What is a Significant Data Fiduciary under DPDP — and are you one?
The government can designate certain companies as Significant Data Fiduciaries, triggering a higher compliance tier. Here is what that means and how to know if you are at risk.
What factors determine Significant Data Fiduciary designation under DPDP?
The Act gives the government discretion to designate any Data Fiduciary as an SDF based on several factors: the volume and sensitivity of personal data processed, risk to the rights of data principals, potential impact on India's sovereignty or public order, risk to electoral democracy, national security considerations, and any other prescribed criteria. The government will publish the list of designated SDFs; until then, any company meeting these risk thresholds should prepare for the possibility of designation.
What extra compliance obligations does a Significant Data Fiduciary have?
Designated SDFs must appoint a Data Protection Officer (DPO) who is resident in India and reports to the board. They must conduct periodic Data Protection Impact Assessments (DPIAs) for high-risk processing activities. They must submit to periodic audits by an independent data auditor approved by the Data Protection Board. They must also register with the Board within the prescribed timeline and comply with any additional standards the government notifies for their category. These are over and above the standard obligations every Data Fiduciary must meet.
Which companies are most likely to be designated as Significant Data Fiduciaries?
Based on the risk factors in the Act, the highest-probability candidates for SDF designation are: large social media platforms with tens of millions of Indian users, consumer internet companies processing sensitive personal data at scale (health, financial, children's data), payment aggregators and fintech platforms processing high volumes of financial data, companies providing critical digital infrastructure, and any platform the government identifies as having significant societal or political influence. Mid-market B2B SaaS companies are less likely to be designated in the first round, but should monitor the government's notifications.
How should companies prepare for SDF designation before the list is published?
Given that the SDF list is forthcoming, companies in high-risk categories should treat SDF compliance as likely and start preparing now. That means conducting a DPIA for your highest-risk processing activities, identifying candidates for the DPO role (or evaluating external DPO services), mapping your data flows for auditor readiness, and building a governance structure that can demonstrate board-level accountability for privacy. If you are eventually designated, the compliance deadline from that point will be short.
What are the penalties for failing to meet SDF obligations under DPDP?
Non-compliance with SDF obligations — such as failing to appoint a DPO or refusing to submit to an audit — can attract penalties from the Data Protection Board. The Act provides for significant financial penalties, and for SDFs the regulatory scrutiny will be higher than for standard Data Fiduciaries. The Board can also direct remediation and, in serious cases, suspend processing activities. Building SDF-readiness now is far cheaper than scrambling after designation.
Frequently asked questions
When will the government publish the list of SDFs?
The government has not yet published the SDF list as of mid-2026. It is expected to come in subordinate legislation or a Ministry of Electronics & IT (MeitY) notification after the DPDP Rules 2025 are fully operationalised. Companies in high-risk categories should monitor government notifications and prepare proactively.
Do small companies need to worry about SDF designation?
SDF designation is aimed at large-scale processors with significant societal impact, so most small and mid-sized companies are unlikely to be designated in the first round. However, if a small company processes particularly sensitive data — children's data, health records — at scale, it could be at risk. The safer posture is to build good foundational compliance regardless and revisit SDF risk as the government's criteria become clearer.
Can a company challenge SDF designation?
The Act does not provide an explicit mechanism to appeal SDF designation in the same way you can appeal a penalty order. However, if the designation is made on factually incorrect grounds, administrative law remedies may be available. The more practical approach is to engage with the government during the consultation process before the list is finalised.
Assess your SDF risk
Niti Bharat's SDF Risk Assessment helps large data processors understand their likelihood of designation and what additional obligations to prepare for.
Check Your SDF Risk