregators sit under this factor.
Sixth, public order. Large communication platforms whose failure or misuse could disrupt public services (payments rails, ride-hailing at scale, national health messaging systems) fall in this category.
03How designation happens
You do not opt in. The Government issues a written notice.
The notice may target your entity by name, or an entire class you belong to. For example: "large social media intermediaries" or "consumer credit information companies." Your obligations under Section 10(2) begin from the date the notice specifies.
As of September 2026, no public designation has been issued. MeitY has floated the possibility of using SDF designations to impose targeted cross-border restrictions on specific data categories, ahead of any broader country-level restrictions under Section 16.
04What extra you owe as an SDF
Section 10(2), read with Rules 12 and 13 of the DPDP Rules 2025, adds four categories of obligation on top of everything a Data Fiduciary already owes. All four come into force on 14 May 2027 when Rules 12 and 13 take effect.
India-resident DPO
You must appoint a Data Protection Officer, resident in India, who reports to the Board of Directors or an equivalent governing body. The DPO is the point of contact for the Data Protection Board.
Annual DPIA
Data Protection Impact Assessment on every high-risk processing activity, once every twelve months at minimum. The DPIA report must be submitted to the Board.
Independent audit
External compliance audit by a qualified data auditor, once every twelve months. The audit report goes to the Data Protection Board.
Algorithm due diligence
You must verify that the algorithmic software you deploy to host, display, upload, modify, publish, transmit, store, update or share personal data does not pose a risk to Data Principals' rights.
05The Rule 12(4) cross-border twist
Rule 12(4) allows the Central Government to restrict cross-border transfer of specific data categories for SDFs alone.
Even under Section 16's negative-list default (all transfers permitted unless specifically restricted), Rule 12(4) gives the Government a targeted lever. It can identify a category of personal data that SDFs process, based on a committee's recommendation, and require that data to stay in India. This is de facto sectoral localisation without touching Section 16.
No such category has been notified as of September 2026. Financial identifiers, health identifiers, and biometric identifiers are the categories most often flagged in industry consultation. If you are on track to be designated an SDF, plan for the possibility that at least one high-sensitivity category will need to remain in India.
06Who has been designated so far
As of September 2026, no public list of designated Significant Data Fiduciaries has been issued by MeitY. Industry expectation is that the first designations will follow the seating of the Data Protection Board, currently pending Chairperson and four Member appointments (applications invited on 6 May 2026, follow-up on 6 June 2026). Watch the Updates feed for the first notification.
Classes most likely to be designated first, based on industry commentary and the six-factor test: large social media intermediaries (Meta, X, YouTube), consumer credit information companies (CIBIL, Experian, Equifax, CRIF), large payment aggregators (Razorpay, PayU, Cashfree), UPI apps (Google Pay, PhonePe, Paytm), and large e-commerce marketplaces (Amazon, Flipkart, Meesho).