Designation as a Significant Data Fiduciary is the point at which DPDP compliance stops being a project and becomes an operating structure. A Data Protection Officer based in India and answerable to the board. An independent data auditor. Data Protection Impact Assessments and periodic audits as a standing obligation. It is worth knowing in advance whether it is coming.
Designation is by notification, not by threshold
The first thing to be clear about is the mechanism. Unlike some regimes that attach heightened obligations to a numeric threshold, the Act empowers the Central Government to notify any Data Fiduciary or class of Data Fiduciaries as significant, having regard to a set of factors: the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, security of the State, and public order.
Two implications follow. First, there is no number you can stay beneath. Second, the factors are not all about scale. A modest business processing data with a high potential impact on individual rights — health data, children’s data, data used for consequential automated decisions — may present a stronger case for designation than a much larger business processing routine transactional records.
The additional obligations, in operational terms
A Data Protection Officer, in India, reporting to the board
The DPO must be based in India, must be an individual responsible to the board of directors or equivalent governing body, and is the point of contact for the grievance redressal mechanism. This is a governance requirement as much as a privacy one. Three points routinely cause difficulty:
- It cannot be an offshore role. Multinational groups with a global privacy office will need an India-resident individual, not a regional lead with India in their remit.
- Reporting line matters. A DPO buried three levels inside IT does not satisfy a requirement framed around responsibility to the board.
- Conflicts are real. Appointing the person who owns the data monetisation strategy creates an obvious tension. Where internal candidates are conflicted, the role has to be structured accordingly.
An independent data auditor
Significant Data Fiduciaries must appoint an independent data auditor to evaluate compliance. “Independent” is the operative constraint: the auditor should not be the firm that designed the programme being audited, and organisations that engaged a single vendor to build and assure their compliance will need to separate those functions.
Impact assessments and periodic audits
A Data Protection Impact Assessment is a process comprising a description of the rights of Data Principals and the purpose of processing, an assessment and management of risk to those rights, and such other matters as may be prescribed. In practice, the useful DPIA is the one done before a feature ships, not the one reconstructed for an auditor eighteen months later. Organisations that already run a security review gate at design stage should attach the DPIA to that gate rather than creating a parallel process nobody uses.
An honest self-assessment
We ask clients six questions. None is determinative; together they give a fair sense of exposure.
- Scale. How many identifiable individuals are in your systems, including former customers and applicants? Count what you hold, not what is active.
- Sensitivity. Do you process health, financial, biometric, precise location or children’s data? The Act has no separate sensitive-data category, but sensitivity is expressly a designation factor.
- Consequence. Are decisions made about individuals using their data — credit, insurance, employment, access to a service — and could an error materially harm them?
- Inference. Do you derive attributes people did not provide? Profiling and inference raise the risk profile independently of volume.
- Position. Are you infrastructure for others — a platform, marketplace, aggregator or identity provider — such that your failure would propagate?
- Salience. Would a serious incident at your organisation be a national news story? This is not a legal test, but the designation factors include public order and security of the State, and salience is a reasonable proxy for how a regulator will weigh those.
Three or more strong answers, in our experience, warrants preparing on the assumption that designation is likely for your class of business, even if it has not yet occurred.
The cost of preparing early is a DPO appointment and an audit. The cost of preparing late is doing both under a compliance deadline, with a regulator already watching.
What preparation actually looks like
We would sequence it as follows. Identify the DPO candidate and resolve the reporting line before anything else, because that appointment determines who owns the rest of the work. Run one DPIA properly, on your highest-risk processing activity, to establish a template and to discover what your organisation actually knows about its own data flows. Separate build from assurance in your vendor arrangements now, while you still have commercial leverage. And put a short standing item on the board agenda — quarterly is sufficient — so that when a notification does arrive, the board is not learning about its data protection posture for the first time.
Designation is not a penalty. It is a statement about the significance of what you hold, and organisations that already treat it that way find the transition unremarkable.
Disclaimer
This note is published for general information only. It is not legal advice, it does not take account of your particular circumstances, and reading it does not create a lawyer-client relationship with Incept Legal. The law is stated as at the date of publication. Please take advice before acting.