Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
Under India DPDP Act, Section 10
Source-linked
Open official source
What does it require?
Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.
Practical action
Assess whether your AI data processing could trigger SDF designation and prepare DPIA tooling.
Who does it apply to?
Entities notified as Significant Data Fiduciaries.
- Sectors
- Cross-sector / all sectors
Evidence examples
- Data protection impact assessment (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 6.1.4 AI system impact assessment | Original editorial mapping. | medium |
Similar obligations in other instruments
- Carry out a fundamental rights impact assessment before deployment — EU AI Act, European Union
- Carry out a data protection impact assessment for high-risk AI processing — ICO AI guidance, United Kingdom
- Deployers must complete impact assessments for high-risk AI — Colorado AI Act, Colorado (United States)
- Conduct a data protection impact assessment for high-risk processing using new technologies — UAE PDPL, United Arab Emirates
- Map context, intended use and potential impacts (Map) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.