Legal requirement Impact assessment India Partially applicable

Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits

Under India DPDP Act, Section 10

Source-linked Open official source

What does it require?

Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.

Practical action

Assess whether your AI data processing could trigger SDF designation and prepare DPIA tooling.

Who does it apply to?

Entities notified as Significant Data Fiduciaries.

Evidence examples

  • Data protection impact assessment (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 6.1.4 AI system impact assessmentOriginal editorial mapping.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.