Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+
Glossary

A category nobody enters by accident

Last updated

7 October 2026

Sec. 2(z) makes a Significant Data Fiduciary one the Central Government notifies under Sec. 10. The six factors, the three extra duties, and Rule 13.

Most definitions in the Digital Personal Data Protection Act, 2023 describe something you either are or are not as a matter of fact. This one describes something you become only when the Central Government says so, which makes it the one term you cannot settle by reading your own data flows.

The definition, in the Act's words

"Significant Data Fiduciary" means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.

That is Sec. 2(z), and it is circular on purpose: the content is in Sec. 10. Sec. 10(1) lets the Central Government notify any Data Fiduciary, or a whole class of them, "on the basis of an assessment of such relevant factors as it may determine, including" six the Act names:

  • the volume and sensitivity of personal data processed;
  • risk to the rights of Data Principal;
  • potential impact on the sovereignty and integrity of India;
  • risk to electoral democracy;
  • security of the State; and
  • public order.

The word "including" matters: the six are a floor on what may be weighed rather than a closed list, and the Act attaches no number to any of them.

The same thing, in one sentence

A Significant Data Fiduciary is an ordinary Data Fiduciary that the Central Government has formally named for extra duties, usually because of how much or how sensitive its data is.

A worked example

A payments company processing crore-scale transaction histories for Indian users is the shape the Sec. 10(1) factors describe: high volume, financially sensitive, and a real risk to the rights of Data Principals if it goes wrong. On the Act's own terms it is a plausible candidate.

It is still not a Significant Data Fiduciary until a notification under Sec. 10(1) says it is. Until then it owes what every other Data Fiduciary owes — Sec. 5 notice, Sec. 6 consent, Sec. 8 safeguards — and nothing from Sec. 10 at all.

What changes on the day of notification is dated. Rule 13(1) of the DPDP Rules, 2025 starts a twelve-month clock "from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such", so the first impact assessment and audit fall due inside that year.

What a Significant Data Fiduciary is not

It is not a self-assessment. No threshold in the Act or the Rules converts you by being crossed, and there is nothing to register for. Sec. 10(1) requires a notification: the trigger is an act of government, not an act of growth.

It is not a parallel regime. The marginal note to Sec. 10 reads "Additional obligations of Significant Data Fiduciary", and additional is the operative word — everything in Sec. 5 to Sec. 9 continues to apply unchanged.

It is not the same thing as needing a Data Protection Officer. Sec. 2(l) defines the Data Protection Officer as an individual appointed by the Significant Data Fiduciary under Sec. 10(2)(a), so the statutory office belongs to this category alone. Every other Data Fiduciary owes something lighter under Sec. 8(9): the published business contact information of a Data Protection Officer if applicable, or of a person able to answer questions about the processing. Rule 9 repeats that formula.

And it is not a registration, which is where it is most often confused with the Consent Manager. A Consent Manager applies to the Data Protection Board and is registered by it under Rule 4. A Significant Data Fiduciary applies for nothing and is notified by the Central Government. Different body, different direction.

What follows from being notified

Sec. 10(2) sets three obligations, and Rule 13 puts dates and reporting lines on them.

A Data Protection Officer, Sec. 10(2)(a). Four cumulative requirements: the DPO represents the Significant Data Fiduciary under the Act, is based in India, is an individual responsible to the Board of Directors or similar governing body, and is the point of contact for the grievance redressal mechanism. The third is the one that reshapes an org chart.

An independent data auditor, Sec. 10(2)(b). Appointed to carry out a data audit and evaluate compliance with the Act.

Periodic assessment and audit, Sec. 10(2)(c). The Data Protection Impact Assessment is defined inline as a description of the rights of Data Principals and the purpose of processing their personal data, plus the assessment and management of risk to those rights. Rule 13(1) makes the cycle twelve months for both, and Rule 13(2) requires whoever carries them out to furnish the Board a report containing significant observations.

Two further duties sit in the Rules alone. Rule 13(3) requires due diligence to verify that technical measures including algorithmic software adopted for hosting, publishing, storage or sharing of personal data are not likely to pose a risk to the rights of Data Principals. And Rule 13(4) is the hardest line in the framework: personal data the Central Government specifies, on the recommendation of a committee it constitutes, must not be transferred outside India — neither the data nor the traffic data pertaining to its flow.

Entry 4 of the Schedule to Sec. 33(1) caps a breach of the Sec. 10 obligations at up to 150 crore rupees.

Where to go next

The Act, from the beginning places Sec. 10 among the duties that apply to everyone, and what commences when covers the date Rule 13 comes into force. The impact assessment module is built against that twelve-month cycle and the report that has to reach the Board.