Assess · DPIA & SDF Readiness

DPIA & SDF Readiness

Whether you are likely to be designated a Significant Data Fiduciary, what changes the day you are, and what you do not owe until then.

Assess your exposure The six factors §10 names Most businesses are not SDFs. We would rather tell you that than sell you.
The thing to understand first

Nobody becomes an SDF by deciding to

Section 10(1) makes this a designation by the Central Government, which changes what “readiness” can honestly mean.

01

It is notified, not claimed

The government may notify a Data Fiduciary, or a whole class of them, as significant. You cannot opt in, and you cannot opt out by arguing you are small.

02

Classes, not just companies

A notification can name a category of business rather than a named entity. So the question is not only about you — it is about the sector you sit in.

03

The obligations attach immediately

There is no build phase after designation. A DPO based in India, an independent auditor and an impact assessment are not a fortnight’s work.

Which is the whole argument for assessing now rather than later. Not because you owe anything today — most readers of this page do not — but because the gap between designation and compliance is measured in months, and the notification does not wait for you to close it.

What we actually do

The engagement, and where it can stop

It is sized to the answer. If you are plainly not a candidate, the work is short and we will say so in writing.

1

We assess your position on all six factors

Volume and sensitivity, risk to people’s rights, sovereignty, electoral democracy, security of the State, public order — with reasoning a board could read.

2

We cost the gap, if it happened tomorrow

What the five additional obligations would take in time and structure, and which of them you are already most of the way towards without realising.

3

We run a DPIA where one is warranted

For a specific high-risk activity rather than for the organisation at large. A DPIA of everything is a document nobody reads, including whoever wrote it.

4

We list your automated decisioning

Bought and built, and whether you could evidence Rule 13(2) diligence on each. For most clients this is the first time anyone has written the list down.

And there is a fifth outcome we would rather sell you than the other four. If the six factors point clearly away from designation, you get that as a short written assessment — which is worth having on file the next time somebody tries to sell you an SDF programme you do not owe.

Section 10(1)

What the government weighs

Six factors are named in the Act. Two of them decide most ordinary cases; the other four decide the ones nobody expects.

01

Volume and sensitivity

The practical test for most businesses. A chain holding millions of clinical records is a different proposition from a single clinic holding thousands.

02

Risk to data principals’ rights

Not just how much you hold but what happens to a person if it goes wrong. Health, finance and children’s data carry weight here that contact details do not.

03

Sovereignty and integrity of India

Infrastructure, defence-adjacent supply chains, anything the state has an interest in keeping inside its own borders.

04

Risk to electoral democracy

Platforms that shape what large numbers of people see. Unusual to trip, and decisive when you do.

05

Security of the State

The factor that catches businesses who think of themselves as ordinary because their own product is ordinary. Who your customers are can matter more than what you sell.

06

Public order

Broad by design, and the one that makes a confident self-assessment unwise. Likelihood is the honest output here, not a verdict.

Section 10(2) · Rule 13

Five things that become obligations

Everything else in the Act still applies. These are the additions, and one of them is rarely discussed anywhere.

§10(2)(a)₹150 Cr

A Data Protection Officer based in India, answerable to the board and the point of contact for grievance redressal. A named person, not a mailbox.

DPO
§10(2)(b)₹150 Cr

An independent data auditor to carry out a data audit. Independent means not you, and not the people who built what is being audited.

Auditor
Rule 13(1)₹150 Cr

A data protection impact assessment and an audit every twelve months, with significant observations reported to the Board.

DPIA + audit
Rule 13(2)₹150 Cr

Due diligence that algorithmic software you deploy on personal data does not risk data principals’ rights — including software you bought.

Algorithmic
Rule 13(3)₹150 Cr

Personal data the government specifies must not leave India. A localisation obligation that lands on your architecture, not your policy.

Localisation

The algorithmic one is the sleeper. Every business now runs scoring, ranking, routing or recommendation somewhere, and most bought it rather than built it — which does not move the duty. If a vendor cannot tell you what their system relied on to reach an outcome, you cannot discharge Rule 13(2) by having purchased it.

The assessment itself

What a DPIA actually is

The Act defines it, which is unusually helpful. Four things, and the third is where the work is.

1

The rights of the people affected

Described, not assumed. Who they are, what they can ask of you, and how they would go about it — which for most organisations is the first time anyone has written it down from the person’s side rather than the system’s.

2

The purpose of the processing

Stated at a granularity somebody could disagree with. “Improving services” is not a purpose you can assess the risk of, and a DPIA built on one assesses nothing.

3

Assessment of the risk of harm

What actually happens to a person if this goes wrong. Not a heat map — the specific harm: the patient whose diagnosis reaches an employer, the candidate whose rejection reasons reach their current manager.

4

How that risk is managed

The measures, and honestly whether they work. A DPIA that concludes everything is fine is the one an auditor reads most carefully, because almost nothing is.

A DPIA is mandatory only for a Significant Data Fiduciary. Plenty of organisations do one anyway before a high-risk launch — a new clinical product, a children’s feature, a model trained on customer records — because §33(2) makes what you did beforehand a factor in what any failure costs afterwards.

The engagement

What you get from us

Sized to the answer. If you are unlikely to be designated, this is a short piece of work and we will say so in writing.

01

A likelihood assessment

Your position against all six factors, with reasoning you could show a board. Likelihood and the reasons for it, never a false verdict on something only the government decides.

02

The gap if it happened tomorrow

What the five obligations would cost you in time and structure, and which of them you are already most of the way to without realising.

03

A DPIA where one is warranted

For a specific high-risk activity rather than for the organisation in general. A DPIA of everything is a document nobody reads, including its author.

04

The algorithmic review

What automated decisioning you run, bought or built, and whether you could evidence Rule 13(2) diligence on each. Usually the first time anyone has listed them.

05

Or a short letter saying no

If you are plainly not a candidate, that is the deliverable, and it is worth having in writing when somebody tries to sell you SDF obligations next quarter.

Most businesses are not Significant Data Fiduciaries.

Finding that out early is cheaper than discovering it after you have bought a compliance programme built for one.

Questions

About SDF status and DPIAs

How do we know if we are a Significant Data Fiduciary?

You do not decide it. Section 10(1) of the Act makes it a designation by the Central Government, which may notify a particular Data Fiduciary or an entire class, weighing six factors: the volume and sensitivity of personal data processed, risk to data principals' rights, sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. What an assessment gives you is a reasoned likelihood and a plan, not a verdict — and anyone selling you certainty about a government decision is selling you something they do not have.

Do we need a DPIA if we are not an SDF?

Not as an obligation. §10(2)(c) makes periodic impact assessments a duty of Significant Data Fiduciaries specifically, and Rule 13 sets the twelve-month cadence. Many organisations do one anyway before a genuinely high-risk launch — a clinical product, a feature aimed at children, a model trained on customer records — because §33(2) makes what you did in advance an express factor in any penalty afterwards. Doing one where it is not owed is a choice; being unable to show you considered the risk is not a good position.

What is Rule 13's algorithmic due diligence?

A Significant Data Fiduciary must observe due diligence to verify that algorithmic software it deploys for processing personal data is not likely to pose a risk to data principals' rights. The part organisations miss is that it covers software you bought as well as software you wrote. "The vendor's tool decided" is not diligence — if the supplier cannot tell you what an outcome relied on, buying it has handed you an obligation rather than removed one.

What does the localisation obligation mean in practice?

Rule 13 provides for personal data specified by the Central Government to be restricted from transfer outside India. It is an architecture question rather than a policy one: where your databases, backups and object storage physically sit, and whether your processors can keep them here. Worth knowing your position before a designation makes it urgent, because moving a production estate between regions is not a quarter's work.

We are a hospital chain. Are we likely to be one?

Volume and sensitivity are the two factors that decide most ordinary cases, and clinical records score on both. A large multi-state chain is a more plausible candidate than a single-location hospital — but this is exactly the judgement worth reasoning through properly rather than assuming in either direction, because being wrong is expensive in both. Sector designation by class is also possible, which makes it a question about healthcare as much as about you.

What does it cost?

It depends on the size of your estate and how much automated decisioning you run, and we scope it rather than quote blind. If you are plainly not a candidate the work is short and the deliverable is a letter saying so. Be wary of anyone quoting a full SDF programme before establishing whether you are one — programmes for genuine SDFs are quoted across this market in the tens of lakhs, and most businesses do not owe them.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Find out before you are told.

The obligations attach the day you are designated. The gap between that day and being ready is measured in months.