Chapter II — Obligations of Data Fiduciary
Section 10 — Additional obligations of Significant Data Fiduciary
10. (1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including—
(a) the volume and sensitivity of personal data processed;
(b) risk to the rights of Data Principal;
(c) potential impact on the sovereignty and integrity of India;
(d) risk to electoral democracy;
(e) security of the State; and
(f) public order.
(2) The Significant Data Fiduciary shall—
(a) appoint a Data Protection Officer who shall—
(i) represent the Significant Data Fiduciary under the provisions of this Act;
(ii) be based in India;
(iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and
(iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act;
(b) appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and
(c) undertake the following other measures, namely:—
(i) periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed;
(ii) periodic audit; and
(iii) such other measures, consistent with the provisions of this Act, as may be prescribed. CHAPTER III R IGHTS AND DUTIES OF DATA PRINCIPAL
Source: The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Act No. 22 of 2023, Gazette of India Extraordinary, 11 August 2023; SHA-256 4deb23981d30… — verified copy
Plain-language note
Plain-language note pending
Questions people ask about this provision
- What is a Significant Data Fiduciary under the DPDP Act?
- Who is required to appoint a Data Protection Officer under the DPDP Act?
- When is a Data Protection Impact Assessment (DPIA) required under the DPDP Act?
- What additional obligations apply to Significant Data Fiduciaries under the DPDP Act?
- What factors trigger Significant Data Fiduciary status under the DPDP Act?
- Are specific industries like insurance, banking, NBFCs, or automotive companies considered Significant Data Fiduciaries under the DPDP Act?
- What is the penalty for failing to meet Significant Data Fiduciary obligations under the DPDP Act?
- Does the DPDP Act require hiring a full-time Data Protection Officer or allow a virtual DPO?
Taught in Special Cases