10. The Three Step FIlter for SDF
ISSUE #93Published: 9/25/2026

10. The Three Step FIlter for SDF

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

Use this three-step filter to determine if your organization qualifies as a Significant Data Fiduciary (SDF) under DPDPA Section 10.

Step 1: The government assesses data volume and sensitivity millions of users, health/financial data, or services impacting democracy, national security, and public order.

Step 2: They can designate either a specific company or an entire sector (like all social media platforms or payment aggregators) as SDF.

Step 3: A public gazette notification formally declares SDF status only then do extra obligations kick in, including appointing a DPO, independent auditors, yearly DPIAs, and localization requirements.

If you're not on that list, consider yourself fortunate but core DPDPA compliance still applies.