Answer 10 questions about your organisation — get an instant SDF assessment and a complete breakdown of the additional obligations that apply to you.
Under Section 10 of the DPDPA 2023, the Central Government designates certain Data Fiduciaries as Significant — based on the volume and sensitivity of data they process, potential risks to Data Principals, and national security relevance.
SDFs must appoint a Data Protection Officer — a qualified individual who reports directly to the Board of Directors and oversees compliance.
SDFs must conduct a Data Protection Impact Assessment every 12 months and submit significant findings to the Data Protection Board.
An independent data auditor must audit the SDF's data processing activities annually and report findings to the Board.
SDFs must verify that any algorithmic software used for handling personal data does not risk Data Principals' rights.
SDFs face additional restrictions on processing children's data — including prohibitions on tracking and behavioural monitoring of minors.
The DPO's reports and DPIA findings must be reviewed at board level — making data protection a formal governance obligation.