Data Protection Officer under the DPDP Act: who needs one and what they do

Updated 26 Sep 2026 · 5min read · Reviewed by ConsentLo's DPDP audit team

Unlike the GDPR, the DPDP Act makes a Data Protection Officer mandatory only for Significant Data Fiduciaries. Every other organisation still needs someone who answers questions about its processing. Here is how the roles work.

Who must appoint a DPO

Significant Data Fiduciaries, notified by the Central Government based on factors such as the volume and sensitivity of data and the risk to people, must appoint a Data Protection Officer. The DPO must be based in India, represent the organisation under the Act, and be responsible to its Board of Directors or similar governing body.

What the DPO does

A DPO typically:

  • Is the point of contact for grievances from Data Principals.
  • Oversees notices, consent, rights and breach processes.
  • Leads the Data Protection Impact Assessment and periodic audit cycle.
  • Approves breach intimations and reports to the Data Protection Board.
  • Reports on privacy risk to the board of directors.

Everyone else: a published contact

A Data Fiduciary that is not significant must still publish the business contact details of a person who can answer questions about its processing of personal data. Many organisations give this role to a privacy lead or grievance officer. The contact must appear in notices and responses to Data Principals.

Setting the DPO up to succeed

A DPO needs visibility and evidence: a live view of requests and deadlines, incidents and clocks, DPIAs and audit findings. ConsentLo gives the DPO a single workspace for these, with a read-only seat for independent auditors.

Frequently asked questions

Is a DPO mandatory under the DPDP Act?

Only for Significant Data Fiduciaries. Other Data Fiduciaries must publish the contact of a person who can answer questions about their processing.

Does the DPO have to be in India?

Yes. A Significant Data Fiduciary's Data Protection Officer must be based in India.

Who does the DPO report to?

The DPO is responsible to the board of directors or similar governing body of the Significant Data Fiduciary.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.