Blog
Written by the Erasure product and engineering team
Part of Privacy operations
Significant Data Fiduciary Under DPDP: Are You One, and What Changes
The DPDP Act lets the government designate Significant Data Fiduciaries with extra duties: DPIAs, data audits, an India-based DPO. Here is what SDF status means in practice.
Significant Data Fiduciary (SDF) is a designation under India's DPDP Act that adds a layer of obligations on top of the baseline fiduciary duties. The government can notify fiduciaries as SDFs based on the volume and sensitivity of personal data they process, their risk to data principals, and their impact on national security and public order.
For most startups, SDF status is a future possibility rather than a current fact. But the obligations attached to it are worth understanding now, because the evidence trail SDF duties require is the same evidence trail every fiduciary should be building anyway.
How SDF designation works
The DPDP Act gives the central government the power to notify certain data fiduciaries as Significant Data Fiduciaries. The criteria, set out in the Act and elaborated in the Rules, include:
- Volume of personal data processed
- Sensitivity of the data
- Risk to the rights of data principals
- Impact on sovereignty, security, public order, or the integrity of India
The government also maintains a list of entities that are SDFs by default: social media intermediaries, online gaming platforms, and online trading platforms are named in the Rules, among others.
The designation process is not automatic; it is a notification. But companies that fit the profile should plan as if it will happen, because the obligations are substantial.
What SDF obligations add
Under the Act and the Rules, an SDF carries duties beyond the baseline:
| Obligation | What it involves | |------------|------------------| | Data Protection Impact Assessment | Assess privacy risk of processing activities, especially new or high-risk ones | | Periodic data audits | Independent audit of processing and safeguards, on a schedule | | Data Protection Officer | A DPO based in India, with defined responsibilities | | Algorithmic due diligence | For systems that process personal data algorithmically, demonstrate fairness and accountability |
The DPO requirement is the one that gets companies' attention: a named individual, based in India, responsible for data protection matters. That is a real organisational commitment, not a title on a business card.
The honest read for startups
Here is the part the compliance industry does not emphasise enough: most startups will not be designated SDFs in the first wave. The government's focus will be on the largest platforms, the intermediaries named in the Rules, and the sectors with the most sensitive data.
What this means practically:
- Do not build your entire compliance program around SDF status
- Do build the evidence trail that SDF duties require, because it is the same trail baseline duties need
- Do track your data volumes, because crossing the notification threshold is not a surprise if you are watching
A company that has a data inventory, a deletion workflow, and evidence of fulfilment is already most of the way to SDF readiness. The designation would add a DPIA process and a named DPO; it would not require starting from zero.
DPIA: the obligation that scales badly
The Data Protection Impact Assessment is the SDF duty most likely to become a treadmill if left late. A DPIA is a structured assessment of how a processing activity affects data principals' privacy: what data, why, what risk, what mitigations.
The problem is that DPIAs done reactively, in a panic before a launch, are theatre. A DPIA is only useful when it is tied to the actual data flows, which means it is only useful when you have a data map. The data mapping post covers the inventory layer that makes DPIAs honest.
Building SDF-ready infrastructure without the title
The pragmatic path for a startup is to build the capabilities SDF status requires, without waiting for the notification:
- Data inventory and maps. You cannot audit or assess what you cannot enumerate.
- Deletion and rights workflow. The operational core of the Act, and the evidence trail any audit will examine.
- Security safeguards with logs. Rule 6's encryption, access control, and one-year log retention are audit fodder.
- A named owner. Even without a formal DPO, someone should own privacy operations. When designation comes, you already know who.
- A DPIA habit. Run one for the genuinely high-risk processing activities, not for everything.
That is the shape of Erasure: Data Maps for inventory, Rights for the request lifecycle with verification and durable jobs, Systems for fulfilment, Evidence for the record. The compliance checklist puts these in order, and the Rules explainer covers Rule 13 in context.
The bottom line
SDF designation is a threshold event that most startups will not hit in the first wave. The obligations behind it, DPIAs, audits, a DPO, evidence, are not exotic; they are the same operational capabilities every fiduciary under DPDP should be building. Build the capabilities, watch your volumes, and designation stops being a cliff and becomes a formality.
The DPDP Act guide is the broader map, and the penalties post covers what enforcement is likely to look like.
About this post
Written by the Erasure product and engineering team
Published 30 July 2026
Part of Privacy operations
This article is grounded in Erasure's product documentation and explains engineering and operational implications. Where it discusses regulation, it is not legal advice. See our editorial policy.
More on privacy operations
DPDP Compliance Checklist for Indian Startups (2026)
A practical, itemized DPDP compliance checklist for Indian product companies: notice, consent, data inventory, deletion workflows, evidence, and security safeguards.
DPDP Rules 2025 Explained: What Changed and What You Must Do
The DPDP Rules were notified on November 13, 2025 with a phased rollout. This breaks down notice, consent, security, breach reporting, and SDF obligations into engineering work.
DPDP Act 2023: The Complete Guide for Indian Product Companies
India's Digital Personal Data Protection Act is in force, with rules notified in November 2025 and penalties expected from May 2027. Here is what product teams actually need to do.