Chapter 2 · Obligations of Data Fiduciary
Section 10 - Additional obligations of Significant Data Fiduciary
DPIA, audits and a Data Protection OfficerSome organisations handle so much, or such sensitive, personal data that the Central Government can designate them a 'Significant Data Fiduciary'.
Download full Act (PDF)In plain English
Some organisations handle so much, or such sensitive, personal data that the Central Government can designate them a 'Significant Data Fiduciary'. This tier carries heavier duties: appoint a Data Protection Officer based in India who answers to the governing body and serves as the grievance contact, appoint an independent data auditor, and run periodic Data Protection Impact Assessments and audits to find and manage risks to Data Principals.
A large social-media platform processing the data of millions of Indians is a likely candidate for designation as a Significant Data Fiduciary.
Key points
- The Government designates SDFs based on data volume, sensitivity and risk factors.
- Must appoint a Data Protection Officer based in India, answerable to the governing body.
- Must undertake periodic Data Protection Impact Assessments (DPIAs).
- Must undergo periodic independent audits and any other prescribed measures.
Official section text
Section 10. Additional obligations of Significant Data Fiduciary.
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including -
the volume and sensitivity of personal data processed;
risk to the rights of Data Principal;
potential impact on the sovereignty and integrity of India;
risk to electoral democracy;
security of the State; and
public order.
The Significant Data Fiduciary shall -
appoint a Data Protection Officer who shall -
represent the Significant Data Fiduciary under the provisions of this Act;
be based in India;
be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and
be the point of contact for the grievance redressal mechanism under the provisions of this Act;
appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and
undertake the following other measures, namely: -
periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed;
periodic audit; and
such other measures, consistent with the provisions of this Act, as may be prescribed.