9.  Are you NDF or SDF
ISSUE #92Published: 9/25/2026

9. Are you NDF or SDF

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Are you a Normal Data Fiduciary (NDF) or Significant Data Fiduciary (SDF)? Most articles don't explain this—but it's the single biggest factor determining your DPDPA compliance obligations.

Under Section 10, the Central Government notifies SDFs based on data volume, risk to Data Principal rights, impact on India's sovereignty, electoral democracy, and state security—typically targeting large social media platforms.

Only SDFs must appoint an independent DPO based in India (reporting directly to the board, not the CIO), conduct periodic Data Protection Impact Assessments (DPIAs), and appoint independent data auditors.

If you're an NDF handling routine customer or employee data, you're not subject to these heightened obligations—but you still must comply with core DPDPA principles.