By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
A Significant Data Fiduciary (SDF) under the Digital Personal Data Protection Act, 2023 is not a status a business chooses — it is a designation the Central Government makes under Section 10 on risk-based factors, and once notified the fiduciary carries five extra statutory duties on top of the baseline that every Data Fiduciary carries: a board-answerable Data Protection Officer in India, an independent data auditor, an annual Data Protection Impact Assessment (DPIA) and audit with reporting to the Board, algorithmic due diligence, and a possible data-localisation direction for notified categories of data. No SDF class had been notified as of August 2026, which makes the current window the time to prepare, not the time to wait.
How does a business become an SDF?
The process is entirely governmental, which surprises teams that expect a registration threshold like significant social media intermediary status under the IT Rules. Under Section 10(1) DPDP Act the Central Government may notify any Data Fiduciary or class of Data Fiduciaries as an SDF having regard to:
- Volume and sensitivity of personal data processed.
- Risk to the rights of Data Principals.
- Potential impact on the sovereignty and integrity of India, electoral democracy, security of the State and public order.
The Government can notify by category — for example, all e-commerce entities above a user threshold, or all fiduciaries processing certain sensitive data — or by naming a specific fiduciary. Assessment is as the Government determines on the Section 10(1) factors.
The practical consequence for Kerala businesses is that SDF status is not limited to Big Tech. A healthtech handling health data (which is personal data of high sensitivity), a fintech processing financial data at volume, or an adtech platform whose profiling affects rights at scale could be designated as part of a class even without the headcount of a social media intermediary. The Kerala Startup Mission cohort — particularly startups that have scaled beyond Kerala to a pan-India user base — should assess SDF readiness as a risk scenario, not as a distant hypothetical.
What are the five extra SDF duties?
1. Data Protection Officer in India, answerable to the board
Under Section 10(2)(a) DPDP Act, a notified SDF must appoint a Data Protection Officer based in India who is the contact point for grievance redressal and who is answerable to the board of directors (or the governing body for non-corporate fiduciaries). The DPO is not a compliance-department delegate with an email alias — the statute places the role at board level so that data protection decisions have board visibility and accountability. The DPO details must be published under Section 8(9) (general fiduciary duty to publish business contact information) and must be the channel through which Data Principals can exercise their Section 13 grievance rights against the SDF.
2. Independent data auditor
Under Section 10(2)(b) and Rule 13, a notified SDF must appoint an independent data auditor — an external, qualified auditor, not an internal team — to audit its compliance with the Act and Rules. The independence requirement is substantive: an auditor who is also a vendor providing the SDF’s data-processing infrastructure would not satisfy the independence test. The auditor’s access must be sufficient to verify processing activities, security safeguards and cross-border handling, and the audit findings feed the DPIA and the Board reporting below.
3. Data Protection Impact Assessment and periodic audit — at least every 12 months
Under Section 10(2)(c) and Rule 13, a notified SDF must conduct a Data Protection Impact Assessment and a periodic audit and report significant observations to the Data Protection Board of India. The periodicity is at least once every 12 months from the date of notification as an SDF (or from the previous assessment). The DPIA must assess the risks of the SDF’s processing to Data Principal rights, the safeguards in place, and the effectiveness of security and governance controls. Rule 13 requires that the significant observations from the DPIA and audit be placed before the Board — not merely retained internally — so the assessment has regulatory visibility from the start.
4. Algorithmic due diligence
Under Rule 13(3) DPDP Rules, 2025, an SDF must undertake due diligence to verify that its algorithms and other technical means do not pose risks to the rights of Data Principals. For Kerala businesses building recommendation, pricing, hiring, credit-scoring or content-moderation algorithms, this is the provision that connects data protection to AI governance: a model that profiles or ranks individuals using personal data must be checked that it does not discriminate, misclassify or otherwise infringe rights. The duty complements — but is separate from — the IT Amendment Rules, 2026 duties on synthetically generated information and the emerging AI governance discussion at MeitY.
5. Possible data-localisation direction
Under Rule 13(4) DPDP Rules, 2025 read with Rule 15, the Central Government may, on the recommendation of a committee constituted for Rule 13, direct a notified SDF to ensure that such personal data and associated traffic data as it specifies is not transferred outside India and is kept within India. No such specification had been made as of August 2026. The general DPDP position on cross-border transfer under Section 16 and Rule 15 is permissive by default — transfer is allowed unless the Government by notification restricts flows to specific countries — but the SDF localisation power under Rule 13(4) is an additional, targeted power that can require an SDF to keep notified data categories in India even where Section 16 would otherwise permit transfer. For a full treatment of cross-border rules, see the cross-border data transfer guide.
What stays the same — the baseline every fiduciary carries regardless of SDF status?
SDF duties are additive. Every Data Fiduciary, whether or not notified as significant, must from May 2027 (the 18-month tranche of the DPDP Rules, G.S.R. 846(E), 13 November 2025) comply with:
- Section 5 notice — itemised, plain-language notice before consent, in English and Eighth Schedule languages chosen by the Data Principal, including Malayalam for Kerala users.
- Section 6 consent — free, specific, informed, unconditional and unambiguous consent by clear affirmative action, with withdrawal as easy as giving it, and the fiduciary bearing the burden of proof under Section 6(10).
- Section 8 security and breach — reasonable security safeguards under Rule 6 (encryption or masking, access controls, logging for one year, monitoring and backups) and breach notification under Rule 7 — without-delay intimation to affected individuals and to the Board, with a detailed report within 72 hours.
- Section 8(7) erasure — erasure once consent is withdrawn or the specified purpose is no longer served, unless retention is required by law, with Rule 8 adding a three-year inactivity clock for large e-commerce, gaming and social media fiduciaries named in the Third Schedule.
- Section 9 children’s data, Sections 11 to 14 Data Principal rights, Section 13 grievance redressal, and Section 14 nomination.
A Kerala business that waits for an SDF notification to begin this baseline work will find that the 12-month SDF clock then starts on top of unfinished baseline work — the position where penalties compound. The schedule in the DPDP countdown guide treats the baseline as the current priority for precisely this reason.
What should a Kerala business do now if it might become an SDF?
A practical pre-notification programme that does not waste effort if the business is never notified, but that avoids a scramble if it is:
- Map and classify data sensitivity. Not every data field carries the same SDF risk. Tag personal data by sensitivity — health, financial, biometric, location — and by volume, so the Section 10(1) factors can be self-assessed against realistic Government criteria.
- Identify a board-answerable DPO candidate. Even before formal SDF status, designating a senior person with board access and publishing their contact satisfies the spirit of Section 8(9) and means the Section 10(2)(a) appointment is a formalisation, not a fresh hire and induction in 2027.
- Scope the independent auditor. Engage in early conversations with qualified data auditors about scope, access and independence, so the first Section 10(2)(b) audit can be commissioned without a procurement cycle that consumes half the 12-month window.
- Run a DPIA pilot on the highest-risk processing. Pick one high-volume or high-sensitivity flow — for example, an AI-driven recommendation or a health-data pipeline — and run a DPIA using the Rule 13 structure. The pilot builds the methodology, the evidence file and the Board-reporting format before the statutory deadline.
- Document algorithmic logic. For any algorithm that materially affects Data Principals, record the purpose, training data governance, evaluation for rights risks, and human-oversight points. This file serves both Rule 13(3) algorithmic due diligence and, where relevant, the forthcoming AI governance expectations.
- Scenario-plan localisation. Identify which data categories would be operationally difficult to keep within India if a Rule 13(4) direction were made — for example, analytics pipelines that currently replicate to a foreign region — and design a feasible localisation path, even if not yet executed.
Primary sources
- Digital Personal Data Protection Act, 2023 — India Code (Sections 2(i), 2(k), 6, 8, 9, 10, 11 to 16, 18 to 33 and the Schedule)
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY (Rules 3, 6, 7, 8, 10 to 15, First and Third Schedules)
- PIB press release and backgrounder on notification of the DPDP Rules (14 and 17 November 2025)
- AZB & Partners summary of DPDP Rules enforcement timelines — Mondaq, 21 November 2025 (SDF duties from May 2027)
- DPDP Act and Rules phased compliance note — CADP, G.S.R. 846(E) text (Rule 13 twelve-month DPIA cycle)
FAQ
