SDF
What is a Significant Data Fiduciary (SDF)?
Significant Data Fiduciaries face extra DPDP duties — a DPO in India, annual DPIAs, and audits. Find out if you're likely one, and what it means.
Most organizations under the DPDP Act are Data Fiduciaries. A subset — those that handle data at higher volume or higher risk — can be notified as Significant Data Fiduciaries (SDFs), and they carry extra duties. This guide explains who's likely an SDF and what it means.
What makes a Data Fiduciary "significant"
The government can notify an organization (or a class of them) as an SDF based on an assessment of relevant factors, including:
- the volume and sensitivity of personal data processed,
- the risk to the rights of Data Principals,
- potential impact on the sovereignty and integrity of India,
- risks to electoral democracy, state security, and public order.
There's no single magic number — it's a risk-based judgment. But as a rule of thumb, large user bases and sensitive data push you toward SDF territory.
Who's likely an SDF
Strong candidates include:
- Fintech — sensitive financial and KYC data.
- Healthtech — health records, often children's data.
- Large e-commerce, online gaming, and media & social platforms — high volume, profiling, behavioural data.
If that sounds like you, plan as if you'll be notified.
The extra duties of an SDF
Being an SDF adds specific, ongoing obligations:
1. Appoint a Data Protection Officer (DPO)
You must appoint a DPO based in India who reports to your board/governing body and acts as the point of contact for grievances. A senior in-house DPO can cost ₹20–40 lakh a year — which is why many organizations use DPO-as-a-Service instead.
2. Conduct an annual DPIA
A Data Protection Impact Assessment — a structured review of the risks your processing poses to Data Principals and how you mitigate them — must be carried out periodically (annually).
3. Undergo an annual independent audit
An independent data auditor must assess your compliance each year. Your DPO coordinates this and manages the evidence.
4. Other measures
The government may specify additional measures, which can include obligations around algorithmic processing and data flows.
Why this matters even if you're not sure
Two reasons:
- The duties are continuous. A DPO, an annual DPIA, and an annual audit are a standing program, not a one-off — so it pays to design for them early.
- The penalties are higher. Breaching SDF-specific obligations carries penalties up to ₹150 crore, on top of the general regime. See Penalties & Enforcement.
Find out where you stand
Don't wait for a notification to start preparing. A readiness audit gives you a likely SDF determination and a plan; the free DPDP Quick Scan gives you an instant first read.
General information, not legal advice. SDF status is determined by government notification — confirm your position with qualified advice.
Frequently asked questions
The government notifies SDFs based on factors like the volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security, and public order. There's no single number — but high volume or sensitive data makes it more likely. Our readiness audit assesses your likelihood.
Appointing a Data Protection Officer based in India, conducting an annual Data Protection Impact Assessment, undergoing an annual independent data audit, and other additional measures the government may specify.
See how this applies to you
The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.
Take the free Quick Scan