Rule 13 establishes a higher and more continuous standard of accountability for a Data Fiduciary that the Central Government has notified as a Significant Data Fiduciary. It supplements Section 10 of the Digital Personal Data Protection Act, 2023 by prescribing an annual compliance cycle, direct reporting of significant audit and impact-assessment observations to the Data Protection Board, due diligence concerning technical and algorithmic systems, and a conditional localisation requirement for personal data later specified by the Central Government.
The Rule does not apply merely because an organisation is large, operates digitally, processes sensitive information or considers itself systemically important. The additional obligations begin when the Central Government formally notifies the particular Data Fiduciary or a class to which it belongs as a Significant Data Fiduciary under Section 10(1). Section 10 identifies the relevant designation factors as including the volume and sensitivity of personal data, risk to Data Principal rights, potential impact on sovereignty and integrity, electoral democracy, State security and public order.
Rule 13 is scheduled to come into force on 13 May 2027. However, the designation of a particular entity and some obligations under Rule 13 will depend on later notifications, including any notification specifying personal data that must remain within India.
A drafting correction should also be noted. The relevant Ministry is the Ministry of Electronics and Information Technology, not the “Ministry of Electronics and Technology.”