Short answer: Only by notification; none notified yet
Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.
What the law says
Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India.
Section 10 · Rule 13: The government may notify organisations as Significant Data Fiduciaries based on the volume and sensitivity of data and the risk involved. They need a DPO based in India, an independent data auditor, and a yearly impact assessment and audit. None had been notified when this page was last reviewed.
Section 16 · Rule 15: Personal data may go outside India unless the government restricts a country. A sector law or regulator that sets a stricter rule still applies. No country had been restricted when this page was last reviewed.
Steps
Estimate how many people's data you hold and how sensitive it is.
Note any public or security role your data plays.
If you are a likely candidate, run a trial impact assessment this year.
Identify an auditor you could appoint.
Watch MeitY notifications.
Evidence to keep
Volume and sensitivity note
Trial impact assessment
Board note
Common mistakes
Assuming 'not notified' means 'never'
Waiting for notification to start
Thinking only tech companies will be notified
How it plays out by sector
Banking, financial services and insurance: Large banks, insurers and payment companies hold sensitive financial data for crores of people. Plan as a likely candidate.
IT, ITeS, BPO and GCC: Notification is more likely for consumer platforms than for IT services, but large SaaS players should watch.
Healthcare and hospitals: Large hospital chains and health platforms hold sensitive data at scale; plan as a possible candidate.
From each seat
CEO / MD: Ask management for a short note on whether you could be notified, and what it would take to be ready.
Director: Ask whether management has assessed the chance of notification. Large or sensitive data holders should have a view.
Chief risk officer: Keep notification as a scenario in the register, with a trigger and an owner.
What a good answer from management sounds like
“We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.” Effort and time: Medium if you are a likely candidate.