A Significant Data Fiduciary isn’t a label you apply to yourself. The Central Government decides who gets it, and once it lands, the compliance load changes shape entirely. Rule 13 of the Digital Personal Data Protection Rules, 2025 sets out exactly what changes: a resident Data Protection Officer, an independent auditor, an annual impact assessment, a check on your own algorithms, and possibly a hard limit on where certain data can travel.
Most explainers stop at “you’ll need a DPO and a DPIA.” That’s true but incomplete, and it skips the part that actually matters for planning: when these duties bite, what they cost if you get them wrong, and what the Rules themselves say versus what’s still just industry speculation dressed up as fact.
This guide works through Rule 13 clause by clause, against the current, verified commencement timeline, not a projected one. If you’re still working out whether your organisation could even be classified as an SDF in the first place, we’ve covered the identification criteria in more depth in our earlier piece on SDF scrutiny and in our breakdown of the heightened compliance tier. This piece assumes that groundwork and goes deep on the part those posts only touched briefly: what Rule 13 actually obligates you to do, and on what clock.
What Is a Significant Data Fiduciary?
Every organisation that decides why and how personal data is processed is a Data Fiduciary under the DPDP Act, 2023. A Significant Data Fiduciary (SDF) is a narrower category within that: a Data Fiduciary, or class of Data Fiduciaries, that the Central Government formally notifies as significant under Section 10(1) of the Act.
The distinction matters because standard DPDP compliance, consent, notice, security safeguards, grievance redressal, applies to everyone. SDF status adds a second, heavier layer on top: governance structures, external oversight, and documentation requirements that go well beyond what a typical Data Fiduciary has to build.
You don’t self-declare this status, and you can’t opt out of it once notified. It’s a government designation, not a business decision.
Who Decides, and Based on What?
Section 10(1) gives the Central Government the power to notify any Data Fiduciary or class of Data Fiduciaries as significant, based on an assessment of relevant factors, including:
- The volume and sensitivity of personal data processed
- Risk to the rights of Data Principals
- Potential impact on the sovereignty and integrity of India
- Risk to electoral democracy
- Security of the State
- Public order
Here’s something worth being precise about, because a fair amount of content circulating online gets this wrong: the Act itself does not fix numeric thresholds. There’s no statutory line that says “50 lakh users” or “₹250 crore turnover” triggers SDF status automatically. Those figures show up frequently in industry commentary and, we’ll be direct about this, in some of our own earlier content, as informed speculation about what the government might use administratively. They are not enacted criteria. The actual text of Section 10(1) lists qualitative factors, and the specific thresholds, if any, arrive only through an actual notification naming a fiduciary or class of fiduciaries.
As of the most recent publicly available information, no such list has been published. Industry analysts widely expect large technology platforms, social media companies, and major banking and insurance players to be among the first named, but “widely expected” and “notified” are different things, and it’s worth keeping that distinction sharp when you’re briefing leadership.
When Do These Obligations Actually Take Effect?
This is the part that gets glossed over most often, and it changes how urgently you should be moving.
The DPDP Rules, 2025 were notified on 13 November 2025 under G.S.R. 846(E), and they commence in three distinct phases rather than all at once:
- Phase 1, 13 November 2025 (immediate): Rules 1, 2, and 17 to 21 took effect. This established the Data Protection Board and brought the core definitions into force.
- Phase 2, 13 November 2026 (12 months): Rule 4 takes effect, opening Consent Manager registration with the Board.
- Phase 3, 13 May 2027 (18 months): Rules 3, 5 to 16, and 22 to 23 take effect. This is the phase that includes Rule 13, meaning the SDF-specific obligations, DPO appointment, independent audits, DPIAs, algorithmic due diligence, and transfer restrictions, become legally enforceable here, not before.
So, strictly by the notified schedule, Rule 13 isn’t live yet. But there’s a live variable that changes this picture, and it’s worth knowing about even though it isn’t finalised.
On 23 January 2026, MeitY held stakeholder consultations proposing to fast-track several SDF-specific provisions, including the government’s power to notify SDFs, the cross-border transfer restrictions in Rule 13(4), and the power to call for information, moving their effective date up from May 2027 to as early as the date any amendment is itself notified. Feedback was invited through early February 2026. As of the most recent tracking available, this remains a stakeholder proposal reported through unnamed sources, not a formally notified amendment. MeitY has not published a follow-up notification confirming it.
Treat that proposal as a real possibility, not a fixed date. Plan around the confirmed 13 May 2027 deadline, but don’t assume you have until then, because the compressed timeline could still land, and preparation work doesn’t compress the same way a deadline does.
What Does Rule 13 Require, Clause by Clause?
Rule 13, titled “Additional obligations of Significant Data Fiduciary,” works alongside Section 10(2) of the Act. Here’s what each part actually requires, in plain terms.
A resident Data Protection Officer, Section 10(2)(a)
Every SDF must appoint a DPO who:
- Represents the SDF for purposes of the Act
- Is based in India
- Is an individual answerable to the Board of Directors or an equivalent governing body
- Serves as the point of contact for the grievance redressal mechanism
This is a materially different role from the general Data Fiduciary DPO or grievance officer most companies already have. The SDF’s DPO answers to the board directly, not to a compliance manager three levels down, and has to be physically based in India regardless of where the parent company sits. We’ve covered the broader DPO role in more depth in our guide to the Data Protection Officer’s role in India, if you want the fuller picture.
An independent data auditor, Section 10(2)(b)
An SDF has to appoint an external, independent auditor to evaluate its compliance with the Act. This isn’t an internal audit function reporting up through the same management chain as the data operations it’s reviewing. It’s a genuinely separate check, and the findings feed into the reporting obligation below.
Annual DPIA and audit, Rule 13(1) and Section 10(2)(c)
Once every twelve months, counted from the date an entity is notified as an SDF (not from a calendar year), it must undertake a Data Protection Impact Assessment and an audit. Section 10(2)(c)(i) describes what the DPIA has to cover: a description of Data Principals’ rights, the purpose of the processing involved, and an assessment and management of the risk those rights face.
The person carrying out the DPIA and the audit then has to furnish the Board with a report of significant observations, findings serious enough to matter, not a routine sign-off. If you’re building this process from scratch, our piece on conducting a Data Protection Impact Assessment under the DPDP Act walks through the mechanics in more detail.
Algorithmic due diligence, Rule 13(3)
This is the clause that surprises people who assume DPDP obligations are purely about consent forms and breach notices. An SDF has to observe due diligence to verify that the algorithmic software it deploys for hosting, displaying, uploading, modifying, publishing, transmitting, storing, updating, or sharing personal data isn’t likely to pose a risk to Data Principal rights.
In practice, that means recommendation engines, fraud-scoring models, and any automated decision system touching personal data need a documented review, not just a security sign-off. If your product roadmap includes AI-driven personalisation or scoring, this clause is the one to read twice.
Transfer restrictions and the advisory committee, Rule 13(4) and (5)
Rule 13(4) allows the Central Government to restrict an SDF’s transfer of specified categories of personal data outside India, based on the advice of a committee it constitutes for the purpose. Rule 13(5) defines that committee: officials from the Ministry of Electronics and Information Technology, and optionally from other ministries or departments, tasked with recommending which measures SDFs should take over time.
Two things to note. First, no specific list of restricted data categories has been published yet, so there’s nothing to comply with here today beyond awareness. Second, this committee structure gives the government room to add new SDF obligations administratively as risks evolve, without needing a fresh Act amendment each time. If cross-border data flows are core to how you operate, our piece on the official rules for international data transfers is worth reading alongside this section.
How Much Does Getting This Wrong Cost?
The Schedule to the DPDP Act sets penalty ceilings by provision, and Section 10 has its own tier. A breach of SDF obligations attracts a penalty of up to ₹150 crore per instance, imposed by the Data Protection Board following an inquiry.
That’s a lower ceiling than the ₹250 crore cap for failing to implement reasonable security safeguards under Section 8(5), or the ₹200 crore cap for breach notification failures under Section 8(6) and children’s data violations under Section 9. It’s still a serious number, and it applies specifically and only to the governance failures Rule 13 describes: no DPO, no independent auditor, a skipped DPIA, or an algorithm nobody checked.
For the full penalty schedule and how the Board actually runs an inquiry, see our guides on the DPDP Act’s penalty and enforcement structure and how the Data Protection Board’s role and process work. Worth adding here: the Board itself is already constituted and can receive complaints, even though Section 10’s substantive duties don’t bite until Phase 3. A complaint about something else entirely can still put your organisation on the Board’s radar well before your SDF obligations formally start.
Why 2027 Isn’t a Reason to Wait
It’s tempting to read “Rule 13 commences 13 May 2027” as “nothing to do until then.” That reading misses three things.
First, SDF notification and Rule 13 obligations are two separate clocks. The moment you’re notified as an SDF, whether that happens tomorrow or in 2028, your twelve-month DPIA and audit cycle starts running from that date, not from a fixed calendar deadline. If you’re notified before the general commencement date fully settles the practical mechanics, you don’t get extra runway just because the Rule technically wasn’t “live” yet.
Second, appointing a genuinely independent auditor, standing up a DPO function that reports to your board, and building a repeatable annual DPIA process are not things you assemble in a sprint. Organisations that started GDPR’s equivalent groundwork only after enforcement began spent years playing catch-up. The lesson transfers directly.
Third, the compression proposal from January 2026 is real, even if unconfirmed. If MeitY does finalise a faster timeline for SDFs specifically, the organisations still scoping their approach in early 2027 will be the ones scrambling.
How to Prepare: A Practical Readiness Roadmap
None of this needs to wait for a formal SDF notification to start. A few concrete steps make sense regardless of your current status:
- Map your exposure against Section 10(1)’s factors now. Volume, sensitivity, and risk to Data Principal rights aren’t abstract; you can assess your own data footprint against them today rather than waiting for a government letter.
- Draft the DPO reporting line before you need it. A DPO who answers to the board is a governance change, not just a hiring decision, and governance changes take longer to land than job postings do.
- Pilot a DPIA on your highest-risk processing activity. You don’t need SDF status to run one. A voluntary DPIA on your riskiest data flow, health data, biometric data, large-scale profiling, gives you a template you can scale later and a genuine defence file if the Board ever asks questions in the meantime.
- Inventory your algorithmic systems. List every model or automated system that touches personal data, even informally. Rule 13(3)’s due diligence requirement is far easier to satisfy if you already know what you’re reviewing.
- Track the cross-border data flow map. Even without a published restricted-category list, knowing where personal data physically goes today saves significant time if a localisation requirement lands.
This is precisely the operational gap RuleExpert’s platform is built to close. Our DPIA Automation guides your team through the assessment with templates aligned to the DPDP Rules, our Data Registry keeps a live map of what personal data you hold and where it moves, and our Compliance Copilot flags governance gaps, like a DPO reporting line that doesn’t yet reach the board, before a regulator does. If you want a clear-eyed view of where your organisation actually stands against Section 10 and Rule 13, book a demo with RuleExpert and we’ll walk through your specific data footprint rather than a generic checklist.
Mistakes Businesses Make About SDF Status
A few patterns show up repeatedly in how organisations misjudge this framework:
- Treating speculative thresholds as settled law. As covered above, the Act doesn’t fix numeric triggers. Building a compliance plan entirely around an assumed “50 lakh user” line is building on sand.
- Waiting for the May 2027 date as if it’s the only date that matters. The Consent Manager milestone in November 2026 and the possibility of an earlier SDF-specific fast-track both deserve a place on your calendar.
- Confusing a general grievance officer with the SDF-specific DPO. The statutory requirements, India residency, board-level reporting, are materially different, and treating them as interchangeable creates a gap an auditor will find quickly.
- Assuming algorithmic due diligence only applies to obvious AI products. A fraud-scoring rule engine or a basic recommendation algorithm still counts if it processes personal data and could affect Data Principal rights.
- Self-certifying instead of engaging an independent auditor. Section 10(2)(b) is explicit about independence. An internal audit team reporting through the same chain as the function it’s reviewing doesn’t meet that bar.
- Skipping the annual cadence question. The twelve-month clock starts on notification, not on 1 April or 1 January. Missing that detail throws off an entire compliance calendar.
Frequently Asked Questions
What is a Significant Data Fiduciary under the DPDP Act? It’s a Data Fiduciary, or class of Data Fiduciaries, formally notified by the Central Government under Section 10(1) of the DPDP Act, 2023, based on factors like data volume and sensitivity, risk to Data Principal rights, and potential impact on India’s sovereignty, security, electoral democracy, or public order.
What obligations does Rule 13 of the DPDP Rules impose on an SDF? Rule 13, read with Section 10(2), requires an SDF to appoint a resident Data Protection Officer, engage an independent data auditor, conduct an annual DPIA and audit with reporting to the Data Protection Board, carry out algorithmic due diligence, and comply with any cross-border transfer restrictions the government notifies.
When do Significant Data Fiduciary obligations under the DPDP Rules take effect? Rule 13 falls within the third commencement phase of the DPDP Rules, 2025, which takes effect on 13 May 2027, eighteen months after the Rules were notified. A proposal to fast-track SDF-specific provisions to November 2026 was floated in January 2026 stakeholder consultations but had not been formally notified as of the most recent tracking.
Is there a fixed threshold, like a number of users, that makes a company an SDF? No. Section 10(1) of the Act lists qualitative factors rather than numeric thresholds. Specific figures circulating in industry commentary reflect speculation about administrative practice, not enacted statutory criteria. Only an actual government notification determines SDF status.
Does the Data Protection Officer for an SDF have to be based in India? Yes. Section 10(2)(a) requires the DPO to be based in India, to represent the SDF under the Act, to be answerable to the Board of Directors or an equivalent governing body, and to serve as the grievance redressal point of contact.
How often must a Significant Data Fiduciary conduct a DPIA? Once every twelve months, counted from the date the entity is notified as an SDF, per Rule 13(1). This is an ongoing, recurring obligation, not a one-time exercise.
What is algorithmic due diligence under Rule 13? It’s the requirement under Rule 13(3) that an SDF verify its algorithmic software, used for hosting, displaying, transmitting, storing, or sharing personal data, isn’t likely to pose a risk to Data Principal rights. This applies to recommendation engines, scoring models, and other automated systems that touch personal data.
What is the penalty for failing to meet SDF obligations? Up to ₹150 crore per instance under the Schedule to the DPDP Act, imposed by the Data Protection Board after a formal inquiry, which is separate from the ₹250 crore ceiling for security safeguard failures and the ₹200 crore ceiling for breach notification or children’s data violations.
Can a company be an SDF without knowing it yet? No. SDF status only applies once the Central Government formally notifies a Data Fiduciary or class of Data Fiduciaries. No list of designated SDFs has been published as of the most recent available information, though several sectors are widely expected to be early candidates.
Should a company start preparing for SDF obligations before being notified? Yes, particularly if the organisation processes data at meaningful scale or handles sensitive categories. Governance changes like an India-based, board-reporting DPO and a repeatable DPIA process take longer to build than the notification-to-compliance window is likely to allow.