Section 10: The SDF Designation Power
Section 10 of the DPDPA empowers the Central Government to notify any Data Fiduciary, or class of Data Fiduciaries, as a Significant Data Fiduciary (SDF). The designation is based on an assessment of: (a) the volume and sensitivity of personal data processed, (b) risk to the rights of Data Principals, (c) potential impact on the sovereignty and integrity of India, (d) risk to electoral democracy, (e) security of the State, and (f) public order.
When MNC Subsidiaries Cross the Threshold
India subsidiaries of multinational companies can cross the SDF threshold in several ways. The most common: (a) the subsidiary processes personal data of a large number of Indian Data Principals (the volume trigger), (b) the subsidiary processes sensitive categories of data such as health data, financial data, or biometric data at scale, (c) the subsidiary is in a sector that the government considers strategically sensitive (telecom, defence, critical infrastructure), or (d) the subsidiary's data processing poses potential risks to national security or public order.
Enhanced Obligations of an SDF
Once designated, an SDF must: (a) appoint a Data Protection Officer (DPO) based in India who represents the SDF before the Board (Section 10(2)(a), Rule 11), (b) appoint an independent data auditor to conduct periodic audits (Section 10(2)(b), Rule 12), (c) conduct Data Protection Impact Assessments (Section 10(2)(c), Rule 13), (d) take additional measures as prescribed, including algorithmic audits for automated processing decisions.
The DPO Requirement
The DPO appointed by an SDF must be based in India and must be senior management. This creates a practical problem for lean subsidiary operations — a dedicated, India-based, senior DPO is a significant resource commitment. The DPO reports directly to the Board of Directors of the SDF entity and acts as the point of contact for the Data Protection Board of India. The DPO cannot be a shared resource based outside India, even if the global parent has a Group DPO in another jurisdiction.
Audit Obligations
Rule 12 prescribes the audit framework. The independent data auditor must evaluate: the completeness and accuracy of the description of processing, the appropriateness of automated processing and associated safeguards, the data security measures, and the effectiveness of measures to prevent data breaches. The audit report is submitted to the Board. Non-compliance identified in the audit must be remediated on a prescribed timeline.
Impact Assessment Obligations
Rule 13 mandates periodic DPIAs. For technology companies, this is particularly significant because the assessment must cover: (a) the rights of Data Principals, (b) the purpose and means of processing, (c) the categories and volume of personal data processed, (d) the risk of harm to Data Principals, and (e) the measures to manage and mitigate risk. Algorithmic processing — including AI and ML systems — must be specifically assessed.
How to Prepare Before Designation
Waiting for the SDF notification before beginning preparation is a strategic mistake. Companies that anticipate SDF designation should: (a) begin DPO recruitment immediately, (b) commission a baseline DPIA to identify gaps, (c) engage independent data auditors and establish the audit relationship, (d) implement board-level data protection governance, and (e) budget for the enhanced compliance infrastructure. The notification will set a compliance deadline — companies that have not prepared will face an impossible implementation timeline.

