DPDP creates a higher obligation tier called the Significant Data Fiduciary. Most Indian marketing teams assume it will not apply because they are not large. Volume is only one criterion.
What triggers designation
The Central Government designates based on volume and sensitivity of personal data processed, risk to data principals, potential effect on the sovereignty and integrity of India, risk to electoral democracy, and security of the state and public order.
Sensitivity sits alongside volume. A small company processing health data at modest scale can plausibly attract more scrutiny than a large one processing newsletter signups.
The extra obligations
- A Data Protection Officer based in India, answerable to the board
- An independent data auditor and periodic data protection impact assessments
- Periodic audits and other prescribed measures
These are not paperwork. A DPO based in India reporting to the board is a hire. An independent auditor is a recurring cost.
If you are near the line
Nobody self-designates. You are designated. So the useful preparation is not declaring yourself one, it is surviving becoming one without a scramble.
Two artefacts carry most of that weight: a current record of what personal data you process and why, and knowing which of it is health, financial or children data. Those are what an auditor asks for first, and building them retroactively across a live stack takes months.
General information, not legal advice. Rules current as of July 2026.