Significant Data Fiduciary Obligations
SL-01Notification as an SDF adds a distinct set of obligations on top of everything else in the Act. They are all structural rather than operational — appointments, cadences and verifications — which makes them unusually easy for a regulator to test.
Seven distinct obligations flow from notification under Section 10.
The Central Government may notify a Data Fiduciary as significant having regard to these factors. Recorded score 78/100 on 04 Jan 2026.
- Volume and sensitivity of personal data processed92
- Risk to the rights of Data Principals78
- Potential impact on the sovereignty and integrity of India62
- Risk to electoral democracy40
- Security of the State71
- Public order84
Section 10 breaches
Obligation by obligation
The DPO must represent the Significant Data Fiduciary, be based in India, and report to the board or governing body.
An independent auditor must evaluate compliance with the Act and carry out the periodic audit.
A DPIA must be undertaken at least once every twelve months, with significant observations reported to the Board.
An audit must be carried out at least once every twelve months alongside the DPIA.
Algorithmic software used for processing must be verified as not posing a risk to the rights of Data Principals.
Specified categories of personal data must not be transferred outside India where restricted.
The two appointments an SDF must be able to evidence on demand.
- Data Protection Officer
- Adv. Meera Iyer
- Designation
- Data Protection Officer
- Based in India
- Yes
- Appointed
- 20 Jan 2026
- Reports to
- Principal Secretary (board equivalent)
- Certifications
- CIPP/ECIPMLLM (Cyber Law)
- Independent data auditor
- Harpreet Kaur, Lead Auditor
- Auditor independence
- Documented in the engagement letter