InfraVeritas360DPDPiq

DPDP Insights › Questions › Do we need a DPO?

Question

Do we need a DPO?

Short answer: Not required by law unless notified as an SDF, but name one person

Only a Significant Data Fiduciary must appoint a DPO, based in India. Every other organisation must publish the contact of a person who can answer questions about personal data. In practice, most organisations of any size name one accountable person anyway, because someone has to own requests, complaints and breaches.

What the law says

Section 8(9) and Rule 9 require a published contact person for every Data Fiduciary. Section 10 requires a DPO in India for Significant Data Fiduciaries.

Steps

  1. Name one accountable person, with a deputy.
  2. Publish the contact on your website, app and notices.
  3. Give the role time, a budget line and a route to management.
  4. Set a short monthly report: requests, complaints, incidents, actions.
  5. Review the role if you are notified as an SDF.

Evidence to keep

Common mistakes

How it plays out by sector

From each seat

What a good answer from management sounds like

“We have named an accountable person with a deputy, published the contact, and that person reports to management every month.” Effort and time: Light · 2 to 4 weeks.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.