loader image

DPDP’s Significant Data Fiduciary Designation Is the Sleeping Compliance Obligation for India’s GCCs

DPDP’s Significant Data Fiduciary Designation Is the Sleeping Compliance Obligation for India’s GCCs

Global Capability Centres (GCCs) in India have spent the last year preparing for the Digital Personal Data Protection Act, 2023 (“DPDP Act”). Privacy notices have been updated, vendor agreements revisited, cross-border data flows mapped, and internal policies refreshed. Yet, one of the Act’s most consequential compliance obligations has received comparatively little attention: the possibility of being designated as a Significant Data Fiduciary (“SDF”).

Unlike many obligations under the DPDP Act that apply to every Data Fiduciary, the SDF framework introduces an additional layer of governance for organisations whose processing activities present heightened regulatory concerns. For GCCs handling global HR data, customer support operations, cybersecurity monitoring, financial analytics, healthcare information or AI-enabled processing, this is not a provision that should be treated as a distant possibility. It is a governance issue that deserves board-level attention today.

SDF designation is based on risk: not organisational size

Section 10 of the DPDP Act empowers the Central Government to notify any Data Fiduciary, or class of Data Fiduciaries, as a Significant Data Fiduciary after considering factors such as the volume and sensitivity of personal data processed, the risk posed to the rights of Data Principals, potential impact on the sovereignty and integrity of India, security of the State, public order and electoral democracy.[1]

Importantly, the Act does not prescribe numerical thresholds based on employee strength, annual turnover or the number of records processed. Nor does it state that every GCC or multinational subsidiary will automatically become an SDF. The designation is ultimately a policy decision of the Central Government based on the statutory factors set out in Section 10.[2]

However, the absence of a fixed threshold should not encourage complacency. Many GCCs deal with personal data on a scale that goes far beyond routine back-office operations. Processing of large volumes of personal data across jurisdictions is often part of employee lifecycle management, payroll administration, fraud detection, AI model development, customer analytics and cybersecurity operations, continuously. Considering these realities of operations, organisations would be well advised to consider whether their governance framework could cope with the increased obligations that would apply to an SDF.

Why the SDF framework matters

The most important result of designation as an SDF is that privacy compliance is no longer about policy documents but about institutional governance.

Section 10 requires every Significant Data Fiduciary to appoint an India-based Data Protection Officer (“DPO”), engage an independent Data Auditor, conduct periodic Data Protection Impact Assessments (“DPIAs”), undertake periodic audits and comply with any additional measures prescribed under the Rules.[3]

The Digital Personal Data Protection Rules, 2025 further clarify these obligations. Rule 13 requires SDFs to conduct a DPIA and an audit at least once every twelve months, submit reports containing significant observations to the Data Protection Board, and exercise due diligence in ensuring that technical measures, including algorithmic software, do not pose risks to the rights of Data Principals.[4]

These are not obligations that can be implemented overnight. They require organisations to establish governance structures, identify internal accountability, document processing activities and integrate privacy oversight into enterprise risk management.

The India-based DPO requirement changes governance

For many multinational enterprises, privacy compliance is managed through regional or global legal teams located outside India. While such structures may continue to support enterprise-wide consistency, Section 10 requires the appointed DPO to be based in India, represent the organisation under the Act, report to the Board of Directors or an equivalent governing body, and function as the point of contact for grievance redressal.[5]

This reflects a broader legislative intent to embed privacy governance within corporate decision-making rather than treating it as a purely legal or technical function.

For GCCs, the question is therefore not simply who will become the DPO, but whether the existing governance model allows that individual to exercise the level of independence and oversight contemplated by the Act.

DPIAs should begin before designation

Although the statutory obligation to conduct DPIAs applies only after SDF designation, organisations should resist viewing DPIAs as a post-notification exercise.

A meaningful DPIA requires a clear understanding of what personal data is processed, where it originates, who accesses it, the purposes for which it is used, the risks posed to Data Principals and the measures adopted to mitigate those risks. For those GCCs dealing with global data sets across multiple business functions, it may take months, not weeks, to develop this understanding.

Starting this work early not only helps with future compliance but also improves data governance, strengthens internal controls and improves organisational readiness for regulatory scrutiny.

A practical way forward

Rather than trying to figure out if they will be deemed Significant Data Fiduciaries, GCCs should focus on developing their governance capabilities under the DPDP framework.

This includes maintaining an up-to-date inventory of personal data processing activities, reviewing reporting structures for privacy governance, integrating DPDP compliance into internal audit programmes, documenting AI-enabled processing activities and periodically assessing whether existing governance mechanisms remain fit for purpose.

The DPDP Act deliberately adopts a risk-based approach instead of a one-size-fits-all compliance model. Consequently, the organisations best prepared for future regulatory developments are unlikely to be those waiting for a notification, but those treating privacy governance as an integral component of enterprise risk management.[6]

Ultimately, the “sleeping obligation” under the DPDP Act is not the possibility of designation itself. It is the mistaken assumption that, if designation occurs, the necessary governance structures can be created at short notice. For GCCs entrusted with processing vast amounts of personal data on behalf of multinational enterprises, preparation not prediction will be the more effective compliance strategy.[7]


[1] Digital Personal Data Protection Act, No. 22 of 2023, S10(1)

[2] Id

[3] Id. S10(2).

[4] Digital Personal Data Protection Rules, 2025, r. 13.

[5] Digital Personal Data Protection Act, No. 22 of 2023, S 10(2)(a).

[6] Id. S 8(4)(6)

[7] Press Information Bureau, Government of India, DPDP Rules, 2025 Notified: A Citizen-Centric Framework for Privacy Protection and Responsible Data Use (Nov. 17, 2025).

Cookie Consent with Real Cookie Banner