CHAPTER II - OBLIGATIONS OF DATA FIDUCIARY

Section 10 - Additional obligations of Significant Data Fiduciary

Official text

(1)The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including—

(a)the volume and sensitivity of personal data processed;

(b)risk to the rights of Data Principal;

(c)potential impact on the sovereignty and integrity of India;

(d)risk to electoral democracy;

(e)security of the State; and

(f)public order.

(2)The Significant Data Fiduciary shall—

(a)appoint a Data Protection Officer who shall—

(i)represent the Significant Data Fiduciary under the provisions of this Act;

(ii)be based in India;

(iii)be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and

(iv)be the point of contact for the grievance redressal mechanism under the provisions of this Act;

(b)appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and

(c)undertake the following other measures, namely:—

(i)periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed;

(ii)periodic audit; and

(iii)such other measures, consistent with the provisions of this Act, as may be prescribed.

Cross-references

Section 10

Commentary

1.1 Clause-by-clause commentary read with Rule 13 of the DPDP Rules, 2025

2. Opening structure of Section 10

Section 10 establishes a two-stage framework.

The first stage is designation. Under Section 10(1), the Central Government may notify a particular Data Fiduciary or a class of Data Fiduciaries as a Significant Data Fiduciary.

The second stage is enhanced compliance. Once a Data Fiduciary has been notified as an SDF, or falls within a class notified as SDFs, Section 10(2) and Rule 13 impose additional obligations concerning:

  • appointment of a Data Protection Officer;

  • appointment of an independent data auditor;

  • periodic Data Protection Impact Assessments;

  • periodic audits;

  • submission of significant observations to the Data Protection Board;

  • due diligence regarding technical measures and algorithmic software; and

  • restrictions on the transfer outside India of personal data specified by the Central Government and traffic data pertaining to its flow.

These obligations are additional to the obligations applicable to Data Fiduciaries generally. Designation as an SDF does not replace Sections 4 to 9. It means that the notified Data Fiduciary must comply with the generally applicable provisions and also satisfy the enhanced requirements under Section 10 and Rule 13.

3. Section 10(1): “The Central Government may notify”

The power to designate an SDF belongs to the Central Government.

A Data Fiduciary does not become an SDF merely because it processes a large volume of personal data or considers its processing sensitive. Formal notification is required.

This follows from the words:

“The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary.”

The statutory mechanism therefore does not operate through self-certification.

A Data Fiduciary may assess internally whether it is likely to be designated, but that internal assessment does not itself trigger Section 10. The additional statutory obligations arise when:

  1. the Data Fiduciary is individually notified; or

  2. it is included within a notified class of Data Fiduciaries.

This distinction is reflected in Rule 13(1), which calculates the twelve-month cycle from the date on which the Data Fiduciary:

  • is notified as an SDF; or

  • is included in a class notified as SDFs.

4. Meaning of “may”

The word “may” gives the Central Government the authority to make the designation after assessing relevant factors. It does not provide that every Data Fiduciary satisfying one or more factors automatically becomes an SDF.

Example

For example, a Data Fiduciary may process a substantial volume of personal data. That fact makes Section 10(1)(a) relevant to the Government’s assessment, but it does not independently confer SDF status.

The Central Government must still exercise the notification power.

5. Individual and class-based notifications

The provision permits notification of:

  • any Data Fiduciary, meaning a particular Data Fiduciary; or

  • a class of Data Fiduciaries, meaning a set of Data Fiduciaries falling within a description in the notification.

Where a class is notified, the legal question will be whether the particular Data Fiduciary comes within the terms of that class.

An organisation cannot assume that Section 10 does not apply merely because its name does not appear in the notification where the notification clearly covers its class.

Conversely, notification of one Data Fiduciary does not automatically notify its parent, subsidiary or affiliated company. Each entity’s position will depend on:

  • the terms of the notification;

  • the class, if any, that has been notified; and

  • whether the entity is itself a Data Fiduciary for the relevant processing.

6. “On the basis of an assessment”

The Central Government’s designation must be based on an assessment.

The Act does not prescribe:

  • a mathematical formula;

  • a scoring method;

  • a minimum number of Data Principals;

  • a minimum number of records;

  • a financial threshold;

  • an annual turnover threshold;

  • a mandatory consultation process.

Accordingly, no numerical threshold should be treated as part of Section 10 unless it appears in a notification issued by the Central Government.

The assessment may take into account the express statutory factors and any other relevant factors determined by the Central Government.

The Act does not say that every factor must be present. Nor does it prescribe the weight to be given to each factor. The Government may assess the factors individually and collectively according to the processing carried out by the Data Fiduciary or class.

7. “Such relevant factors as it may determine, including”

The word “including” indicates that the factors set out in paragraphs (a) to (f) are not necessarily exhaustive.

The Central Government may determine other relevant considerations when deciding whether to notify a Data Fiduciary or class as SDFs.

However, the Act does not identify what those additional factors might be. It would therefore be speculative to state that use of artificial intelligence, foreign ownership, market share, number of children, turnover or any other particular consideration is automatically an additional designation factor.

Such matters may become relevant depending on:

  • the Government’s assessment;

  • the circumstances of the processing; or

  • the language of a future notification.

Until then, the only express statutory factors are those contained in Section 10(1)(a) to 10(1)(f).

8. Section 10(1)(a): Volume and sensitivity of personal data processed

The first factor is:

“the volume and sensitivity of personal data processed.”

This requires consideration of both the amount of personal data processed and its sensitivity.

9. Volume

The Act does not define volume for Section 10.

Volume may refer to the scale of personal-data processing. The particular indicator used by the Government may depend on the notified class or Data Fiduciary.

Possible measures of volume could include the number of Data Principals, records or processing operations, but Section 10 itself does not select a metric.

It would therefore be incorrect to state that an entity becomes likely or certain to receive SDF designation when it crosses a particular number of users or transactions unless the Government formally adopts that threshold.

10. Sensitivity

The DPDPA does not create a separate statutory category called “sensitive personal data.” Nevertheless, Section 10 expressly directs attention to the sensitivity of personal data.

Sensitivity must therefore be understood in relation to the nature and context of the information and the consequences that may follow from its processing.

The provision does not provide a closed list of sensitive data categories. It leaves that assessment to the Central Government.

The reference to sensitivity does not alter the definition of personal data or create a separate legal ground. It functions as a designation factor for deciding whether enhanced obligations should apply.

11. Combined wording

The phrase does not state that both volume and sensitivity must independently cross a prescribed threshold.

The Central Government may assess their combined significance. The Act does not prescribe how they are to be balanced.

Accordingly, it should not be stated categorically that:

  • high volume and low sensitivity will always result in designation;

  • low volume and high sensitivity will never result in designation; or

  • both must be high.

Those conclusions would go beyond the statutory text.

12. Section 10(1)(b): Risk to the rights of Data Principals

The second factor is:

“risk to the rights of Data Principal.”

The relevant rights include the rights provided under the Act. These include:

  • access to information about personal data;

  • correction;

  • completion;

  • updating;

  • erasure;

  • grievance redressal;

  • nomination;

  • withdrawal of consent where consent is the processing basis.

The Central Government may assess whether the nature, scale or method of processing creates risk to the effective exercise or protection of those rights.

The provision refers to risk, not proven infringement. The Government is therefore not required to wait for:

  • a complaint;

  • a Board order;

  • a personal data breach;

  • a court judgment;

  • demonstrated individual loss.

The possibility or likelihood of adverse consequences may be considered during designation.

However, Section 10(1)(b) does not itself prescribe:

  • a formal risk methodology;

  • mandatory risk categories;

  • likelihood ratings;

  • severity ratings;

  • a particular balancing test.

Those matters may be adopted as assessment tools, but they should not be presented as express statutory requirements.

13. Section 10(1)(c): Potential impact on sovereignty and integrity of India

The third factor concerns:

“potential impact on the sovereignty and integrity of India.”

The word “potential” indicates that actual damage is unnecessary. The Government may consider whether the processing could affect sovereignty or integrity.

The provision does not define the circumstances in which such an impact arises. Nor does it state that:

  • all foreign-owned Data Fiduciaries create such an impact;

  • all cross-border processing affects sovereignty;

  • all mapping or location services must be notified;

  • all critical-infrastructure operators are automatically SDFs.

Those may be relevant factual circumstances, but the statutory question remains whether the processing has a potential impact on the sovereignty and integrity of India.

This factor is separate from the volume of data and risk to individual rights. A Data Fiduciary may be considered significant because the processing has implications at a national level even where the immediate individual-rights analysis does not fully capture the concern.

14. Section 10(1)(d): Risk to electoral democracy

The fourth factor is:

“risk to electoral democracy.”

This provision recognises that processing of personal data may have implications for electoral processes and democratic participation.

The Act does not define “risk to electoral democracy.” It also does not state that every Data Fiduciary involved in:

  • political advertising;

  • political communication;

  • social media;

  • electoral services;

  • data analytics;

must be designated as an SDF.

The Government must assess whether the Data Fiduciary’s processing creates the relevant risk.

The factor is not limited to political parties or candidates. A Data Fiduciary may process personal data in a manner relevant to electoral democracy even if its ordinary business is advertising, communication, social media, analytics or another service.

At the same time, Section 10(1)(d) is a designation criterion. It does not itself:

  • prohibit political advertising;

  • regulate electoral content;

  • create a separate lawful ground;

  • create a right to explanation;

  • determine the legality of a particular electoral communication.

Its function is to determine whether the Data Fiduciary should be subject to enhanced obligations under Section 10.

15. Section 10(1)(e): Security of the State

The fifth factor is:

“security of the State.”

The Act does not define the expression for Section 10.

It should not be equated automatically with:

  • cybersecurity of every private organisation;

  • protection against ordinary fraud;

  • protection of corporate confidential information;

  • prevention of private economic loss.

The factor concerns the effect of personal-data processing on the security of the State.

Whether a particular Data Fiduciary raises that concern will depend on the processing and the Government’s assessment.

This paragraph again operates at the designation stage. It does not itself confer any security or surveillance power on the Data Fiduciary or the Government.

16. Section 10(1)(f): Public order

The sixth factor is:

“public order.”

The provision does not define the exact nature or degree of public-order risk that would justify designation.

The Government may assess whether personal-data processing by a Data Fiduciary or class has consequences for public order.

This factor should not be treated as identical to difficulty, inconvenience or controversy. Its application must be determined through the Central Government’s assessment.

As with Sections 10(1)(c), (d) and (e), this paragraph does not itself create a substantive prohibition. It identifies a matter that may justify enhanced SDF obligations.

17. Section 10(2): Additional, not substitutive, obligations

Section 10(2) applies after designation.

The SDF remains a Data Fiduciary and remains subject to all applicable provisions of the Act and Rules.

The additional obligations do not replace:

  • lawful-purpose requirements;

  • notice;

  • consent;

  • legitimate-use requirements;

  • processor responsibility;

  • data-quality obligations;

  • reasonable security safeguards;

  • breach notification;

  • erasure;

  • child-data protection;

  • Data Principal rights.

Example

For example, completing a DPIA does not legalise processing that lacks a valid ground. Appointment of a DPO does not excuse a breach-notification failure. An audit report cannot validate targeted advertising directed at children contrary to Section 9.

Section 10 strengthens institutional accountability. It does not create a separate processing ground or exemption.

18. Section 10(2)(a): Appointment of a Data Protection Officer

Every SDF must appoint a DPO.

The Act states four characteristics or functions of the DPO:

  1. representation of the SDF;

  2. location in India;

  3. responsibility to the governing body;

  4. grievance contact.

The Act does not prescribe:

  • academic qualifications;

  • professional certifications;

  • minimum experience;

  • fixed tenure;

  • remuneration;

  • a mandatory internal or external appointment model.

Accordingly, it should not be stated that the DPO must possess a law degree, technical degree, privacy certification or specified number of years of experience.

The SDF must nevertheless appoint an individual capable of performing the express statutory functions.

19. Section 10(2)(a)(i): Representation of the SDF

The DPO must:

“represent the Significant Data Fiduciary under the provisions of this Act.”

The DPO is therefore the individual through whom the SDF may act or communicate in matters arising under the Act.

The provision does not list every representational activity. Depending on the context, representation may involve communications with the Data Protection Board, responses during proceedings or other official engagement under the Act.

The phrase does not transfer the SDF’s statutory responsibility to the DPO.

The SDF remains responsible for compliance under Section 8(1). The DPO is its representative, not a substitute Data Fiduciary.

The board of directors cannot avoid organisational responsibility by asserting that:

  • the DPO controlled privacy;

  • the breach was the DPO’s failure;

  • management relied on the DPO;

  • the DPO signed the report.

The SDF is the regulated entity.

20. Section 10(2)(a)(ii): DPO based in India

The DPO must:

“be based in India.”

The provision does not require Indian citizenship. It addresses where the DPO is based.

The Act does not define:

  • residence;

  • minimum physical presence;

  • place of employment;

  • remote-work requirements.

The ordinary implication is that the DPO’s professional base for the statutory role must be in India.

A multinational organisation may maintain a global privacy function outside India, but the individual appointed as the SDF’s statutory DPO must satisfy the India-based requirement.

An overseas privacy officer cannot alone fulfil this requirement merely because the organisation has an Indian office or an Indian email address.

21. Section 10(2)(a)(iii): Individual responsible to the governing body

The DPO must be:

“an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary.”

Three elements are important.

22. The DPO must be an individual

A department, committee, vendor or law firm cannot itself be the DPO.

A team may support the DPO. An external service provider may support the function. The designated DPO must nevertheless be an identified individual.

23. Responsibility to the board

The DPO must be responsible to the board of directors or equivalent governing body.

The provision creates a senior reporting relationship. It ensures that the DPO is accountable at the governing-body level rather than only within a lower operational department.

24. Similar governing body

This accommodates organisations that do not have a conventional company board.

The similar governing body may be the entity’s equivalent apex governing authority.

The Act does not prescribe:

  • reporting frequency;

  • mandatory meeting attendance;

  • board committee structure;

  • board-approved tenure;

  • removal procedure.

Those matters may be addressed in organisational governance, but they are not express statutory requirements.

25. DPO independence

The DPDPA does not expressly reproduce the GDPR provisions stating that a DPO must not receive instructions or be dismissed or penalised for performing the DPO role.

It would therefore be inaccurate to state that Section 10 expressly grants those protections.

The requirement that the DPO be responsible to the board nevertheless supports a degree of organisational standing necessary to perform the statutory functions.

The SDF should avoid assigning the role in a manner that makes performance impossible. For example, an individual who cannot communicate with the board or access relevant processing information may not be capable of representing the SDF effectively.

That conclusion follows from the practical requirements of the statutory role. It should not be converted into unprescribed fixed-tenure or dismissal protections.

26. Section 10(2)(a)(iv): Grievance-redressal point of contact

The DPO must be:

“the point of contact for the grievance redressal mechanism under the provisions of this Act.”

This links the DPO with the SDF’s grievance mechanism under Section 8(10).

The DPO does not necessarily have to investigate every grievance personally. The SDF may use:

  • support personnel;

  • privacy teams;

  • legal teams;

  • business teams;

  • processors.

However, the DPO must function as the statutory point of contact.

The mechanism should not direct grievances exclusively to a separate department in a manner that makes the DPO inaccessible or uninvolved.

Section 8(9) also requires publication of the DPO’s business contact information where applicable. The Act does not specifically require publication of:

  • the DPO’s personal mobile number;

  • residential address;

  • personal email;

  • complete identity details.

The contact information should be business information sufficient to permit communication.

27. Section 10(2)(b): Independent data auditor

The SDF must:

“appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act.”

The auditor has two statutory characteristics:

  1. independence; and

  2. responsibility for evaluating compliance.

28. Meaning of independence

The Act does not define independence or prescribe a detailed independence code.

It does not state:

  • mandatory rotation periods;

  • revenue-dependence limits;

  • prohibition on all consulting services;

  • professional qualifications;

  • external-auditor status;

  • cooling-off periods.

The SDF should nevertheless ensure that the auditor can evaluate compliance objectively.

An arrangement may raise concerns where the auditor:

  • audits its own decisions;

  • is controlled by the team being audited;

  • cannot access necessary evidence;

  • is required to suppress adverse findings.

Those concerns arise from the word “independent.” The exact governing standards may develop through future guidance, enforcement or professional practice.

29. Internal or external auditor

Section 10 does not expressly state that the independent data auditor must be external.

An internal audit function might claim independence through functional reporting and organisational separation. An external auditor may provide clearer independence in many circumstances.

The statutory question is whether the auditor is independent, not merely whether the auditor is on or off the payroll.

30. DPO and auditor

The DPO and independent data auditor perform different roles.

The DPO represents the SDF and participates in its internal governance. The auditor evaluates the SDF’s compliance.

Appointing the DPO as the independent auditor would create an obvious difficulty where the DPO is required to audit governance or controls in which the DPO participated.

The Act does not expressly prohibit the same person, but the independence requirement must be respected.

31. Scope of the data audit

The audit must evaluate compliance in accordance with the Act.

The audit should therefore concern the provisions applicable to the SDF, including the additional Section 10 obligations.

The Act and Rule 13 do not prescribe a detailed audit checklist. The scope should be sufficient to determine whether the SDF effectively observes the Act and Rules.

This may involve examination of:

  • applicable processing;

  • grounds;

  • notice;

  • consent;

  • processor arrangements;

  • data quality;

  • technical and organisational measures;

  • security safeguards;

  • breach notification;

  • erasure;

  • grievances;

  • children’s data;

  • Data Principal rights;

  • DPO appointment;

  • DPIAs;

  • algorithmic due diligence;

  • localisation requirements.

This list follows the compliance subject matter of the Act. It should not be treated as a separately prescribed audit schedule.

The audit should evaluate actual observance. A policy stating that data is erased does not prove that erasure occurs. The auditor may therefore need sufficient evidence to assess operation, not merely documentation.

32. Section 10(2)(c)(i): Periodic DPIA

The SDF must undertake a periodic Data Protection Impact Assessment.

Section 10 describes the DPIA as a process comprising:

  1. a description of the rights of Data Principals;

  2. a description of the purpose of processing their personal data;

  3. assessment of risk to the rights of Data Principals;

  4. management of those risks;

  5. other prescribed matters.

This is the statutory minimum content.

33. Description of rights

The DPIA must identify the relevant rights of Data Principals.

The DPIA should therefore not be limited to system security. It must assess the effect of processing on rights under the Act.

34. Purpose of processing

The purpose must be described sufficiently to allow the processing to be assessed.

A vague statement such as “business operations” would make meaningful risk assessment difficult.

The DPIA should identify what the SDF intends to achieve through the processing.

35. Assessment of risk

The DPIA must assess risk to rights.

The Act does not prescribe a particular scoring system. The SDF may adopt:

  • qualitative assessment;

  • quantitative assessment;

  • risk matrices;

  • narrative assessment.

The method should enable real assessment rather than mechanical completion.

36. Management of risk

The DPIA must address management of identified risks.

This means that it should not end with identification alone. It should explain how the SDF proposes to address the risk.

The Act does not prescribe the specific controls that must be used in every case. Controls will depend on the processing and relevant statutory obligations.

37. Rule 13(1): Once in every twelve-month period

Rule 13 gives precise content to the word “periodic.”

An SDF must undertake:

  • a DPIA; and

  • an audit, once in every period of twelve months from:

  • the date it is notified as an SDF; or

  • the date it is included in a notified class.

This creates a recurring annual obligation.

38. Calculation of the period

The reference date is the designation date, not:

  • the financial year;

  • the calendar year;

  • the date of DPO appointment;

  • the date of first processing.

Example

For example, if an SDF is notified on 1 July 2027, it must undertake the required DPIA and audit within the first twelve-month period beginning on that date and again in each subsequent twelve-month period.

The Rule does not prescribe:

  • a particular month;

  • a fixed due date within the period;

  • sixty-day or ninety-day submission deadlines.

39. DPIA and audit are separate

The use of “a Data Protection Impact Assessment and an audit” indicates two distinct exercises.

The DPIA assesses and manages rights risks.

The audit evaluates effective observance and compliance.

One document might contain material relevant to both, but the SDF must ensure that both statutory functions are performed.

40. Meaning of “undertake”

The Rule requires the SDF to undertake the DPIA and audit. It is not enough to:

  • schedule them;

  • appoint a consultant;

  • circulate a questionnaire;

  • begin evidence collection.

The processes must be meaningfully carried out within the relevant twelve-month period.

41. Rule 13(2): Report to the Board

Rule 13(2) provides that the SDF shall:

“cause the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations in the Data Protection Impact Assessment and audit.”

The relevant “Board” is the Data Protection Board of India. This is distinct from the “Board of Directors” expressly referred to in Section 10(2)(a)(iii).

42. Obligation of the SDF

The SDF has the duty to cause the report to be furnished.

It cannot say that submission was solely the assessor’s or auditor’s responsibility.

The SDF must establish an arrangement under which the relevant person prepares and furnishes the report.

43. Role of the person carrying out the assessment and audit

The person carrying out the DPIA and audit must furnish the report.

This wording places the reporting function with the person performing the assessment rather than exclusively with SDF management.

The Rule does not explain whether:

  • the same person must carry out both;

  • separate persons may prepare separate reports;

  • a consolidated report must be submitted.

The prudent reading is that where different persons carry out the DPIA and audit, the SDF should ensure that significant observations from both processes are furnished to the Board.

44. Significant observations

The Rule does not define “significant.”

The term indicates that the report need not reproduce every minor observation. It should include observations sufficiently important in the context of compliance, rights risk or effective observance.

Potential considerations in determining significance include:

  • seriousness;

  • scale;

  • recurrence;

  • impact on Data Principals;

  • systemic nature;

  • material statutory non-compliance;

  • unresolved risk.

These are interpretive considerations, not a prescribed significance test.

45. No express public-disclosure requirement

Rule 13(2) requires submission to the Data Protection Board. It does not require:

  • publication on the SDF’s website;

  • publication of a summary;

  • publication of the full report;

  • disclosure to all Data Principals.

Nor does it prescribe a sixty-day or ninety-day filing period in the text provided.

46. Rule 13(3): Due diligence regarding technical measures

Rule 13(3) requires an SDF to:

“observe due diligence to verify that technical measures including algorithmic software adopted by it” for listed personal-data operations “are not likely to pose a risk to the rights of Data Principals.”

The obligation has four elements:

  1. due diligence;

  2. verification;

  3. technical measures, including algorithmic software;

  4. risk to Data Principal rights.

47. “Technical measures including algorithmic software”

The phrase is broader than artificial intelligence.

Algorithmic software is expressly included, but the Rule also covers other technical measures adopted for processing.

The listed operations are:

  • hosting;

  • display;

  • uploading;

  • modification;

  • publishing;

  • transmission;

  • storage;

  • updating;

  • sharing.

The Rule therefore reaches technical systems involved in the handling of personal data even where the system does not make a decision about the Data Principal.

Example

Examples may include:

  • hosting platforms;

  • databases;

  • content-management systems;

  • transmission systems;

  • automated updating tools;

  • sharing interfaces;

  • algorithmic ranking;

  • automated classification.

The Act and Rule do not define algorithmic software. The expression should not be artificially restricted only to machine-learning systems.

48. “Adopted by it”

The technical measure must be adopted by the SDF.

This can include technical measures developed internally or obtained from another person and deployed by the SDF.

The fact that software is supplied by a vendor does not necessarily remove it from the words “adopted by it.” If the SDF selects and uses the software for relevant personal-data processing, it has adopted the technical measure for its operations.

The Rule does not prescribe the exact contractual documents or technical information the SDF must obtain from a vendor. The SDF must nevertheless perform enough due diligence to make the required verification.

49. “Observe due diligence to verify”

The Rule does not require absolute proof that a technical measure can never pose risk.

It requires due diligence directed towards verification.

Due diligence ordinarily indicates reasonable care appropriate to the circumstances.

The SDF should therefore have a documented basis for concluding that the relevant technical measure is not likely to pose risk to Data Principal rights.

The Rule does not prescribe a universal verification method. Depending on the technical measure, verification may involve:

  • review;

  • testing;

  • evidence from the provider;

  • monitoring;

  • assessment of operation;

  • examination of effects on rights.

These are possible methods of satisfying the Rule, not a prescriptive statutory checklist.

A vendor’s unexamined assertion that software is compliant may not provide a sufficient basis for the SDF itself to verify the position.

50. “Not likely to pose a risk to the rights of Data Principals”

The Rule is concerned with the likelihood of rights risk.

It does not say that technical measures must be entirely free from every conceivable risk. It requires due diligence concerning whether they are likely to pose risk.

The rights referred to are the rights of Data Principals under the Act.

A technical measure may create risk where, for example, it:

  • uses inaccurate information in an affecting decision;

  • prevents correction;

  • prevents erasure;

  • continues processing after withdrawal;

  • discloses information to unauthorised recipients;

  • makes grievances impossible to investigate.

These examples illustrate how technical measures may affect statutory rights. The Rule does not itself create a separate right to explanation, a right to human intervention or a general prohibition on automated decision-making.

Any commentary should therefore avoid importing such rights from the GDPR unless Indian law separately provides them.

51. Algorithms and Section 8(3)

Rule 13(3) should be read alongside Section 8(3).

Where personal data is likely to be used to make a decision affecting the Data Principal, the Data Fiduciary must ensure completeness, accuracy and consistency.

For an SDF using algorithmic software to support such decisions:

  • Section 8(3) governs the quality of personal data;

  • Rule 13(3) governs due diligence concerning technical and algorithmic risk;

  • the annual DPIA assesses and manages risk to rights;

  • the annual audit evaluates effective observance.

This does not create a new automated-decision regime. It means that the existing data-quality and SDF-specific obligations operate together.

52. Rule 13(3) and third-party software

Where an SDF deploys third-party algorithmic software, it remains responsible for due diligence.

The Rule does not require disclosure of:

  • source code;

  • proprietary model weights;

  • every training record;

  • every technical detail.

The necessary information will depend on what is required to verify rights risk.

Where the vendor’s confidentiality restrictions prevent the SDF from carrying out meaningful due diligence, the SDF must determine whether it can lawfully and responsibly adopt the system.

The Rule does not permit the SDF to avoid its obligation by delegating all verification to the software provider.

53. Rule 13(3) and continuing review

Rule 13(3) does not state that due diligence is performed only once every twelve months.

The annual DPIA and audit have an express twelve-month period. Algorithmic and technical due diligence does not have an express periodicity in Rule 13(3).

This means the SDF must apply due diligence in connection with the relevant technical measures as adopted and used.

It is reasonable to reassess the conclusion where there is a material change in:

  • the technical measure;

  • the personal data;

  • the purpose;

  • the operation;

  • the rights risk.

This follows from the continuing nature of using the technical measure. It should not be converted into an invented mandatory monthly, quarterly or event-specific statutory schedule.

54. Rule 13(4): Specified personal data and localisation

Rule 13(4) requires an SDF to take measures to ensure that personal data specified by the Central Government is processed subject to the restriction that:

  • the specified personal data; and

  • traffic data pertaining to its flow, are not transferred outside India.

This is not a blanket localisation obligation covering every item of personal data processed by every SDF.

Three conditions must be satisfied:

  1. the Central Government must specify the personal data;

  2. the specification must be based on recommendations of the Committee;

  3. the SDF must ensure that the specified data and associated traffic data are not transferred outside India.

Until personal data is formally specified, Rule 13(4) should not be described as localising every SDF database.

55. Personal data “specified by the Central Government”

The Rule does not itself list the categories of personal data subject to the restriction.

The operative scope will depend on the Central Government’s specification.

The specification may identify:

  • particular personal data;

  • a category;

  • personal data processed for a particular purpose;

  • data processed by a particular SDF or class.

The precise scope cannot be conclusively stated without the relevant specification.

An SDF should therefore identify which of its data falls within the words used by the Government rather than assume either that:

  • all personal data is covered; or

  • only a specifically named database is covered.

56. “Shall undertake measures to ensure”

The SDF must take effective measures to prevent prohibited transfer.

The Rule does not prescribe a fixed technical architecture.

Depending on the specified data and system design, relevant measures may concern:

  • storage;

  • access;

  • processors;

  • transmission;

  • backup;

  • system configuration.

Those are matters the SDF may need to address to ensure the statutory result.

The legal obligation is outcome-oriented: the specified personal data and relevant traffic data must not be transferred outside India.

Merely inserting a contractual statement that data will remain in India may be insufficient if the actual processing transfers it abroad.

57. “Not transferred outside the territory of India”

The Rule does not define transfer for this purpose.

The SDF must examine actual data flows.

Potential transfer situations may include:

  • foreign storage;

  • foreign backup;

  • transmission to a foreign processor;

  • foreign-hosted processing;

  • overseas access;

  • replication.

Whether a particular form of remote access, encrypted transmission or technical support amounts to a transfer may depend on the facts and future interpretation.

The prudent approach is to include those flows in the SDF’s assessment rather than assume that only permanent foreign storage is relevant.

The Rule concerns transfer outside India, not merely location of the primary server.

58. Traffic data pertaining to the flow

The restriction also applies to traffic data concerning the flow of the specified personal data.

The Rule does not define traffic data within Rule 13.

In its ordinary technical context, traffic data may concern the movement or transmission of data, including information about:

  • source;

  • destination;

  • routing;

  • timing;

  • session;

  • flow.

The precise scope should be determined from:

  • the relevant specification;

  • applicable legal definitions;

  • the technical architecture.

The inclusion of traffic data means that compliance should not focus only on the content of the personal-data record. Information concerning how that data moves may itself be subject to the restriction.

59. Rule 13(5): Committee

Rule 13 defines the Committee as one constituted by the Central Government for the purpose of the Rule.

It must include officials from the Ministry of Electronics and Information Technology and may include officials from other Central Government ministries or departments.

The Committee’s function under Rule 13(4) is recommendatory.

The legal sequence is:

  1. Committee considers the matter
  2. Committee recommends
  3. Central Government specifies personal data
  4. SDF applies the transfer restriction

The Committee’s recommendation alone does not amount to the Central Government’s specification.

An SDF should therefore rely on the formal governmental instrument specifying the data.

60. Rule 13 and corporate governance

The Act expressly requires the DPO to be responsible to the board of directors or equivalent governing body. It does not expressly prescribe an entire board privacy-governance framework.

Nevertheless, the governing body must be able to discharge its relationship with the DPO meaningfully.

At a minimum, the structure should permit the DPO to report on matters relevant to the statutory role.

A commentary should not convert that implication into invented requirements concerning:

  • mandatory quarterly meetings;

  • a privacy committee;

  • fixed board agendas;

  • written board approval of every DPIA;

  • mandatory director certification.

Those may be useful governance choices, but they are not found in Section 10 or Rule 13.

61. Interaction between the DPO, auditor, DPIA assessor and the Board

The statutory roles should remain distinct.

61.1 DPO

  • represents the SDF;

  • is based in India;

  • is responsible to the governing body;

  • is the grievance contact.

61.2 Independent data auditor

  • carries out the data audit;

  • evaluates compliance.

61.3 Person carrying out the DPIA and audit

  • furnishes the Data Protection Board with a report containing significant observations.

61.4 Data Protection Board

  • receives the Rule 13(2) report.

The same person may be involved in more than one function only where the statutory requirements, including auditor independence, remain satisfied.

The Act does not expressly require the DPO to conduct the DPIA. It also does not expressly prohibit the DPO from participating in it.

The SDF should determine the arrangement while preserving:

  • effective assessment;

  • independent audit;

  • direct regulatory reporting;

  • governing-body accountability.

62. No unprescribed SDF obligations

Section 10 and Rule 13 do not expressly require:

  • public publication of the audit;

  • a public algorithm transparency report;

  • public disclosure of the DPIA;

  • mandatory annual DPO certification;

  • cyber insurance;

  • a fixed audit-firm rotation period;

  • specific DPO qualifications;

  • a universal right to algorithmic explanation;

  • a universal human-review right;

  • blanket localisation;

  • a ninety-day post-designation roadmap;

  • fixed remediation periods.

Such practices may be adopted voluntarily or required by another law, a future notification or a Board direction. They should not be attributed to Section 10 or Rule 13 without that additional legal basis.

63. Penalty position

A breach of the additional obligations of an SDF may attract a monetary penalty under the DPDPA Schedule.

The statutory amount is a maximum, not an automatic penalty.

The Section 10 penalty is civil and regulatory. It should not be described as a criminal punishment.

Where the same conduct also breaches another provision, such as:

  • security obligations;

  • breach notification;

  • children’s-data requirements;

  • processor obligations;

those contraventions may require separate legal analysis.

64. Consolidated interpretation

Section 10 establishes an enhanced compliance structure for Data Fiduciaries selected through Central Government notification.

The designation is not automatic. It follows an assessment and may apply to a particular Data Fiduciary or a notified class. The Government may consider the six listed factors and other relevant considerations, but no numerical designation threshold appears in the Act itself.

The SDF must appoint an identified individual as DPO. That person must represent the SDF, be based in India, be responsible to its highest governing body and function as the grievance contact. The Act does not prescribe specific qualifications, certifications, tenure or GDPR-equivalent independence protections.

The SDF must appoint an independent data auditor. Independence is mandatory, but the Act does not prescribe a detailed professional code. The auditor’s statutory role is to evaluate the SDF’s compliance with the Act.

The DPIA must address Data Principal rights, the processing purpose, rights risks and management of those risks. Rule 13 requires both the DPIA and audit once in every twelve-month period calculated from designation.

The person carrying out the DPIA and audit must furnish the Data Protection Board with a report containing significant observations. The Rule does not prescribe public disclosure, a fixed reporting deadline or a detailed report format.

The SDF must conduct due diligence regarding technical measures, including algorithmic software, adopted for specified personal-data operations. The obligation is directed at likely risks to Data Principal rights. It does not create a separate right to explanation or a general prohibition on automated decisions.

Finally, Rule 13 creates a targeted localisation requirement. The restriction applies only to personal data specified by the Central Government on the Committee’s recommendation and to traffic data pertaining to the flow of that specified data. It does not impose universal localisation on every item of personal data processed by every SDF.

Key point

The controlling proposition is:

Key point

Section 10 requires a notified Significant Data Fiduciary to establish the specific institutional safeguards named in the Act and Rule 13, but those obligations must be interpreted according to their enacted limits: notification-based designation, an India-based DPO, independent audit, annual DPIA and audit, reporting of significant observations, technical and algorithmic due diligence, and localisation only for data formally specified by the Central Government.

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.