Home / Act 2023 / Sections / Sec. 10
Sec. 10 · Chapter II · DPDP Act 2023

The Significant Data Fiduciary

One paragraph, one notice, and your compliance floor rises. Here is the six-factor test the Central Government applies, and what changes for you the day you are named.

Verified 8 Sep 2026 DPDP Act 2023, Sec. 10 7 min read Also: Rules 12, 13

01What Section 10 says

Section 10 empowers the Central Government to designate you a Significant Data Fiduciary. Designation is by notice and can target you individually or an entire class you belong to.

Your obligations under Section 10(2) begin from the date the notice specifies. The bar for designation is not a rupee figure or a user count. It is a factor test the Government applies at its discretion. Six factors are named in the Act. The Government reserves the right to weigh more.

Digital Personal Data Protection Act, 2023, Section 10(1) and 10(2). Gazette of India, 11 August 2023.

02The Government weighs six factors, and none of them is a numeric threshold

Section 10(1) lists factors the Central Government must consider before designating you. The Act is careful not to set a rupee-turnover or user-count trigger. This is a discretionary designation, and MeitY has kept that discretion deliberately wide.

The volume and sensitivity factor is the most-cited but also the most-misread. A 200-million-user consumer app that only handles email addresses may not qualify. A 5-million-user app that handles biometric identifiers might. Category weighs heavier than raw scale.

The next factor is risk to Data Principal rights. This is aimed at the kinds of automated systems that can quietly deny a right without the person even knowing. Opaque credit scoring, algorithmic hiring filters, automated content-moderation stacks at platform scale.

Then comes impact on the sovereignty and integrity of India. Read this as a hook for foreign-owned data operators with big Indian user bases and for cross-border data brokers. It is broadly drafted on purpose.

Fourth, risk to electoral democracy. Political ad platforms and voter-data aggregators are the named examples in MeitY policy speeches going back to 2024. Expect early designations here once the Board is seated.

Fifth, risk to the security of the State. Telecom operators, critical-infrastructure data holders, and defence supply-chain aggregators sit under this factor.

Sixth, public order. Large communication platforms whose failure or misuse could disrupt public services (payments rails, ride-hailing at scale, national health messaging systems) fall in this category.

03How designation happens

You do not opt in. The Government issues a written notice.

The notice may target your entity by name, or an entire class you belong to. For example: "large social media intermediaries" or "consumer credit information companies." Your obligations under Section 10(2) begin from the date the notice specifies.

As of September 2026, no public designation has been issued. MeitY has floated the possibility of using SDF designations to impose targeted cross-border restrictions on specific data categories, ahead of any broader country-level restrictions under Section 16.

DPDP Act, Sec. 10(1). Notification history via MeitY circulars. Confirm current designation list on the Updates feed.

04What extra you owe as an SDF

Section 10(2), read with Rules 12 and 13 of the DPDP Rules 2025, adds four categories of obligation on top of everything a Data Fiduciary already owes. All four come into force on 14 May 2027 when Rules 12 and 13 take effect.

Rule 12(1)

India-resident DPO

You must appoint a Data Protection Officer, resident in India, who reports to the Board of Directors or an equivalent governing body. The DPO is the point of contact for the Data Protection Board.

Rule 12(1)

Annual DPIA

Data Protection Impact Assessment on every high-risk processing activity, once every twelve months at minimum. The DPIA report must be submitted to the Board.

Rule 12(1)

Independent audit

External compliance audit by a qualified data auditor, once every twelve months. The audit report goes to the Data Protection Board.

Rule 13

Algorithm due diligence

You must verify that the algorithmic software you deploy to host, display, upload, modify, publish, transmit, store, update or share personal data does not pose a risk to Data Principals' rights.

05The Rule 12(4) cross-border twist

Rule 12(4) allows the Central Government to restrict cross-border transfer of specific data categories for SDFs alone.

Even under Section 16's negative-list default (all transfers permitted unless specifically restricted), Rule 12(4) gives the Government a targeted lever. It can identify a category of personal data that SDFs process, based on a committee's recommendation, and require that data to stay in India. This is de facto sectoral localisation without touching Section 16.

No such category has been notified as of September 2026. Financial identifiers, health identifiers, and biometric identifiers are the categories most often flagged in industry consultation. If you are on track to be designated an SDF, plan for the possibility that at least one high-sensitivity category will need to remain in India.

Rule 12(4) DPDP Rules 2025 (effective 14 May 2027). Read with Sec. 16 of the Act.

06Who has been designated so far

As of September 2026, no public list of designated Significant Data Fiduciaries has been issued by MeitY. Industry expectation is that the first designations will follow the seating of the Data Protection Board, currently pending Chairperson and four Member appointments (applications invited on 6 May 2026, follow-up on 6 June 2026). Watch the Updates feed for the first notification.

Classes most likely to be designated first, based on industry commentary and the six-factor test: large social media intermediaries (Meta, X, YouTube), consumer credit information companies (CIBIL, Experian, Equifax, CRIF), large payment aggregators (Razorpay, PayU, Cashfree), UPI apps (Google Pay, PhonePe, Paytm), and large e-commerce marketplaces (Amazon, Flipkart, Meesho).

Running DPIAs and audits at SDF scale? dcomply ships the SDF Determination, DPIA and Audit Register modules that map to Rules 12 and 13. See how →