Skip to content
SecuriFii

Regulation · India

Significant Data Fiduciary: the extra duties, including one about leaving India

The DPDP Act creates a heavier tier for organisations the government designates. Most will never be designated, but the duties are worth knowing, because one of them can restrict where data is allowed to go and it applies to nobody else.

Facts checked2026-09-11

What must a Significant Data Fiduciary do?

Designation is made by the Central Government, having regard to factors including the volume and sensitivity of personal data processed, the risk to data principals, and impacts on the sovereignty and integrity of India, electoral democracy and public order. It is a designation you receive, not a threshold you self-assess against.

The additional duties are: a Data Protection Officer based in India and answerable to the board or equivalent; an independent data auditor; a Data Protection Impact Assessment and an audit once every twelve months, counted from the date of notification as a Significant Data Fiduciary; and algorithmic due diligence — satisfying yourself that algorithmic software used to process personal data does not pose a risk to data principals’ rights.

And the one that surprises people: an SDF must ensure that personal data specified by the Central Government — on the recommendation of a committee it constitutes — is not transferred outside India, together with the traffic data pertaining to its flow. India’s general position on outbound transfers is permissive; this is the carve-out, and it reaches only organisations that have been designated.

The bottom line

Most organisations will not be designated. If you process personal data at scale, note that designation can bring a localisation duty attached to specific categories of data — which is an architecture question, not a policy one, and worth knowing before it applies.

Related insights