What is a Significant Data Fiduciary (SDF) under the DPDP Act? A Significant Data Fiduciary (SDF) is an organisation designated by the Central Government as processing personal data in a manner that poses a significant risk to the rights of data principals, national security, or public order. Designation criteria include the volume and sensitivity of data processed, potential impact on data principals, national security implications, and risk to electoral democracy. SDFs face enhanced obligations including appointing a Data Protection Officer and an independent data auditor, conducting Data Protection Impact Assessments, and complying with additional technical standards prescribed by the government.
SDFs carry the heaviest DPDP obligations — an India-based DPO, independent audits and annual DPIAs. Answer 8 questions to see your likelihood.
⚠ MeitY proposes compressing SDF compliance deadline to November 13, 2026 — 5 months away.
A Data Protection Officer based in India, accountable to the board, published as your point of contact.
Appoint an independent data auditor and undergo periodic audits of DPDP compliance.
Conduct a Data Protection Impact Assessment every year and file as prescribed.
Verify that algorithmic and technical measures don't risk Data Principal rights.
We'll send a short memo for your leadership: your likely classification drivers, the obligations timeline, and the 5 preparations worth making before notification — specific to your answers.
Under Section 10 of the DPDP Act 2023, the Central Government may notify any Data Fiduciary or class of Data Fiduciaries as "Significant" based on factors including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
SDF obligations — an India-based DPO, an independent data auditor, and annual Data Protection Impact Assessments — take months to stand up. MeitY has proposed compressing the SDF compliance window to 12 months, making November 13, 2026 the effective deadline (originally May 2027). Organisations likely to be in scope (large consumer platforms, health and fintech data processors, HR/payroll platforms holding lakhs of records) benefit from preparing now rather than scrambling after notification. This self-assessment is indicative only; actual classification is by government notification.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.