Significant Data Fiduciary (SDF) under DPDP: criteria and obligations
Updated 26 Sep 2026 · 5min read · Reviewed by ConsentLo's DPDP audit team
The DPDP Act lets the Government designate some organisations as Significant Data Fiduciaries (SDFs), which carry extra obligations. If you process personal data at scale or in sensitive areas, it is worth preparing before any notification.
How SDFs are designated
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as significant, considering the volume and sensitivity of personal data, the risk to the rights of Data Principals, and potential impact on the sovereignty and integrity of India, electoral democracy, security of the State and public order.
Additional obligations
On top of every Data Fiduciary duty, an SDF must:
- Appoint a Data Protection Officer based in India, responsible to its board.
- Appoint an independent data auditor to evaluate its compliance.
- Carry out a Data Protection Impact Assessment and an audit periodically; the DPDP Rules, 2025 set this at once every twelve months, with key findings reported to the Board.
- Check that algorithmic software it uses to process personal data does not pose a risk to Data Principals' rights.
- Follow any measures notified to keep specified personal data within India.
Preparing before designation
The annual cycle is easier to run if the evidence already exists: a current data map, a register of processors, DPIA records with scored risks, and logs of requests, incidents and decisions. ConsentLo keeps SDF duties ready but switched off until you are notified, so turning them on is a configuration change rather than a project.
Frequently asked questions
Who decides if a company is a Significant Data Fiduciary?
The Central Government, by notification, based on factors such as the volume and sensitivity of the data and the risk to people and to the State.
How often must an SDF carry out a DPIA?
The DPDP Rules, 2025 require a Data Protection Impact Assessment and an audit once every twelve months.
Does an SDF need an external auditor?
Yes. It must appoint an independent data auditor to evaluate its compliance with the Act.