A “Data Fiduciary” under the DPDP Act, 2023 is an individual, person, company, government body, or organisation that determines the purpose and means of processing personal data. A data fiduciary becomes a Significant Data Fiduciary (SDF) when the Central Government officially notifies them based on an assessment of specific scale and risk factors.
The Significant Data Fiduciary is governed under the DPDP Act. The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s core law regulating digital personal data – how it’s collected, used, stored, and erased when no longer needed. It balances individual data rights with organisational obligations, and sets up the Data Protection Board of India (DPBI) to handle disputes and breaches. (Section 2 and Section 10).
What does “Significant Data Fiduciary” mean?
Every Significant Data Fiduciary is a Data Fiduciary, but not every Data Fiduciary becomes a Significant Data Fiduciary.
A Significant Data Fiduciary (SDF) is a Data Fiduciary or class of Data Fiduciaries that the Central Government may notify under Section 10 of the DPDP Act, 2023, based on factors such as the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, and the potential impact on India’s sovereignty and integrity, electoral democracy, security of the State, and public order.
In simple terms, an organisation may be designated as an SDF when the nature, scale, or potential impact of its personal data processing creates higher risks that warrant additional obligations under the Act.

What Obligations Do Significant Data Fiduciaries Have?
When a Data Fiduciary becomes Significant, the obligations become amplified. These SDFs are expected to maintain higher levels of transparency, security, and accountability. The key responsibilities for an SDF are-
Appointing a Data Protection Officer (DPO)
“Data Protection Officer” is an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10. SDFs must appoint a DPO who:
- Acts as the central point of contact for data principals and regulatory authorities.
- Advises and informs the board, management, and employees of their legal obligations.
- Monitors compliance and conducts audits.
- Ensures data practices align with the legal framework.
Handling the Data Protection Impact Assessments (DPIA)
Section 10(2)(c) of the DPDP Act, 2023 requires SDFs to regularly carry out Data Protection Impact Assessments (DPIA). This systematic process is done to:
- Identify privacy and data protection risks.
- Analyze those risks.
- Minimize them.
It’s carried out particularly before introducing new technologies or operations involving personal data.
Perform Periodic Data Audits
Under Section 10(2)(c)(ii) of the Act, the SDFs cannot make auditing a one-time work, they have to undertake a periodic data audit in a systematic and recurring manner. These mandatory audits verify compliance with the DPDP Act by ensuring:
- Data is processed only for its intended purpose
- Access is limited to authorized personnel only
- Third-party processors adhere to the same privacy standards
Have Transparent Standards
SDFs are required to adopt increased transparency measures, which help them provide detailed privacy notices to data principals covering:
- How their data is being used
- Whom it is shared with
- For what purposes
By following a transparent set of rules, the SDFs can prove their algorithms are fair, unbiased, and safe from discrimination.
Follow the Rules of Different Sectors
SDFs are required to follow sector-specific regulations. Financial institutions, for instance, must also adhere to stringent rules from Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI), and Insurance Regulatory and Development Authority of India (IRDAI).
Must Report Data Breaches
If a data breach occurs, SDFs must notify the Data Protection Board of India within 72 hours from the time of discovery, so authorities can impose the required safety measures. The notice must also be immediately communicated to affected users so they can take precautions against identity theft or fraud. Failure to report a breach can attract a penalty of up to ₹200 crore under sub-section (6) of Section 8.
Processing of Personal Data of a Data Principal
SDFs must process a Data Principal’s personal data only in accordance with the DPDP Act and for a lawful purpose. This requires:
- The data being collected for certain legitimate uses.
- Having the Data Principal’s consent.
[Data Principal (DP) is the person or an individual whose data is being used]
The SDF must also give the Data Principal prior notice under Section 6, informing them about the personal data and the purpose of collecting it. In case of conflict, the Data Principal can exercise their rights under sub-section (4) of Section 6 and Section 13.
Under sub-section (5), the Data Principal can withdraw their consent to the processing of their personal data at any time.
What are the penalties of data protection breaches under the DPDP Act?
| S. no. | Breaches | Section | Penalty |
| 1. | Being unsuccessful while taking reasonable security safeguards to prevent personal data breach. | Section 8(5) | Up to ₹250 crores |
| 2. | Failure to give the Board or the affected Data Principals notice of a personal data breach. | Section 8(6) | Up to ₹250 crores |
| 3. | Breach of additional obligations in relation
to children. |
Section 9 | Up to ₹250 crores |
| 4. | Violating any additional obligations of
Significant Data Fiduciary. |
Section 10 | Up to ₹150 crores |
| 5. | Breach in observance of the duties. | Section 15 | Up to ₹10,000 |
| 6. | Violating any term of voluntary undertaking. | Section 32 | The penalty imposed will match whatever penalty would have applied to the original breach |
| 7. | Breach of any other rule. | – | Up to ₹50 crores |
Other Consequences of a Breach
- Losing trust of the customer.
- The sales cycle can get adversely affected.
- Responding to the breach may result in operational disorder.
- In the worst case scenario, the company has a forced disclosure.
How is Significant Data Fiduciaries different from Data Fiduciaries?
Every Significant Data Fiduciary is first a Data Fiduciary. The significant title is added by the Central Government because of high-risk and it brings extra obligations. The difference between a Data Fiduciary and a ‘significant’ is due to-
How is the role decided?
- Every organization that collects and uses people’s personal data is automatically a Data Fiduciary.
- A Significant Data Fiduciary is a special tag — only the Central Government decides which companies get this label, based on things like how much data they handle and how risky it is.
Additional staffing requirements
- A Data Fiduciary doesn’t need to appoint anyone specific.
- A Significant Data Fiduciary must appoint a Data Protection Officer who lives in India. The SDF also needs to hire an independent auditor to check its data practices.
Mandatory checkups
- A Data Fiduciary just has to follow the basic rules (consent, security, etc.) without any mandatory review cycle.
- A Significant Data Fiduciary must run periodic Data Protection Impact Assessments and periodic audits.
How to become one?
- Data Fiduciary status has no selection criteria.
- A Significant Data Fiduciary is appointed by the Central Government, it is based on factors like: how much sensitive data they process, risk to people’s rights, potential impact on India’s sovereignty, risk to elections, state security, and public order.
Penalty regarding non-compliance
- If a normal Data Fiduciary breaks basic rules, general penalties apply (up to ₹250 crore for serious data breaches).
- If a Significant Data Fiduciary is still a standard Data Fiduciary and can face multiple, stacked penalties for other violations.
Conclusion
The DPDP Act, 2023, along with the DPDP Rules, 2025, is India’s first rights-based framework for digital personal data protection.
Under Section 10, the Central Government may classify certain Data Fiduciaries as Significant Data Fiduciaries (SDFs), based on the volume and sensitivity of data processed, risk to individuals, and potential impact on national interest or public order. As SDFs handle greater risk, they face stricter obligations than ordinary Data Fiduciaries. Non-compliance exposes the SDFs to serious penalties up to ₹150 crore per violation.
FAQs
Ques: What is a Significant Data Fiduciary?
Ans: A Significant Data Fiduciary (SDF) is a specialized category of data handler appointed by the Central Government under the Digital Personal Data Protection Act, 2023.
Ques: How is Data Fiduciary and a Significant Data Fiduciary different?
Ans: Under the DPDP Act, 2023, a Data Fiduciary is an individual, person, company, government body, or organisation that determines the purpose and means of processing personal data. On the other hand, a Significant Data Fiduciary is a Data Fiduciary that the central government notifies based on the large data volume, sensitivity, or risk. When a Data Fiduciary becomes an SDF, it must meet additional compliance requirements on top of the general ones.
Ques: Who has authority to classify data fiduciary as significant?
Ans: The Central Government classifies and notifies SDFs on the basis of different factors.
Ques: How to identify a Significant data fiduciary (SDF)?
Ans: The government evaluates a Data Fiduciary to become an SDF according to these factors-
- High Volume of Personal Data
- Handling of Sensitive Personal Data
- Potential Risk on individual’s identity
- Usage of Emerging Technologies
- Impact on National Security
Ques: What happens if a Significant Data Fiduciary fails to comply with the DPDPA?
Ans: If an SDF fails to comply with the DPDPA, it can result in major penalties, including fines, legal action, and damage to the organization’s credibility.
Ques: What is the penalty for an SDF that violates its obligations?
Ans: Any breach of SDF obligations under Section 10 brings a penalty of up to ₹150 crore and is followed up by an inquiry.

