Whether you are likely to be designated a Significant Data Fiduciary, what changes the day you are, and what you do not owe until then.
Section 10(1) makes this a designation by the Central Government, which changes what “readiness” can honestly mean.
The government may notify a Data Fiduciary, or a whole class of them, as significant. You cannot opt in, and you cannot opt out by arguing you are small.
A notification can name a category of business rather than a named entity. So the question is not only about you — it is about the sector you sit in.
There is no build phase after designation. A DPO based in India, an independent auditor and an impact assessment are not a fortnight’s work.
Which is the whole argument for assessing now rather than later. Not because you owe anything today — most readers of this page do not — but because the gap between designation and compliance is measured in months, and the notification does not wait for you to close it.
It is sized to the answer. If you are plainly not a candidate, the work is short and we will say so in writing.
Volume and sensitivity, risk to people’s rights, sovereignty, electoral democracy, security of the State, public order — with reasoning a board could read.
What the five additional obligations would take in time and structure, and which of them you are already most of the way towards without realising.
For a specific high-risk activity rather than for the organisation at large. A DPIA of everything is a document nobody reads, including whoever wrote it.
Bought and built, and whether you could evidence Rule 13(2) diligence on each. For most clients this is the first time anyone has written the list down.
And there is a fifth outcome we would rather sell you than the other four. If the six factors point clearly away from designation, you get that as a short written assessment — which is worth having on file the next time somebody tries to sell you an SDF programme you do not owe.
Six factors are named in the Act. Two of them decide most ordinary cases; the other four decide the ones nobody expects.
The practical test for most businesses. A chain holding millions of clinical records is a different proposition from a single clinic holding thousands.
Not just how much you hold but what happens to a person if it goes wrong. Health, finance and children’s data carry weight here that contact details do not.
Infrastructure, defence-adjacent supply chains, anything the state has an interest in keeping inside its own borders.
Platforms that shape what large numbers of people see. Unusual to trip, and decisive when you do.
The factor that catches businesses who think of themselves as ordinary because their own product is ordinary. Who your customers are can matter more than what you sell.
Broad by design, and the one that makes a confident self-assessment unwise. Likelihood is the honest output here, not a verdict.
Everything else in the Act still applies. These are the additions, and one of them is rarely discussed anywhere.
A Data Protection Officer based in India, answerable to the board and the point of contact for grievance redressal. A named person, not a mailbox.
DPOAn independent data auditor to carry out a data audit. Independent means not you, and not the people who built what is being audited.
AuditorA data protection impact assessment and an audit every twelve months, with significant observations reported to the Board.
DPIA + auditDue diligence that algorithmic software you deploy on personal data does not risk data principals’ rights — including software you bought.
AlgorithmicPersonal data the government specifies must not leave India. A localisation obligation that lands on your architecture, not your policy.
LocalisationThe algorithmic one is the sleeper. Every business now runs scoring, ranking, routing or recommendation somewhere, and most bought it rather than built it — which does not move the duty. If a vendor cannot tell you what their system relied on to reach an outcome, you cannot discharge Rule 13(2) by having purchased it.
The Act defines it, which is unusually helpful. Four things, and the third is where the work is.
Described, not assumed. Who they are, what they can ask of you, and how they would go about it — which for most organisations is the first time anyone has written it down from the person’s side rather than the system’s.
Stated at a granularity somebody could disagree with. “Improving services” is not a purpose you can assess the risk of, and a DPIA built on one assesses nothing.
What actually happens to a person if this goes wrong. Not a heat map — the specific harm: the patient whose diagnosis reaches an employer, the candidate whose rejection reasons reach their current manager.
The measures, and honestly whether they work. A DPIA that concludes everything is fine is the one an auditor reads most carefully, because almost nothing is.
A DPIA is mandatory only for a Significant Data Fiduciary. Plenty of organisations do one anyway before a high-risk launch — a new clinical product, a children’s feature, a model trained on customer records — because §33(2) makes what you did beforehand a factor in what any failure costs afterwards.
Sized to the answer. If you are unlikely to be designated, this is a short piece of work and we will say so in writing.
Your position against all six factors, with reasoning you could show a board. Likelihood and the reasons for it, never a false verdict on something only the government decides.
What the five obligations would cost you in time and structure, and which of them you are already most of the way to without realising.
For a specific high-risk activity rather than for the organisation in general. A DPIA of everything is a document nobody reads, including its author.
What automated decisioning you run, bought or built, and whether you could evidence Rule 13(2) diligence on each. Usually the first time anyone has listed them.
If you are plainly not a candidate, that is the deliverable, and it is worth having in writing when somebody tries to sell you SDF obligations next quarter.
Finding that out early is cheaper than discovering it after you have bought a compliance programme built for one.
You do not decide it. Section 10(1) of the Act makes it a designation by the Central Government, which may notify a particular Data Fiduciary or an entire class, weighing six factors: the volume and sensitivity of personal data processed, risk to data principals' rights, sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. What an assessment gives you is a reasoned likelihood and a plan, not a verdict — and anyone selling you certainty about a government decision is selling you something they do not have.
Not as an obligation. §10(2)(c) makes periodic impact assessments a duty of Significant Data Fiduciaries specifically, and Rule 13 sets the twelve-month cadence. Many organisations do one anyway before a genuinely high-risk launch — a clinical product, a feature aimed at children, a model trained on customer records — because §33(2) makes what you did in advance an express factor in any penalty afterwards. Doing one where it is not owed is a choice; being unable to show you considered the risk is not a good position.
A Significant Data Fiduciary must observe due diligence to verify that algorithmic software it deploys for processing personal data is not likely to pose a risk to data principals' rights. The part organisations miss is that it covers software you bought as well as software you wrote. "The vendor's tool decided" is not diligence — if the supplier cannot tell you what an outcome relied on, buying it has handed you an obligation rather than removed one.
Rule 13 provides for personal data specified by the Central Government to be restricted from transfer outside India. It is an architecture question rather than a policy one: where your databases, backups and object storage physically sit, and whether your processors can keep them here. Worth knowing your position before a designation makes it urgent, because moving a production estate between regions is not a quarter's work.
Volume and sensitivity are the two factors that decide most ordinary cases, and clinical records score on both. A large multi-state chain is a more plausible candidate than a single-location hospital — but this is exactly the judgement worth reasoning through properly rather than assuming in either direction, because being wrong is expensive in both. Sector designation by class is also possible, which makes it a question about healthcare as much as about you.
It depends on the size of your estate and how much automated decisioning you run, and we scope it rather than quote blind. If you are plainly not a candidate the work is short and the deliverable is a letter saying so. Be wary of anyone quoting a full SDF programme before establishing whether you are one — programmes for genuine SDFs are quoted across this market in the tens of lakhs, and most businesses do not owe them.
Real client quotes, attributed by role and sector — we never name a client.
Working across
The obligations attach the day you are designated. The gap between that day and being ready is measured in months.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.