Are you a Significant Data Fiduciary? The test, and why it matters

A higher DPDP obligation tier applies to designated organisations. The criteria are broader than volume alone.

DPDP creates a higher obligation tier called the Significant Data Fiduciary. Most Indian marketing teams assume it will not apply because they are not large. Volume is only one criterion.

What triggers designation

The Central Government designates based on volume and sensitivity of personal data processed, risk to data principals, potential effect on the sovereignty and integrity of India, risk to electoral democracy, and security of the state and public order.

Sensitivity sits alongside volume. A small company processing health data at modest scale can plausibly attract more scrutiny than a large one processing newsletter signups.

The extra obligations

  • A Data Protection Officer based in India, answerable to the board
  • An independent data auditor and periodic data protection impact assessments
  • Periodic audits and other prescribed measures

These are not paperwork. A DPO based in India reporting to the board is a hire. An independent auditor is a recurring cost.

If you are near the line

Nobody self-designates. You are designated. So the useful preparation is not declaring yourself one, it is surviving becoming one without a scramble.

Two artefacts carry most of that weight: a current record of what personal data you process and why, and knowing which of it is health, financial or children data. Those are what an auditor asks for first, and building them retroactively across a live stack takes months.

General information, not legal advice. Rules current as of July 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *