Regulation · India
Significant Data Fiduciary: the extra duties, including one about leaving India
The DPDP Act creates a heavier tier for organisations the government designates. Most will never be designated, but the duties are worth knowing, because one of them can restrict where data is allowed to go and it applies to nobody else.
Facts checked — 2026-09-11
What must a Significant Data Fiduciary do?
Designation is made by the Central Government, having regard to factors including the volume and sensitivity of personal data processed, the risk to data principals, and impacts on the sovereignty and integrity of India, electoral democracy and public order. It is a designation you receive, not a threshold you self-assess against.
The additional duties are: a Data Protection Officer based in India and answerable to the board or equivalent; an independent data auditor; a Data Protection Impact Assessment and an audit once every twelve months, counted from the date of notification as a Significant Data Fiduciary; and algorithmic due diligence — satisfying yourself that algorithmic software used to process personal data does not pose a risk to data principals’ rights.
And the one that surprises people: an SDF must ensure that personal data specified by the Central Government — on the recommendation of a committee it constitutes — is not transferred outside India, together with the traffic data pertaining to its flow. India’s general position on outbound transfers is permissive; this is the carve-out, and it reaches only organisations that have been designated.
The bottom line
Most organisations will not be designated. If you process personal data at scale, note that designation can bring a localisation duty attached to specific categories of data — which is an architecture question, not a policy one, and worth knowing before it applies.
Related services
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Regulation
Breach notification: the clock starts before you know what happened
Both regimes start counting when you become aware — and India’s rules have no risk threshold for telling the people affected.