Short answer: Not required by law unless notified as an SDF, but name one person
Only a Significant Data Fiduciary must appoint a DPO, based in India. Every other organisation must publish the contact of a person who can answer questions about personal data. In practice, most organisations of any size name one accountable person anyway, because someone has to own requests, complaints and breaches.
What the law says
Section 8(9) and Rule 9 require a published contact person for every Data Fiduciary. Section 10 requires a DPO in India for Significant Data Fiduciaries.
Section 8(9)–(10) · Rules 9, 14: Publish the business contact of a DPO or another person who can answer questions about personal data. Run a working grievance process and reply within a reasonable period, not more than 90 days.
Section 10 · Rule 13: The government may notify organisations as Significant Data Fiduciaries based on the volume and sensitivity of data and the risk involved. They need a DPO based in India, an independent data auditor, and a yearly impact assessment and audit. None had been notified when this page was last reviewed.
Steps
Name one accountable person, with a deputy.
Publish the contact on your website, app and notices.
Give the role time, a budget line and a route to management.
Set a short monthly report: requests, complaints, incidents, actions.
CEO / MD: The person you name needs your visible backing. Give the role a budget line and ask for a short report every month.
Director: Ask who the accountable person is, what authority they have, and when they last reported to the board or a committee.
What a good answer from management sounds like
“We have named an accountable person with a deputy, published the contact, and that person reports to management every month.” Effort and time: Light · 2 to 4 weeks.