---
title: "Significant Data Fiduciaries Under DPDP Act: Extra Duties"
description: "How Significant Data Fiduciaries are designated under DPDP Act Section 10 and their extra duties: DPO, auditor, DPIA, algorithmic due diligence, localisation."
url: "https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/"
image: "https://advaslam.com/og/writing/dpdp-significant-data-fiduciary-sdf-obligations.png"
---

[Data protection & DPDP compliance](https://advaslam.com/practice/data-protection/)

# Significant Data Fiduciaries Under the DPDP Act: Who They Are and What Extra Duties They Carry

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 1 September 2026

A Significant Data Fiduciary (SDF) under the [Digital Personal Data Protection Act, 2023](https://indiacode.gov.in/handle/123456789/496508) is not a status a business chooses — it is a designation the Central Government makes under [Section 10](https://indiacode.gov.in/handle/123456789/496508) on risk-based factors, and once notified the fiduciary carries five extra statutory duties on top of the baseline that every Data Fiduciary carries: a board-answerable [Data Protection Officer in India](https://indiacode.gov.in/handle/123456789/496508), an independent data auditor, an annual [Data Protection Impact Assessment (DPIA)](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) and audit with reporting to the Board, algorithmic due diligence, and a possible data-localisation direction for notified categories of data. No SDF class had been notified as of August 2026, which makes the current window the time to prepare, not the time to wait.

## How does a business become an SDF?

The process is entirely governmental, which surprises teams that expect a registration threshold like significant social media intermediary status under the IT Rules. Under [Section 10(1) DPDP Act](https://indiacode.gov.in/handle/123456789/496508) the Central Government may notify any Data Fiduciary or class of Data Fiduciaries as an SDF having regard to:

-   Volume and sensitivity of personal data processed.
-   Risk to the rights of Data Principals.
-   Potential impact on the sovereignty and integrity of India, electoral democracy, security of the State and public order.

The Government can notify by category — for example, all e-commerce entities above a user threshold, or all fiduciaries processing certain sensitive data — or by naming a specific fiduciary. Assessment is as the Government determines on the Section 10(1) factors.

The practical consequence for Kerala businesses is that SDF status is not limited to Big Tech. A healthtech handling health data (which is personal data of high sensitivity), a fintech processing financial data at volume, or an adtech platform whose profiling affects rights at scale could be designated as part of a class even without the headcount of a social media intermediary. The [Kerala Startup Mission](https://startupmission.kerala.gov.in) cohort — particularly startups that have scaled beyond Kerala to a pan-India user base — should assess SDF readiness as a risk scenario, not as a distant hypothetical.

## What are the five extra SDF duties?

### 1\. Data Protection Officer in India, answerable to the board

Under [Section 10(2)(a) DPDP Act](https://indiacode.gov.in/handle/123456789/496508), a notified SDF must appoint a **Data Protection Officer based in India** who is the contact point for grievance redressal and who is **answerable to the board of directors** (or the governing body for non-corporate fiduciaries). The DPO is not a compliance-department delegate with an email alias — the statute places the role at board level so that data protection decisions have board visibility and accountability. The DPO details must be published under Section 8(9) (general fiduciary duty to publish business contact information) and must be the channel through which Data Principals can exercise their Section 13 grievance rights against the SDF.

### 2\. Independent data auditor

Under [Section 10(2)(b)](https://indiacode.gov.in/handle/123456789/496508) and Rule 13, a notified SDF must appoint an **independent data auditor** — an external, qualified auditor, not an internal team — to audit its compliance with the Act and Rules. The independence requirement is substantive: an auditor who is also a vendor providing the SDF’s data-processing infrastructure would not satisfy the independence test. The auditor’s access must be sufficient to verify processing activities, security safeguards and cross-border handling, and the audit findings feed the DPIA and the Board reporting below.

### 3\. Data Protection Impact Assessment and periodic audit — at least every 12 months

Under [Section 10(2)(c)](https://indiacode.gov.in/handle/123456789/496508) and Rule 13, a notified SDF must conduct a **Data Protection Impact Assessment** and a periodic **audit** and report **significant observations** to the [Data Protection Board of India](https://www.meity.gov.in). The periodicity is at least **once every 12 months** from the date of notification as an SDF (or from the previous assessment). The DPIA must assess the risks of the SDF’s processing to Data Principal rights, the safeguards in place, and the effectiveness of security and governance controls. Rule 13 requires that the significant observations from the DPIA and audit be placed before the Board — not merely retained internally — so the assessment has regulatory visibility from the start.

### 4\. Algorithmic due diligence

Under [Rule 13(3) DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf), an SDF must undertake **due diligence to verify that its algorithms and other technical means do not pose risks to the rights of Data Principals**. For Kerala businesses building recommendation, pricing, hiring, credit-scoring or content-moderation algorithms, this is the provision that connects data protection to AI governance: a model that profiles or ranks individuals using personal data must be checked that it does not discriminate, misclassify or otherwise infringe rights. The duty complements — but is separate from — the [IT Amendment Rules, 2026](https://egazette.gov.in) duties on synthetically generated information and the emerging AI governance discussion at MeitY.

### 5\. Possible data-localisation direction

Under [Rule 13(4) DPDP Rules, 2025](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) read with Rule 15, the Central Government may, on the recommendation of a committee constituted for Rule 13, direct a notified SDF to ensure that such **personal data and associated traffic data** as it specifies is **not transferred outside India** and is **kept within India**. No such specification had been made as of August 2026. The general DPDP position on cross-border transfer under [Section 16](https://indiacode.gov.in/handle/123456789/496508) and Rule 15 is permissive by default — transfer is allowed unless the Government by notification restricts flows to specific countries — but the SDF localisation power under Rule 13(4) is an additional, targeted power that can require an SDF to keep notified data categories in India even where Section 16 would otherwise permit transfer. For a full treatment of cross-border rules, see the [cross-border data transfer guide](https://advaslam.com/writing/dpdp-cross-border-data-transfer-section-16/).

## What stays the same — the baseline every fiduciary carries regardless of SDF status?

SDF duties are additive. Every Data Fiduciary, whether or not notified as significant, must from **May 2027** (the 18-month tranche of the DPDP Rules, G.S.R. 846(E), 13 November 2025) comply with:

-   **Section 5 notice** — itemised, plain-language notice before consent, in English and Eighth Schedule languages chosen by the Data Principal, including Malayalam for Kerala users.
-   **Section 6 consent** — free, specific, informed, unconditional and unambiguous consent by clear affirmative action, with withdrawal as easy as giving it, and the fiduciary bearing the burden of proof under Section 6(10).
-   **Section 8 security and breach** — [reasonable security safeguards](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) under Rule 6 (encryption or masking, access controls, logging for one year, monitoring and backups) and breach notification under [Rule 7](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) — without-delay intimation to affected individuals and to the Board, with a detailed report within 72 hours.
-   **Section 8(7) erasure** — erasure once consent is withdrawn or the specified purpose is no longer served, unless retention is required by law, with Rule 8 adding a three-year inactivity clock for large e-commerce, gaming and social media fiduciaries named in the Third Schedule.
-   **Section 9 children’s data, Sections 11 to 14 Data Principal rights, Section 13 grievance redressal, and Section 14 nomination.**

A Kerala business that waits for an SDF notification to begin this baseline work will find that the 12-month SDF clock then starts on top of unfinished baseline work — the position where penalties compound. The schedule in [the DPDP countdown guide](https://advaslam.com/writing/dpdp-act-deadline-businesses/) treats the baseline as the current priority for precisely this reason.

## What should a Kerala business do now if it might become an SDF?

A practical pre-notification programme that does not waste effort if the business is never notified, but that avoids a scramble if it is:

1.  **Map and classify data sensitivity.** Not every data field carries the same SDF risk. Tag personal data by sensitivity — health, financial, biometric, location — and by volume, so the Section 10(1) factors can be self-assessed against realistic Government criteria.
2.  **Identify a board-answerable DPO candidate.** Even before formal SDF status, designating a senior person with board access and publishing their contact satisfies the spirit of Section 8(9) and means the Section 10(2)(a) appointment is a formalisation, not a fresh hire and induction in 2027.
3.  **Scope the independent auditor.** Engage in early conversations with qualified data auditors about scope, access and independence, so the first Section 10(2)(b) audit can be commissioned without a procurement cycle that consumes half the 12-month window.
4.  **Run a DPIA pilot on the highest-risk processing.** Pick one high-volume or high-sensitivity flow — for example, an AI-driven recommendation or a health-data pipeline — and run a DPIA using the Rule 13 structure. The pilot builds the methodology, the evidence file and the Board-reporting format before the statutory deadline.
5.  **Document algorithmic logic.** For any algorithm that materially affects Data Principals, record the purpose, training data governance, evaluation for rights risks, and human-oversight points. This file serves both Rule 13(3) algorithmic due diligence and, where relevant, the forthcoming AI governance expectations.
6.  **Scenario-plan localisation.** Identify which data categories would be operationally difficult to keep within India if a Rule 13(4) direction were made — for example, analytics pipelines that currently replicate to a foreign region — and design a feasible localisation path, even if not yet executed.

## Primary sources

-   [Digital Personal Data Protection Act, 2023 — India Code](https://indiacode.gov.in/handle/123456789/496508) (Sections 2(i), 2(k), 6, 8, 9, 10, 11 to 16, 18 to 33 and the Schedule)
-   [Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf) (Rules 3, 6, 7, 8, 10 to 15, First and Third Schedules)
-   [PIB press release and backgrounder on notification of the DPDP Rules (14 and 17 November 2025)](https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)
-   [AZB & Partners summary of DPDP Rules enforcement timelines — Mondaq, 21 November 2025](https://webiis10.mondaq.com/india/privacy-protection/1708314/update-indias-digital-personal-data-protection-framework-comes-into-effect) (SDF duties from May 2027)
-   [DPDP Act and Rules phased compliance note — CADP, G.S.R. 846(E) text](https://cadp.in/resources/official-texts/dpdp-rules-2025/) (Rule 13 twelve-month DPIA cycle)

FAQ

## Common questions

**What is a Significant Data Fiduciary under the DPDP Act?**

A Data Fiduciary or class of Data Fiduciaries notified by the Central Government under Section 10 of the DPDP Act, 2023 on the basis of factors including volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on electoral democracy, security of the State and public order. Notification is by the Government, not self-declared, and no SDF class had been notified as of August 2026.

**What extra obligations does an SDF have?**

Under Section 10 read with Rule 13 of the DPDP Rules, 2025, a notified SDF must appoint a Data Protection Officer based in India answerable to the board, appoint an independent data auditor, conduct a Data Protection Impact Assessment and a periodic audit at least once every 12 months with significant observations reported to the Board, exercise due diligence under Rule 13(3) that its processing including algorithmic software does not risk Data Principal rights, and under Rule 13(4) keep such personal data and traffic data as the Government may specify, on a committee recommendation, within India.

**Does SDF status depend on company size or turnover alone?**

No. Section 10(1) lists volume and sensitivity of personal data and risk to rights as factors, alongside impact on electoral democracy, security of the State and public order. Size, turnover and user count are indicators the Government weighs, but the statute frames the test as a risk-based designation, and the notification can be class-based — for example, all fiduciaries of a certain type — not only company-by-company.

**What is the penalty for breaching SDF obligations?**

Up to one hundred and fifty crore rupees per breach under the Schedule to the DPDP Act, read with Section 33, imposed by the Data Protection Board after inquiry and hearing weighing the factors in Section 33(2).

**Can a Kerala startup be designated as an SDF?**

Yes, if it falls within a notified class or is individually notified. The Act applies pan-India and notification turns on data-related risk factors, not geography or incorporation state. A Kerala SaaS, healthtech or fintech handling sensitive personal data at scale or affecting rights at scale could be designated as part of a class even if it is not among the largest platforms by headcount. There is no small-business or startup exemption from SDF designation in the Act.

**A note on this article.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

Keep reading

Data protection & DPDP compliance

### DPDP Compliance Guide for Kerala Businesses to May 2027

DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties.

25 Sept 2026

[DPDP Compliance Guide for Kerala Businesses to May 2027](https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/)

Data protection & DPDP compliance

### Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act

Company leaked your Aadhaar, phone or health data? DPDP Sections 11-14 rights, Board complaint, IT Act 43A compensation, consumer and civil remedies.

6 Sept 2026

[Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act](https://advaslam.com/writing/data-breach-victim-rights-dpdp-compensation/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"Significant Data Fiduciaries Under the DPDP Act: Who They Are and What Extra Duties They Carry","description":"How Significant Data Fiduciaries are designated under DPDP Act Section 10 and their extra duties: DPO, auditor, DPIA, algorithmic due diligence, localisation.","url":"https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/","mainEntityOfPage":"https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/","datePublished":"2026-09-01T00:00:00.000Z","dateModified":"2026-09-01T00:00:00.000Z","keywords":"Significant Data Fiduciary DPDP, SDF obligations DPDP Act, Section 10 DPDP Act SDF, DPIA DPDP Act, DPDP localisation requirement, SDF notification India","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/writing/dpdp-significant-data-fiduciary-sdf-obligations.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/data-protection/#service","name":"Data protection & DPDP compliance","url":"https://advaslam.com/practice/data-protection/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Articles","item":"https://advaslam.com/writing/"},{"@type":"ListItem","position":3,"name":"Significant Data Fiduciaries Under the DPDP Act: Who They Are and What Extra Duties They Carry","item":"https://advaslam.com/writing/dpdp-significant-data-fiduciary-sdf-obligations/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What is a Significant Data Fiduciary under the DPDP Act?","acceptedAnswer":{"@type":"Answer","text":"A Data Fiduciary or class of Data Fiduciaries notified by the Central Government under Section 10 of the DPDP Act, 2023 on the basis of factors including volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on electoral democracy, security of the State and public order. Notification is by the Government, not self-declared, and no SDF class had been notified as of August 2026."}},{"@type":"Question","name":"What extra obligations does an SDF have?","acceptedAnswer":{"@type":"Answer","text":"Under Section 10 read with Rule 13 of the DPDP Rules, 2025, a notified SDF must appoint a Data Protection Officer based in India answerable to the board, appoint an independent data auditor, conduct a Data Protection Impact Assessment and a periodic audit at least once every 12 months with significant observations reported to the Board, exercise due diligence under Rule 13(3) that its processing including algorithmic software does not risk Data Principal rights, and under Rule 13(4) keep such personal data and traffic data as the Government may specify, on a committee recommendation, within India."}},{"@type":"Question","name":"Does SDF status depend on company size or turnover alone?","acceptedAnswer":{"@type":"Answer","text":"No. Section 10(1) lists volume and sensitivity of personal data and risk to rights as factors, alongside impact on electoral democracy, security of the State and public order. Size, turnover and user count are indicators the Government weighs, but the statute frames the test as a risk-based designation, and the notification can be class-based — for example, all fiduciaries of a certain type — not only company-by-company."}},{"@type":"Question","name":"What is the penalty for breaching SDF obligations?","acceptedAnswer":{"@type":"Answer","text":"Up to one hundred and fifty crore rupees per breach under the Schedule to the DPDP Act, read with Section 33, imposed by the Data Protection Board after inquiry and hearing weighing the factors in Section 33(2)."}},{"@type":"Question","name":"Can a Kerala startup be designated as an SDF?","acceptedAnswer":{"@type":"Answer","text":"Yes, if it falls within a notified class or is individually notified. The Act applies pan-India and notification turns on data-related risk factors, not geography or incorporation state. A Kerala SaaS, healthtech or fintech handling sensitive personal data at scale or affecting rights at scale could be designated as part of a class even if it is not among the largest platforms by headcount. There is no small-business or startup exemption from SDF designation in the Act."}}]}]}
```
