4

Significant Data Fiduciary Obligations

SL-01

Notification as an SDF adds a distinct set of obligations on top of everything else in the Act. They are all structural rather than operational — appointments, cadences and verifications — which makes them unusually easy for a regulator to test.

DischargesS.10R.12
SDF obligation position

Seven distinct obligations flow from notification under Section 10.

Met3
Gaps2
In progress1
Determination factors

The Central Government may notify a Data Fiduciary as significant having regard to these factors. Recorded score 78/100 on 04 Jan 2026.

  • Volume and sensitivity of personal data processed
    92
  • Risk to the rights of Data Principals
    78
  • Potential impact on the sovereignty and integrity of India
    62
  • Risk to electoral democracy
    40
  • Security of the State
    71
  • Public order
    84
Obligations
7
Met
3
Gaps
2
Ceiling
₹150 Cr

Section 10 breaches

Obligation by obligation

Appoint a Data Protection Officer based in India

The DPO must represent the Significant Data Fiduciary, be based in India, and report to the board or governing body.

Compliant

Adv. Meera Iyer appointed 20 Jan 2026, based in India, dedicated engagement reporting to the Principal Secretary.

Appoint an independent data auditor

An independent auditor must evaluate compliance with the Act and carry out the periodic audit.

Compliant

Harpreet Kaur engaged as Lead Auditor under an engagement letter held in the evidence vault. Independence from the delivery team is documented.

Undertake a Data Protection Impact Assessment annually

A DPIA must be undertaken at least once every twelve months, with significant observations reported to the Board.

Compliant

Within cadence.

Undertake a periodic audit annually

An audit must be carried out at least once every twelve months alongside the DPIA.

In progress

Annual SDF re-audit — FY 2027-28 scheduled, due in 9 months, led by the independent auditor.

Verify algorithmic software

Algorithmic software used for processing must be verified as not posing a risk to the rights of Data Principals.

Gap

The scheme eligibility scoring model has not been signed off. Human review is not available and bias testing has not been completed, so the determination cannot be made.

Observe restrictions on transferring specified personal data

Specified categories of personal data must not be transferred outside India where restricted.

Gap

Two transfers currently lack a completed assessment, including one under an expired agreement. Neither destination is on the restricted list, but the assessment itself is the obligation.

Report significant observations to the Board

Significant observations from the DPIA and audit must be reported to the Data Protection Board.

Not assessed

No report has been filed for the current cycle because the DPIA and audit have not concluded. The report is due once they do.

Appointment record

The two appointments an SDF must be able to evidence on demand.

Data Protection Officer
Adv. Meera Iyer
Designation
Data Protection Officer
Based in India
Yes
Appointed
20 Jan 2026
Reports to
Principal Secretary (board equivalent)
Certifications
CIPP/ECIPMLLM (Cyber Law)
Independent data auditor
Harpreet Kaur, Lead Auditor
Auditor independence
Documented in the engagement letter