Are you a Normal Data Fiduciary (NDF) or Significant Data Fiduciary (SDF)? Most articles don't explain this—but it's the single biggest factor determining your DPDPA compliance obligations.
Under Section 10, the Central Government notifies SDFs based on data volume, risk to Data Principal rights, impact on India's sovereignty, electoral democracy, and state security—typically targeting large social media platforms.
Only SDFs must appoint an independent DPO based in India (reporting directly to the board, not the CIO), conduct periodic Data Protection Impact Assessments (DPIAs), and appoint independent data auditors.
If you're an NDF handling routine customer or employee data, you're not subject to these heightened obligations—but you still must comply with core DPDPA principles.
