DPDP Act 2023 Series · #10 · Module 2 · Core DPDP Concepts

Significant Data Fiduciary (SDF)

Who Are They — and Why Do They Carry Additional Responsibilities Under the Digital Personal Data Protection Act, 2023?

Significant Data Fiduciary illustration

What Is a Data Fiduciary?

Before we talk about Significant Data Fiduciaries, let's establish the baseline. Under the DPDP Act, a Data Fiduciary is any person, company, or organization that determines the purpose and means of processing personal data. They are responsible for collecting, storing, and using data — and must do so lawfully and responsibly.

Determines Purpose

Decides why personal data is collected and what it will be used for.

Determines Means

Decides how the data is processed, stored, and shared.

Bears Accountability

Is legally responsible for protecting the data of every Data Principal.

Every organization that processes personal data of Indian citizens is likely a Data Fiduciary — but not every one is a Significant Data Fiduciary.

Not Every Data Fiduciary Is an SDF

The DPDP Act creates a two-tier framework. While all Data Fiduciaries have baseline obligations, the Central Government has the power to notify certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) — based on a structured risk assessment, not simply because an organization is large or well-known.

1. Data Fiduciary

Any entity processing personal data. Subject to general DPDP obligations.

2. Government Assessment

Central Government evaluates risk factors defined under the Act.

3. Significant Data Fiduciary

Notified entities with enhanced obligations and higher accountability.

Illustration of Significant Data Fiduciary designation

How Does the Government Decide? The Risk Factors

Designation as an SDF is a risk-based determination. The Central Government considers a defined set of factors before notifying any organization. These factors reflect both the scale of data processing and the broader societal risks involved.

Volume of Personal Data

How much personal data is processed — large-scale processing inherently carries greater risk of harm if misused or breached.

Sensitivity of the Data

Health records, financial data, biometrics, and similar categories demand higher protection due to their potential for serious harm.

Risk to Rights of Data Principals

Processing that could damage the privacy, dignity, or fundamental rights of individuals warrants additional scrutiny.

National & Public Interest Risks

Impact on sovereignty, electoral democracy, state security, and public order are critical factors in the Government's assessment.

It's About Risk — Not Just Size

A Small Organization CAN Be High-Risk

A boutique genetic testing company with 10,000 users processes deeply sensitive biometric and health data. Its small size does not reduce the potential harm of a breach or misuse.

A Large Organization May Not Always Qualify

A large retail chain processing basic purchase history and loyalty card data may not automatically meet the threshold for SDF designation — even if it serves millions of customers.

Risk is determined by what data is processed and what harm could result — not headcount or revenue.

The Government evaluates all relevant factors holistically before making a determination.

Key Principle: Designation follows risk, not company size, brand prominence, or revenue.

Who Could Be Designated as an SDF?

While only the Central Government can formally designate an SDF, the following types of organizations are illustrative examples of entities that may meet the risk threshold — based on the scale and sensitivity of their data processing activities.

Large Hospital Networks

Processing millions of sensitive patient health records across facilities.

National Banks & NBFCs

Holding financial, identity, and transactional data of crores of customers.

Social Media Platforms

Aggregating vast personal, behavioral, and demographic data at national scale.

Major E-Commerce Platforms

Combining purchase, location, financial, and behavioral profiles of millions.

Government Digital Platforms

Operating large-scale citizen-facing systems handling identity and welfare data.

Large HealthTech Companies

Processing clinical, diagnostic, and personal health information at scale.

These are illustrative examples only. Actual designation requires formal notification by the Central Government.

Additional Obligations of an SDF

Once designated, an SDF must go beyond the standard DPDP compliance framework. These additional obligations are designed to ensure stronger governance, independent oversight, and proactive risk management for organizations whose data processing could have significant societal impact.

1. Data Protection Officer (DPO)

Appoint a qualified DPO — typically a senior employee — who is accountable to the Board and serves as the primary point of contact for data protection matters.

2. Independent Data Auditor

Engage an independent auditor to evaluate compliance with the Act and applicable rules, providing an objective external review of data practices.

3. Data Protection Impact Assessment (DPIA)

Conduct periodic DPIAs to identify, assess, and mitigate privacy risks before and during high-risk data processing activities.

4. Periodic Audits & Risk Management

Undertake regular audits and implement additional risk management measures as prescribed, ensuring continuous compliance and accountability.

The Hospital Example: Why Additional Safeguards Matter

Scenario

Consider a large hospital network with facilities across multiple states, processing millions of patient records — including diagnoses, treatment histories, prescriptions, and financial information.

This is among the most sensitive personal data that exists. A breach could cause irreparable harm — discrimination, financial loss, or reputational damage to patients.

Why Stronger Governance Becomes Necessary

  • Large-scale processing of health data multiplies the potential impact of any privacy failure.
  • Patients have limited ability to protect themselves once data is shared with a healthcare provider.
  • A DPO ensures ongoing accountability at the Board level.
  • DPIAs help identify risks in new systems or processes before they cause harm.
  • Independent audits build patient trust and demonstrate genuine commitment to privacy.
Additional safeguards under SDF designation protect both the patients (from harm) and the organization (from liability, reputational damage, and regulatory penalties).

Data Fiduciary vs. Significant Data Fiduciary

Here is a clear side-by-side comparison of how the two categories differ under the DPDP Act, 2023.

DimensionOrdinary Data FiduciarySignificant Data Fiduciary
ObligationsGeneral DPDP obligationsGeneral + Additional obligations
Governance LevelStandard governanceEnhanced, Board-level governance
Data Protection OfficerNot mandated at this levelDPO appointment required
AuditsRegular complianceIndependent Data Auditor required
Impact AssessmentNot specifically mandatedPeriodic DPIA required
Risk ProfileStandard risk-based complianceHigher-risk processing, heightened accountability
DesignationAutomatic — processes personal dataOnly by Central Government notification

Common Misconceptions — Clarified

❌ "Every large company is automatically an SDF."

Fact: Size alone does not determine SDF status. Only the Central Government, after evaluating defined risk factors, can designate an organization as an SDF through formal notification.

❌ "Every hospital is automatically an SDF."

Fact: A small clinic processing a limited number of records may not meet the risk threshold. Designation depends on scale, sensitivity, and assessed risk — not on sector alone.

❌ "Small organizations need not worry about SDF obligations."

Fact: A small organization processing highly sensitive data — such as genetic information or financial records — could potentially be assessed for SDF designation based on risk, not size.

❌ "We can self-declare as an SDF for branding purposes."

Fact: SDF is a legal designation made exclusively by the Central Government. It is not a voluntary certification, badge, or self-declared status.

Why Every Organization Should Understand SDF Obligations

Even if your organization is not currently designated as an SDF, understanding these obligations offers a strategic advantage. The SDF framework represents best-in-class privacy governance — and the benefits extend to every organization that takes data protection seriously.

Better Governance

Better Governance

Structured data protection roles and oversight frameworks improve decision-making across the organization and reduce internal privacy failures.

Stronger Privacy Culture

Stronger Privacy Culture

Embedding privacy practices — inspired by SDF standards — creates an organization-wide mindset that reduces risk and builds resilience.

Improved Risk Management

Improved Risk Management

Regular impact assessments and audits help identify vulnerabilities before they become costly incidents, protecting both data and reputation.

Customer Trust & Future Readiness

Customer Trust & Future Readiness

Organizations that adopt strong privacy governance today are better positioned for regulatory changes tomorrow — and earn deeper trust from customers and partners.

Key Takeaways

1. SDF Is a Risk-Based Concept

Designation is driven by the volume and sensitivity of data processed, and the potential risk to individuals, institutions, and national interest — not company size or sector.

2. Only the Central Government Can Designate an SDF

There is no self-designation, automatic classification, or sector-wide assumption. Formal notification by the Central Government is the only path to SDF status.

3. SDFs Carry Enhanced Compliance Obligations

DPO appointment, independent audits, periodic DPIAs, and additional risk management measures go beyond the baseline requirements for all Data Fiduciaries.

4. Strong Privacy Governance Benefits Every Organization

Whether or not you are designated, adopting SDF-grade governance practices builds trust, reduces risk, and prepares your organization for the evolving data protection landscape.

Coming Up Next in This Series

The next edition of this executive education series on the DPDP Act, 2023 will cover:

📋 Data Protection Officer (DPO)

Roles, responsibilities, and importance of the DPO under the Digital Personal Data Protection Act, 2023 — and what it means for your organization.

DPDP Act 2023 Series · Module 2 → DPDP #11 - Data Protection Officer (DPO)

Stay informed. Stay compliant. Stay ahead.

Upcoming Data Protection Officer module

Disclaimer

⚠️ Important Notice

This presentation is intended solely for educational and professional awareness purposes. It provides a general overview of the subject matter discussed. While every effort has been made to ensure the accuracy of the information presented, the content should be read in conjunction with the applicable laws, rules, regulations, official guidance, and judicial developments. The application of law and professional practices may vary depending on the specific facts and circumstances of each case.

Disclaimer artwork