DPDP Posture

SDF vs Regular Data Fiduciary: Do You Need a DPO?

Jan 22, 20265 min read

Significant Data Fiduciary status triggers additional DPDP requirements. Here is how to know if you qualify.

One of the most consequential distinctions in DPDP is between a regular Data Fiduciary and a Significant Data Fiduciary. The difference is not just terminology — it is the difference between a basic compliance programme and a substantially more demanding set of obligations that includes mandatory senior hires, formal impact assessments, and third-party audits.

What every Data Fiduciary must do

If you process personal data of individuals in India, you are a Data Fiduciary. That triggers the base layer of DPDP obligations: establish a legal basis for every processing activity, implement appropriate security safeguards, honour data principal rights (access, correction, erasure), notify breaches to the Board, and appoint a grievance officer (who can be any employee — this is not the same as a DPO).

These are substantial requirements, but they are implementable by a small team with the right tooling. They do not require a dedicated privacy lawyer on staff or a new organisational layer.

What makes you a Significant Data Fiduciary

The government will designate SDFs through notification based on criteria including: volume of personal data processed, sensitivity of data types, potential impact on data principals, risk to sovereignty and public order, and national security considerations. The specific thresholds are pending final notification, but the direction of travel is clear from the draft rules.

  • Volume threshold (likely): Processing personal data of more than a specified number of data principals — draft guidance has indicated figures in the range of 10,000 to 100,000 data principals.
  • Sensitivity threshold: Processing sensitive personal data at any significant scale — this would likely capture healthtech, fintech, and edtech operators regardless of headcount.
  • Critical infrastructure: Entities operating in sectors designated as critical information infrastructure — financial services, healthcare, energy, telecom.
  • Children's data: Any entity that knowingly processes children's data (under 18) faces additional obligations regardless of volume.

The additional SDF obligations

  • Data Protection Officer: Must be a senior employee with demonstrable privacy expertise, resident in India, with a direct reporting line to the board. Cannot be outsourced to a law firm. Salary benchmarks are emerging: ₹15-25L per annum for full-time, ₹3-8L per annum for fractional.
  • Data Protection Impact Assessment: Formal DPIA required for high-risk processing activities before they commence. Not a checkbox exercise — the Board can require access to DPIA documentation.
  • Periodic audits: Annual audits by certified data protection auditors — a profession that is still being defined in India. Audit standards are expected to align with ISO/IEC 27701 (Privacy Information Management).
  • Algorithmic accountability: SDFs that use algorithmic decision-making affecting data principals must provide explainability and maintain records of the logic applied.

The DPO market in India is severely undersupplied relative to anticipated demand. If you need a full-time DPO and wait until SDF designation is confirmed, you may face a 6-12 month hiring timeline. Fractional DPO services are emerging as a bridge solution.

The grey areas that matter most

A B2B SaaS company with 50 enterprise customers but handling sensitive health data for each of them is almost certainly an SDF by sensitivity criteria, even if the number of individual data principals is relatively small. A consumer app with 8,000 users just below a numerical threshold should not assume it is safe — the Board has discretion to designate based on risk profile, not just headcount.

Children's data is the clearest trigger for additional obligations. If your product is used by anyone under 18, DPDP requires verifiable parental consent before processing — a technical requirement that most current products cannot meet. EdTech companies, gaming platforms, and social applications used by minors are in an especially high-risk category.

The strategic recommendation

Build as if you are an SDF from the beginning. The DPO, DPIA, and audit requirements are good practices that improve your data governance regardless of formal designation. Companies that build these structures early will have them as genuine assets when enterprise customers and investors ask — rather than as compliance costs incurred under regulatory pressure.

The companies most at risk are those in the middle: too large and sensitive to ignore SDF obligations, too small to have the legal and operational infrastructure to implement them quickly. If that describes your company, the time to act is before the threshold notification, not after.

Takeaway

SDF designation is coming for many Indian startups faster than they expect. The penalty for getting this wrong — operating as a de facto SDF without the required structures — is not just regulatory fine risk. It is the operational crisis of scrambling to implement in weeks what should have been built over months. Start with the end state in mind.