What is a Significant Data Fiduciary under DPDP and are you one?
SDF designation triggers enhanced obligations that most large companies must prepare for. Here is what it means and how to know if it applies to you.
What criteria determine Significant Data Fiduciary designation?
The DPDP Act gives the government discretion to designate SDFs based on: (1) the volume and sensitivity of personal data processed — organisations processing data for millions of Indians with sensitive categories are prime candidates; (2) risk to the rights of data principals — if a breach or misuse of your data would cause widespread harm; (3) the potential impact on sovereignty, integrity, or national security — which explains why large tech platforms are expected to be early designees; and (4) public order implications. The government has not yet published the SDF list — but organisations meeting these criteria should prepare.
Which types of organisations are likely to be designated as SDFs?
Most likely: large consumer technology platforms (social media, e-commerce, ride-sharing) with hundreds of millions of Indian users; major payment aggregators and UPI platforms; large health data platforms and insurance aggregators; government-integrated data systems; credit bureaus; and large financial institutions. Potentially: major HRMS platforms processing millions of employees' data; large OTT platforms; and dominant cloud service providers. Less likely but possible: companies processing significant volumes of sensitive data in healthcare or financial services at scale.
What additional obligations does SDF designation impose?
SDFs must: appoint a Data Protection Officer (DPO) who is India-resident, reports directly to the Board, and is the point of contact with the Data Protection Board; conduct periodic Data Protection Impact Assessments for high-risk processing activities; engage an independent Data Auditor for periodic audits of their data processing practices; and comply with any additional obligations the government prescribes for SDFs (which may include interoperability, transparency reporting, or specific algorithmic accountability requirements). These are significantly more demanding than the standard Fiduciary obligations.
What does an SDF-ready Data Protection Officer look like?
An India-resident DPO for an SDF should have: deep knowledge of Indian data protection law (DPDP Act, IT Act, sectoral regulations); experience managing privacy programmes at scale; the seniority to engage credibly with the Board of Directors and regulatory bodies; and the independence to raise issues without fear of retaliation. The DPO role is not primarily a legal or compliance function — it requires technical understanding of data processing systems, organisational influence, and regulatory relationship management. Most SDFs will need to either hire externally or develop this profile internally over 12–18 months.
What is a Data Protection Impact Assessment (DPIA) under DPDP?
A DPIA is a formal assessment conducted by SDFs before undertaking processing activities likely to create high risk to data principals. It assesses: the nature, scope, context and purpose of the processing; the risks to individual rights; and the mitigations in place. SDFs must conduct DPIAs for: large-scale processing of sensitive personal data; systematic profiling; use of new technologies (AI, biometric systems); and other high-risk activities defined by the government. The DPIA must be submitted to the Board as part of the SDF's compliance documentation. Non-SDFs are not mandated to conduct DPIAs but should conduct equivalent Privacy Impact Assessments for high-risk activities.
How should non-SDFs prepare for potential SDF designation?
Even if you are not yet sure whether you will be designated, build SDF-ready foundations: appoint a privacy lead (internal or fractional DPO) now; begin conducting PIAs for high-risk activities; commission a gap assessment against SDF requirements; build your data governance infrastructure (data inventory, ROPA, consent management); and develop a relationship with a DPDP specialist who can support the designation process. The cost of scrambling to implement SDF requirements after designation is dramatically higher than building towards them proactively.
Frequently asked questions
Can an organisation challenge its SDF designation?
The DPDP Act does not explicitly provide for appeal of SDF designation in the draft framework — the government has wide discretion. If you believe you have been incorrectly designated, the route would be through legal challenge to the designation notification. However, building a compliance programme that meets SDF standards is likely more productive than litigation — it demonstrates willingness to meet the regulatory expectations and builds the relationship with the Data Protection Board.
Is there a size threshold for SDF designation?
The Act does not set a specific size threshold (number of users, revenue, employees). It is based on the criteria described above — volume of sensitive data, risk level, national security implications. A small company processing the personal data of millions of vulnerable individuals (a healthcare platform serving rural populations) could theoretically be an SDF. A large company processing minimal personal data (a B2B industrial equipment vendor) is unlikely to be designated. Context matters more than absolute size.
What are the penalties for non-compliance by an SDF?
SDFs face higher penalty caps than standard Fiduciaries: up to ₹250 crore for failure to implement required safeguards. The mandatory DPO appointment, DPIA, and Data Audit obligations are all separately enforceable — meaning an SDF could face multiple penalty orders for different compliance failures. The reputational risk of enforcement action against an SDF — which will be public — adds to the commercial incentive for rigorous compliance.
Prepare for SDF designation
Niti Bharat's DPDP Maturity Assessment includes an SDF readiness module — DPIA capability, DPO job specification, audit programme design, and board reporting framework.
Start SDF Readiness Assessment