AMLEGALS — Strategic Lawyering

DPDPA for Boards: Significant Data Fiduciary and Governance

DPDPA for Boards: Significant Data Fiduciary and Governance

Significant Data Fiduciary is not a title. It is a target.

The scene

The board pack had a single slide on DPDPA, between treasury and CSR. It said 'on track'. Nobody asked on track to what. Nobody asked what would happen if the Government notified the company as a Significant Data Fiduciary next quarter.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

It's an operational matter.

Penalties up to ₹250 crore are balance-sheet events.

Treat exposure like credit risk: quantified, owned, reported.

We're not an SDF.

The Government notifies SDFs based on volume, sensitivity and risk; it is not self-declared.

Prepare as if you might be named.

The DPO will handle it.

A DPO without authority is a scapegoat with a title.

Give the role a board line, a budget and a veto.

What Significant Data Fiduciaries must do

Section 10 requires an India-based Data Protection Officer answerable to the board, an independent data auditor, periodic data protection impact assessments and audits, and other measures the Rules prescribe. The Rules add an annual cycle and scrutiny of algorithmic software.

Monday morning

01 Put DPDPA exposure on the risk register with a number, not a colour.

02 Ask management: if we were notified as an SDF tomorrow, what would change?

03 Schedule one board session on the worst-week scenario.

Questions, answered plainly

What is a Significant Data Fiduciary under DPDPA? +

A Significant Data Fiduciary is a Data Fiduciary or class notified by the Central Government under Section 10, considering factors such as volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security and public order.

What are the obligations of a Significant Data Fiduciary? +

It must appoint a Data Protection Officer based in India who is responsible to the board, appoint an independent data auditor, and carry out periodic data protection impact assessments and audits, along with measures in the Rules.

Argument 08 ₹250 crore is not a line item. It is a balance-sheet event. Read →

Argument 01 Implementation ends on a date. Resilience begins on it. Read →

Argument 02 Before data leaks, clarity leaks. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).