Significant Data Fiduciary Applies from 13 May 2027

Do you need a DPO or a DPIA? Only if the government notifies you

A man in a blue shirt at his desk reviewing a printed sheet while a colleague sits across from him, files and a monitor behind them.

Only a Significant Data Fiduciary, a business the Central Government notifies, must appoint a Data Protection Officer, appoint an independent data auditor and run impact assessments, which the Rules require once every twelve months. The Act asks no other business for these. The extra duties start on 13 May 2027.

Last checked against the official text: Updated 5 min read

On this page
  1. The short answer
  2. Who becomes a Significant Data Fiduciary
  3. What a notified business must do
  4. What every other business does
  5. Startups and the extra duties
  6. What this does not tell you
  7. Our view: what to do now
  8. Common questions
  9. Sources

Many guides tell businesses to appoint a Data Protection Officer and to run an impact assessment. The DPDP Act asks for both only from a Significant Data Fiduciary, and only the Central Government can make a business one. This page sets out who that is, which extra duties follow, and what every other business still has to do about a contact person. It covers the Act, the Rules and the commencement notification only. The sections on the law are cited in the Sources box. The section marked Our view is our opinion and carries no citation.

The short answer

A Significant Data Fiduciary is a Data Fiduciary, or a class of Data Fiduciaries, that the Central Government notifies. Only a notified business must appoint a Data Protection Officer, appoint an independent data auditor, and run periodic Data Protection Impact Assessments (DPIAs). The Act does not ask any other business for these three. Those duties start on 13 May 2027, eighteen months after the commencement notification of 13 November 2025.

Who becomes a Significant Data Fiduciary

The government decides, by notification, on the basis of an assessment of factors it determines. The Act lists six, and the word “including” shows that the list is open:

  • the volume and sensitivity of the personal data processed;
  • the risk to the rights of Data Principals;
  • the potential impact on the sovereignty and integrity of India;
  • the risk to electoral democracy;
  • the security of the State; and
  • public order.

The Act gives the power to the Central Government and has no route for a business to declare itself one. The texts of the Act and the Rules set no number of users, records or rupees of turnover at which a business is notified. We have not seen any notification of a Significant Data Fiduciary, or of a class of them, in the texts this page relies on. Check the Gazette for the current position before you rely on any list.

The Rules let the Central Government call for information from a Data Fiduciary so that it can carry out this assessment. The request comes through an officer of the Ministry of Electronics and Information Technology whom the Secretary designates. That power also starts on 13 May 2027.

What a notified business must do

A man in a blue shirt at his desk with stacks of files and two monitors, a pen in his hand.
DutyWhat the text says
Data Protection OfficerAn individual who represents the business under the Act, is based in India, is responsible to the Board of Directors or a similar governing body, and is the point of contact for the grievance redressal mechanism
Independent data auditorAppointed to carry out a data audit that evaluates the business’s compliance with the Act
Data Protection Impact AssessmentA process that describes the rights of Data Principals and the purpose of the processing, and assesses and manages the risk to those rights. Done periodically, and under the Rules once in every period of twelve months from the date of notification
Periodic auditDone together with the impact assessment once every twelve months, to check that the Act and the Rules are observed
Report to the Data Protection BoardThe person who carries out the assessment and the audit gives the Board a report with their significant observations
Technical measuresDue diligence to verify that the technical measures it uses to host, display, upload, change, publish, send, store, update or share personal data, including algorithmic software, are not likely to pose a risk to the rights of Data Principals
Data kept in IndiaMeasures so that personal data the Central Government specifies, on the recommendation of a committee, and the traffic data about its flow, are processed under a restriction that they are not transferred outside India

For a breach of the Act’s additional obligations of a Significant Data Fiduciary, the penalty may extend to ₹150 crore, set in the Schedule to the Act. The Board can impose it only after an inquiry finds the breach significant and the business has been heard. The penalties article explains how the ceilings work.

What every other business does

A business that is not notified has no duty to appoint a Data Protection Officer. It still has three duties that look similar:

  • A contact person. It must publish the business contact information of a Data Protection Officer, if applicable, or of a person who can answer questions from Data Principals about the processing of their personal data. The Rules add that this goes prominently on the website or app and in every response to a rights request.
  • A contact in each consent request. Every request for consent gives the contact details of a Data Protection Officer, where applicable, or of another person the business authorises to respond to the Data Principal.
  • A grievance mechanism. It must have an effective way to redress grievances, and publish a response period of no more than 90 days. The rights article covers it.

Startups and the extra duties

The Central Government may notify certain Data Fiduciaries, including startups, as businesses to which the Significant Data Fiduciary provisions do not apply. The startups article sets out that power and what we have and have not seen under it.

What this does not tell you

This page does not say which businesses the government will notify, and it names none. Other laws and sector rules may ask for a similar role or a similar assessment. We did not check them. The timeline shows where each date falls.

Our view: what to do now

Our view. This is the order we would work in. Apart from the dates set out above, it makes no claim about the law.

  1. Name a contact person. Choose one person who can answer a Data Principal, put the contact on your website and in your consent notice, and make sure your grievance process routes to the same person.
  2. Note your volume and sensitivity. Volume and sensitivity together are the first factor in the list above. A short note of what personal data you hold and how much of it is sensitive tells you quickly whether you could be assessed.
  3. Try one impact assessment. The Act asks for it only from Significant Data Fiduciaries. A written assessment of your riskiest process shows where the rights of your customers are most exposed.
  4. Watch the Gazette. Look for notifications from 13 May 2027 and note the twelve-month cycle that starts on the date of any notification that names you.

Common questions

What is a Significant Data Fiduciary?

A Data Fiduciary, or a class of Data Fiduciaries, that the Central Government notifies on the basis of an assessment of factors it determines. The Act lists six, including the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals. The list is open.

Do I need a Data Protection Officer?

Only if you are notified as a Significant Data Fiduciary. The Act defines a Data Protection Officer as an individual that a Significant Data Fiduciary appoints. Every other business must publish the business contact information of a Data Protection Officer, if applicable, or of a person who can answer a Data Principal’s questions about the processing of her personal data.

Is a DPIA mandatory for my business?

It is mandatory only for a notified Significant Data Fiduciary, which must run one periodically and, under the Rules, once in every period of twelve months from the date it is notified. The Act does not ask it of other businesses.

How many users or what turnover makes a business a Significant Data Fiduciary?

The Act and the Rules give no number. The government decides by notification, on the basis of factors that include the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals. We have not seen a notification naming any business or class in the texts this page relies on.

What is the penalty, and when do the duties start?

For a breach of the additional obligations of a Significant Data Fiduciary, the penalty may extend to ₹150 crore. The Board can impose it only after an inquiry finds the breach significant and the business has been heard. The duties start on 13 May 2027, eighteen months after the commencement notification.

Next steps

Sources

Every section, rule and date above was checked against the official text on 7 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)

  • Section 2(l)Data Protection Officer: an individual appointed by a Significant Data Fiduciary
  • Section 2(z)Significant Data Fiduciary: a Data Fiduciary or class the Central Government notifies
  • Section 6(3)A request for consent gives the contact details of a Data Protection Officer, where applicable, or of another person the business authorises
  • Section 8(9)Publish the business contact information of a Data Protection Officer, if applicable, or of a person who can answer questions
  • Section 8(10)An effective mechanism to redress grievances
  • Section 10(1)The Central Government may notify a Significant Data Fiduciary on the basis of an assessment of relevant factors: volume and sensitivity of data, risk to rights, sovereignty and integrity, electoral democracy, security of the State, public order
  • Section 10(2)A Data Protection Officer, an independent data auditor, periodic Data Protection Impact Assessment, periodic audit and other prescribed measures
  • Section 17(3)The Central Government may notify Data Fiduciaries, including startups, as exempt from this section and four others
  • Section 33(1)Penalty only if an inquiry finds a breach significant, after a hearing
  • Schedule, item 4Breach of the additional obligations of a Significant Data Fiduciary: penalty may extend to one hundred and fifty crore rupees

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4)Rules 3, 5 to 16, 22 and 23 in force eighteen months from publication
  • Rule 9Publish the contact information prominently and mention it in every response to a rights request
  • Rule 13(1) to (5)Once in twelve months a Data Protection Impact Assessment and an audit; report of significant observations to the Board; due diligence on technical measures; data specified by the government kept in India
  • Rule 14(3)A published grievance response period of no more than ninety days
  • Rule 23(1)The Central Government may call for information through an authorised person
  • Seventh Schedule, item 3Assessment for notifying a Significant Data Fiduciary: information called for through a Ministry of Electronics and Information Technology officer the Secretary designates

Notifications

Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)

  • G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17, 27 (except 27(1)(d)), 28 to 34, 36, 37 and 44(2) in force eighteen months from 13 November 2025

A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.