InfraVeritas360DPDPiq

DPDP Insights › Questions › Could we be a Significant Data Fiduciary?

Question

Could we be a Significant Data Fiduciary?

Short answer: Only by notification; none notified yet

Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.

What the law says

Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India.

Steps

  1. Estimate how many people's data you hold and how sensitive it is.
  2. Note any public or security role your data plays.
  3. If you are a likely candidate, run a trial impact assessment this year.
  4. Identify an auditor you could appoint.
  5. Watch MeitY notifications.

Evidence to keep

Common mistakes

How it plays out by sector

From each seat

What a good answer from management sounds like

“We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.” Effort and time: Medium if you are a likely candidate.

Related questions

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.