Konfirmity

Part of the DPDP compliance guide

Significant Data Fiduciary Under DPDP: Section 10 and Rule 13

Amit Gupta

Amit Gupta

2026-10-05

A Significant Data Fiduciary is a Data Fiduciary, or a class of Data Fiduciaries, that India's Central Government notifies as significant under section 10 of the Digital Personal Data Protection Act, 2023. It is a designation conferred on you, not a threshold you cross. Until you are notified, rule 13 does not apply to you.

That settles most of the worry that brings people to this page. No user count, revenue figure or sensitivity test silently converts an ordinary Data Fiduciary into a significant one.

What is worth knowing is the cost, because these duties are structural: they change who you employ, who reports to your board, where certain data may sit, and what you must say about your own software.

How Significant Data Fiduciary Status Is Conferred

Significant Data Fiduciary status is conferred by notification under section 10. Nothing in the Act or the Rules makes the category self-executing, and nothing asks you to measure yourself against a line.

That changes how you answer questions about it. If a customer's security questionnaire asks whether you are an SDF, the accurate answer is that you have not been notified as one — not that you fall below a threshold, which implies a test that does not exist. And because the designation can land on a class rather than a named entity, you can become an SDF without any change in your own behaviour.

The Two Layers of Duty

A notified SDF carries two layers of duty that summaries routinely merge. One sits in section 10(2) of the Act and governs who you appoint; the other sits in rule 13 of the Rules and governs what you do each year and what you may move.

LayerDuty
Section 10(2) of the ActAppoint a DPO based in India, who represents the entity, is responsible to its Board of Directors or equivalent governing body, and is the point of contact for grievance redressal
Section 10(2) of the ActAppoint an independent data auditor
Rule 13A Data Protection Impact Assessment and an audit once every twelve months
Rule 13Furnish a report of significant observations from both to the Board
Rule 13Due diligence that algorithmic software used on personal data is not likely to pose a risk to Data Principals' rights
Rule 13Ensure personal data specified by the Central Government, and its traffic data, is not transferred outside India

The split is practical. The section 10(2) appointments are hiring and governance decisions with lead times measured in months; the rule 13 duties are an operating cadence plus one hard constraint on architecture. Breach of the additional obligations of a Significant Data Fiduciary under section 10 carries a penalty of up to 150 crore rupees, which puts both layers in front of the board rather than in a backlog.

What Section 10(2) Asks of the Entity

Section 10(2) asks for two appointments, both specified tightly enough that a nominal hire will not satisfy them.

A Data Protection Officer Based in India

The data protection officer India requirement in section 10(2) has four parts, each closing off a common shortcut. The DPO must be based in India, must represent the entity, must be responsible to the Board of Directors or equivalent governing body, and must be the point of contact for grievance redressal.

That rules out the multinational default of a group privacy officer in another jurisdiction with a local manager as nominal contact. It also rules out burying the role under a CISO two levels below the board, because responsibility to the governing body is written into the duty.

Grievance redressal is where the daily work comes from. The DPO is the named human a Data Principal reaches, so the role needs a queue, a response path and enough authority to compel answers from engineering. If you run a privacy roles and responsibilities map, this is where it gains an India-resident node with a line to the board.

An Independent Data Auditor

The independent data auditor is a second, separate appointment, and independence is the operative word: whoever performs the rule 13 audit cannot be the team whose controls are audited, and in practice cannot be the function that owns the DPIA.

Section 10(2) requires the appointment without describing the auditor's qualifications, so the governance around the engagement is what makes it defensible. Scope it in writing, fix the reporting line, keep the papers.

Want to know what rule 13 would cost you before you are notified?

Share your work email and we'll map the section 10(2) appointments and the four rule 13 duties against your current governance, and mark what has a lead time longer than a quarter.

We check that your email domain is real and can receive mail before sending. If we can't verify it, we won't be able to follow up — so please use a work address rather than a forwarding or temporary one.

We'd like to know who we're talking to. By submitting this form you agree that we may contact you about Konfirmity — no more than six emails a year, and we won't ask again each time. You can unsubscribe from any of them, and we'll stop. See our Privacy Policy.

The Four Duties Rule 13 Adds

Rule 13 adds four duties on top of what an ordinary Data Fiduciary owes: two are an annual cadence, one is a disclosure obligation, and one constrains where specified personal data may live.

An Annual DPIA and Audit

The DPDP DPIA requirement for a notified SDF is a Data Protection Impact Assessment and an audit, once every twelve months. The conjunction is the part teams miss: two exercises with different outputs, not one exercise with two names. Satisfying the audit does not discharge the assessment.

The DPIA looks forward at what your processing does to Data Principals; the audit looks back at whether your stated controls operated. If you have run a DPIA under another regime the method transfers well — our DPIA methodology walkthrough covers scoping one and producing a record that survives review. The 12-month clock means fixing a calendar slot and an owner now, because a late DPIA is visible in the dates on the report.

Significant Observations Furnished to the Board

Rule 13 requires significant observations from both the DPIA and the audit to be furnished in a report to the Board — the Data Protection Board of India, not your own board of directors. Both appear in the SDF duties and are easy to confuse: the DPO is responsible to your directors, the observations report goes to the regulator.

That changes how both documents should be written. Anything significant enough to report will be read by the regulator, so you need a defensible selection rule for what counted and a remediation status against each item. An observation with no owner and no date is the worst thing to volunteer.

Algorithmic Due Diligence

The algorithmic due diligence duty is the genuinely novel one, with no close analogue in most privacy regimes. Rule 13 requires an SDF to observe due diligence that the algorithmic software it uses is not likely to pose a risk to the rights of Data Principals.

The reach is wider than "AI". The duty attaches to algorithmic software used for hosting, display, upload, modification, publication, transmission, storage, updating or sharing of personal data. Those 9 verbs cover a recommendation engine, but equally a deduplication job, a retention sweeper, a search index, a notification fan-out and a CDN rule deciding what gets served to whom. If code decides how personal data moves, appears or changes, it is in scope.

The Rules prescribe no method, and inventing one would be a mistake. Due diligence carries its ordinary meaning: a documented, repeatable examination proportionate to the risk. In practice:

  • An inventory of the algorithmic components touching personal data, expressed by function rather than by repository, so the hosting, display, modification and sharing paths are all represented.
  • A stated risk question per component — what could this do to a Data Principal if it behaved as designed, and what if it behaved badly. Mis-ranking, over-exposure, wrongful deletion and misattribution are the usual answers.
  • Evidence of testing against that question, not just that the system works. A ranking change tested only for latency has not been diligenced.
  • A dated review record and a gate on change, so a model or rule change re-enters review rather than inheriting last year's conclusion.

Note what the duty does not say. It does not ask you to prove the absence of risk, and names no fairness metric or audit standard. It asks for diligence proportionate to likely harm, so your defence is the quality of the examination, not the perfection of the system.

The Rule 13(4) Localisation Duty

The localisation duty is rule 13(4), and it is narrow in 3 ways. It applies only to notified Significant Data Fiduciaries. It bites only on personal data the Central Government specifies, on the recommendation of a committee constituted for that purpose. And when it bites, it stops that specified personal data, together with its traffic data, being transferred outside India.

So the duty is a mechanism awaiting content, and the planning question is architectural rather than immediate: if a category you hold were specified tomorrow, could you confine it and its traffic data to Indian infrastructure without re-platforming?

Where Teams Get DPDP Data Localisation Wrong

Treating DPDP data localisation as a blanket rule is the most common error in circulating summaries, and it drives unnecessary spending. No general requirement under DPDP says personal data must stay in India.

Cross-border transfer for everyone else sits in a separate rule, and it is permissive: personal data may be transferred outside India, subject to requirements the Central Government may specify by general or special order regarding making that data available to a foreign State or an entity under its control. That is a conditional permission, not a prohibition — more permissive than the draft that preceded it and than most teams assume. Our cross-border transfer rules breakdown sets out what it turns on.

So an ordinary Data Fiduciary that migrates its estate into an Indian region to satisfy DPDP has bought a constraint the Rules never asked for — while a notified SDF cannot assume that permission covers it, because rule 13(4) overrides it for whatever gets specified.

What to Prepare Before You Are Notified

If you have not been notified, prepare the 3 things with long lead times and skip the ones that are cheap to start late. The appointments and the architecture are slow; the annual cadence is not.

  • Know where an India-resident DPO would come from. Internal candidate or market hire, the answer takes months, and the reporting line to the board takes a governance decision.
  • Keep the algorithmic inventory current. It earns its keep in breach scoping and vendor review regardless of SDF status, and reconstructing it under a deadline is painful.
  • Avoid single-region lock-in. Not migration — optionality. Knowing which datastores could be confined to India is the difference between a config change and a replatform.

What is not worth doing early is appointing an independent data auditor against a duty that does not yet apply. Run the DPIA because the processing warrants one, not because rule 13 might.

Questions on Significant Data Fiduciary Notification

Questions on Significant Data Fiduciary notification come up most often once a team realises the category is conferred rather than self-assessed.

You are one if the Central Government has notified you, or a class you belong to, as significant under section 10. No size, revenue or sensitivity threshold confers the status, and no self-assessment produces it. The accurate questionnaire answer is "we have not been notified as a Significant Data Fiduciary," never "we are below the threshold."

No. The requirement for a DPO based in India who represents the entity, is responsible to the Board of Directors or equivalent governing body, and is the point of contact for grievance redressal sits in section 10(2) and applies to notified SDFs. Ordinary Data Fiduciaries must publish a contact point and run grievance redressal, which is not the same specified role.

No. Personal data may be transferred outside India, subject to requirements the Central Government may specify by general or special order regarding making that data available to a foreign State or an entity under its control. The restrictive duty is rule 13(4): notified SDFs only, and only for personal data the Central Government specifies on a committee's recommendation, together with its traffic data.

Rule 13 requires due diligence that algorithmic software used for hosting, display, upload, modification, publication, transmission, storage, updating or sharing of personal data is not likely to pose a risk to Data Principals' rights. No method is prescribed. A defensible reading: an inventory of in-scope components, a stated risk question for each, evidence of testing against it, a dated review record, and a gate on change.

Rule 13 requires a DPIA and an audit once every twelve months, which reads as two exercises with distinct outputs. They can share scoping work and a calendar slot, but one merged report is hard to defend if the regulator asks which findings came from which.

Keep the SDF duties auditable before the designation arrives

Book a demo and we'll show how Konfirmity holds the DPIA and audit cadence, the algorithmic inventory, and the evidence behind each rule 13 duty in one place.

Book a demo

Treat Notification as a Governance Milestone, Not a Surprise

Notification under section 10 is a governance milestone, and the companies that handle it well decided in advance who the India-resident DPO would be and which datastores could be confined. Neither decision is reversible in a quarter.

The 4 duties that follow are not exotic: an annual assessment and audit with a named owner, a report whose significant observations you selected by a stated rule, an inventory of the software that moves personal data, and the ability to pin a specified category to Indian infrastructure. Three of the four are good practice for anyone holding personal data at scale. The Ministry of Electronics and Information Technology publishes the Act and Rules at meity.gov.in.

Start with the duties that apply regardless. Work the DPDP compliance checklist to closure first — notice, consent, safeguards, breach intimation and rights fulfilment carry no threshold at all, and an SDF that has not finished those will fail on them long before rule 13 is tested.

Tools

Put your DPDP plan into numbers

More DPDP guides

Related Articles

DPDP Breach Notification: The Two Clocks in Rule 7

Risk & Incidents

amit-gupta

2026-10-05

DPDP Breach Notification: The Two Clocks in Rule 7

arrow

Rule 7 gives the Board a 72-hour detailed submission, but affected individuals must be told without delay. The DPDP breach notification runbook, clock by clock.

DPDP Consent Notice Requirements: What Rule 3 Actually Demands

Data & Privacy

amit-gupta

2026-10-05

DPDP Consent Notice Requirements: What Rule 3 Actually Demands

arrow

What rule 3 demands of a DPDP consent notice: an itemised description of data and purposes, standalone wording, and withdrawal as easy as giving consent was.

DPDP Cross Border Data Transfer: Rule 15, Rule 13(4) and What Each One Actually Restricts

Data & Privacy

amit-gupta

2026-10-05

DPDP Cross Border Data Transfer: Rule 15, Rule 13(4) and What Each One Actually Restricts

arrow

Rule 15 permits DPDP cross border data transfer outside India. The only localisation duty sits in rule 13(4) and applies to Significant Data Fiduciaries.

Data Principal Rights Under DPDP: Rule 14 as a Build Specification

Data & Privacy

amit-gupta

2026-10-05

Data Principal Rights Under DPDP: Rule 14 as a Build Specification

arrow

Rule 14 of the DPDP Rules makes Data Principal rights a product surface: published request means, an identifier scheme, nomination, and a ninety-day clock.

DPDP Data Retention and Erasure: What Rule 8 Actually Requires

Data & Privacy

amit-gupta

2026-10-05

DPDP Data Retention and Erasure: What Rule 8 Actually Requires

arrow

DPDP data retention pulls two ways. Rule 8 forces erasure after three years of inactivity for three named classes, and a one-year floor on everybody else.

DPDP Act Penalties: The Seven Bands and What They Attach To

Legal & Contracts

amit-gupta

2026-10-05

DPDP Act Penalties: The Seven Bands and What They Attach To

arrow

DPDP Act penalties run in seven bands up to 250 crore rupees, and the largest attaches to a single duty. What the Schedule says, and what it does not say.

How Real Security Becomes Compliance

Built by the CTO who scaled NIUM to $2 billion. 10 years building security and compliance for regulated fintechs. 4.5 years running Konfirmity profitably.

Book a call