5 min read

What Additional Requirement Applies to a Significant Data Fiduciary?

A breakdown of Section 10 obligations for Significant Data Fiduciaries under the DPDP Act 2023, covering DPO appointments, independent data audits, and DPIA workflows for BFSI enterprises.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Section 10 of the Digital Personal Data Protection Act 2023 subjects an entity notified as a Significant Data Fiduciary to extra obligations. The Central Government designates these entities based on specific risk factors. Upon notification, the organization fulfills three main duties. The fiduciary appoints a Data Protection Officer based in India. The company retains an independent data auditor to evaluate compliance. The entity undertakes periodic Data Protection Impact Assessments. These mandates apply on top of the standard requirements for a general Data Fiduciary. Large financial institutions expect this classification. They process massive volumes of operational records.

The Central Government evaluates several criteria before notifying a Significant Data Fiduciary. Section 10 outlines six factors for this assessment. Authorities review the volume and sensitivity of the personal data processed. The government assesses the risk to the rights of the Data Principal. The evaluation considers potential impact on the sovereignty and integrity of India. Regulators examine the risk to electoral democracy. Security of the State and public order complete the statutory list. A bank holding millions of retail accounts triggers the volume threshold. A social media platform hits the electoral democracy clause. Affected organizations prepare for specific governance adjustments.

Section 10 details a structural hierarchy for the Data Protection Officer. The officer represents the Significant Data Fiduciary under the provisions of the Act. The law requires this individual to reside in India. The DPO answers directly to the Board of Directors or a similar governing body. This statutory reporting line removes the role from middle management. The executive acts as the primary point of contact for the grievance redressal mechanism. A general Data Fiduciary delegates query responses to any designated person. A Significant Data Fiduciary appoints a localized executive. Multinational corporations cannot rely solely on overseas compliance teams for this function.

A Significant Data Fiduciary appoints an independent data auditor. This external reviewer evaluates compliance against the DPDP Act and Rules 2025. Internal teams prepare the primary evidence logs. The independent auditor delivers an objective assessment. The resulting report informs the Data Protection Board of India during reviews. Financial services companies already undergo sectoral audits by regulators like the RBI. The Section 10 data audit requires a distinct focus on personal data processing rules. Teams document control ownership clearly. The enterprise proves compliance with Data Principal rights across specific datasets.

The statute directs Significant Data Fiduciaries to undertake periodic Data Protection Impact Assessments. A DPIA maps specific risks tied to a processing activity. The assessment evaluates the scope of data collection. It identifies mitigating controls for risks to the Data Principal. Product teams complete an impact assessment before launching a retail credit product. Engineering departments execute the same process before migrating a core banking system to a new cloud environment. Organizations review risk early in the development lifecycle. This prevents retroactively assessing live systems on the compliance deadline.

The DPDP Rules 2025 supply specific forms and timelines for these obligations. A Significant Data Fiduciary retains the impact assessment documentation for regulatory inspection. The independent data auditor uses historical records to measure ongoing compliance. Changes to a business process trigger a new assessment requirement. A software update changes the data flows to a different server. The compliance team captures this shift in a revised document. The Board of Directors reviews summary reports of high-risk processing activities identified during these steps. Direct reporting structures formalize the oversight process.

Significant Data Fiduciaries engage multiple vendors. Section 8 makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary. An organization executes a valid contract before engaging a Data Processor. The fiduciary remains liable if the processor breaches the Act. Large entities use dozens of providers for customer support and cloud hosting. The DPO and the independent auditor review processor agreements. The fiduciary ensures data accuracy if the data makes a decision affecting the Data Principal. Disclosures to another Data Fiduciary trigger the same accuracy mandate.

Section 11 grants the Data Principal the right to obtain a summary of personal data. The individual requests the identities of all other Data Fiduciaries and Data Processors holding shared information. Fulfilling these requests poses a technical challenge for an organization of this scale. An entity processing ten million records requires automated retrieval systems. Manual database queries fail under high volume. The independent data auditor tests the speed and accuracy of this exact mechanism. Legacy systems lack the mapping required to generate a complete summary. Enterprise architects design data pipelines to extract this information within prescribed time limits.

Consent is the primary basis for processing. Section 7 legitimate uses provide specific exemptions. Processing without consent applies to employment purposes or responding to medical emergencies. Large enterprises map which basis applies to each database row. Legacy platforms rarely track this distinction. The independent auditor reviews the Record of Processing Activities of the organization. The ledger separates consent-driven data from Section 7 data. Mixing these bases creates compliance failures during the audit. The DPO ensures the board understands this technical requirement. Auditors demand exact database schemas reflecting the legal basis for every attribute collected.

The DPDP Act compliance deadline is 13 May 2027. Compliance leaders take four distinct steps. 1. Map existing sectoral governance frameworks against Section 10 requirements. 2. Establish a documented reporting line from the DPO to the governing board. 3. Build an evidence trail for every impact assessment conducted on new operational products. 4. Centralize consent artifacts and breach intimation workflows to prepare for independent audits. Delaying these steps creates operational risk. The Data Protection Board expects demonstrable compliance upon enforcement. Organizations prepare systems well before the deadline.

A dedicated compliance platform generates required reports for the independent data auditor. The system maps assessment ownership to specific control owners. Chief Risk Officers seek tools that separate regulatory evidence from general operational dashboards. The software tracks breach intimation timelines to ensure the entity meets the 72-hour reporting window under the Rules 2025. Organizations maintain active oversight of vendor contracts and consent registries. Spreadsheets fail when tested by independent auditors under Section 10 scrutiny. Centralize workflows and independent audit evidence packs before enforcement begins. Review the compliance architecture at https://www.complydp.com/audit-preview.

Sources

Frequently asked questions

What is the penalty for a Significant Data Fiduciary failing its duties?

The DPDP Act 2023 outlines maximum penalties of up to 250 crore rupees for broad non-compliance. Specific failures related to SDF obligations under Section 10 can attract fines up to 150 crore rupees. The exact amount depends on the severity and duration of the violation.

Can our existing Chief Information Security Officer act as the DPO?

Section 10 requires the DPO to be an individual based in India responsible directly to the Board of Directors. A CISO could potentially hold both titles. However, the DPO role requires distinct independence to represent the entity under the DPDP Act. Combining roles risks a conflict of interest during independent data audits.

Do we need consent for every processing activity as an SDF?

Consent is the primary basis for processing under the DPDP Act. Processing is also permitted without consent under Section 7 legitimate uses. These include employment purposes or responding to medical emergencies. SDFs map which basis applies to each dataset in their RoPA.

When must we complete our first Data Protection Impact Assessment?

The law takes full effect on 13 May 2027. Entities expecting SDF classification incorporate impact assessment workflows into new product development immediately. You cannot retroactively assess risk for systems actively processing data on the deadline date.

How does an independent data auditor differ from our internal audit team?

Section 10 mandates an independent data auditor to evaluate the compliance of the Significant Data Fiduciary. Internal teams prepare the evidence logs and manage daily operations. The external auditor provides an objective review of these controls.