Not every Data Fiduciary bears the same compliance burden. The DPDPA creates a two-tier structure: ordinary Data Fiduciaries and Significant Data Fiduciaries. The SDF classification, made by the Central Government under Section 10, triggers additional obligations that substantially increase both the initial and recurring cost of compliance.
The designation criteria are broad — volume and sensitivity of data, risk to Data Principals, potential impact on sovereignty, and other factors the government considers relevant. Until the first tranche of designations is notified, organisations in data-intensive sectors should assess their likely classification and prepare accordingly.
Ordinary vs Significant Data Fiduciary
| Dimension | Ordinary Data Fiduciary | Significant Data Fiduciary |
|---|---|---|
| Classification Mechanism | Default status for any entity that determines purpose and means of processing | Designated by Central Government notification under Section 10(1) |
| Data Protection Officer | Not mandatory | Mandatory — must be based in India, represents SDF before the Board |
| Independent Data Auditor | Not required | Mandatory — must evaluate compliance independently |
| Data Protection Impact Assessment | Not required | Mandatory for specified processing activities |
| Periodic Audit | Not specifically required | Mandatory periodic compliance audit |
| Penalty for Non-Compliance | Up to INR 50 crore for general non-fulfilment of obligations | Up to INR 150 crore for non-fulfilment of SDF-specific obligations (in addition to general penalties) |
| Cross-Border Transfer | Subject to general transfer restrictions | May face additional restrictions as notified by Central Government |
| Consent Obligations | Standard consent under Section 6 | Same as ordinary, but DPIA may identify enhanced consent requirements |
The Designation Criteria
Section 10(1) lists the factors the Central Government may consider when designating an SDF:
- ▸Volume and sensitivity of personal data processed
- ▸Risk to the rights of the Data Principal
- ▸Potential impact on the sovereignty and integrity of India
- ▸Risk to electoral democracy
- ▸Security of the State
- ▸Public order
- ▸Such other factors as the Central Government may consider necessary
Related Reading
Frequently Asked Questions
Who designates a Significant Data Fiduciary?
The Central Government designates Significant Data Fiduciaries by notification under Section 10(1) of the DPDPA. This is not a self-classification — you cannot declare yourself an SDF, nor can you opt out of the designation. The criteria include volume and sensitivity of personal data processed, risk to Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order.
What additional obligations does an SDF have?
An SDF must: (1) appoint a Data Protection Officer based in India who represents the SDF before the Board, (2) appoint an independent data auditor to evaluate compliance, (3) conduct Data Protection Impact Assessment for specified processing activities, and (4) undertake periodic audits. These are in addition to all obligations applicable to ordinary Data Fiduciaries.
Can a company self-classify as an SDF?
No. SDF classification is exclusively by Central Government notification under Section 10(1). A Data Fiduciary cannot self-designate. However, organisations expecting designation can voluntarily implement SDF-level compliance measures as a precautionary step. This is a commercial decision, not a legal obligation.
What is the penalty for SDF non-compliance?
The Schedule to the DPDPA prescribes a penalty of up to INR 150 crore for non-fulfilment of additional obligations applicable to Significant Data Fiduciaries. This is per contravention.
SDF Readiness Assessment
We assess your data processing profile against the Section 10 criteria and build the compliance framework — DPO appointment, audit programme, and DPIA methodology — before the designation arrives.
Schedule a Consultation