Section 10 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 10(2) sets extra duties for a notified Significant Data Fiduciary: appoint a Data Protection Officer who is based in India and answerable to the board, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessment, periodic audit and other prescribed measures. A legal due diligence review can test whether your organisation is ready for these.
A Significant Data Fiduciary must appoint a Data Protection Officer who represents it, is based in India, is an individual responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal (section 10(2)(a)). It must appoint an independent data auditor to evaluate its compliance (section 10(2)(b)), and undertake periodic Data Protection Impact Assessment, periodic audit and other prescribed measures (section 10(2)(c)). Breach attracts up to Rs 150 crore (Schedule, item 4).
Section 10(2) at a glance
| Clause | Duty | Detail in the text |
|---|---|---|
| (a) | Appoint a Data Protection Officer | Represents the fiduciary; based in India; an individual responsible to the Board of Directors or similar governing body; point of contact for grievance redressal |
| (b) | Appoint an independent data auditor | Carries out data audit; evaluates compliance with the Act |
| (c)(i) | Periodic Data Protection Impact Assessment | Description of rights and purposes, assessment and management of risk to rights, other matters prescribed |
| (c)(ii) | Periodic audit | Frequency not stated in the Act |
| (c)(iii) | Other measures, consistent with the Act | As prescribed |
These duties arise only for a Data Fiduciary notified under section 10(1). See notifying a Significant Data Fiduciary.
The Data Protection Officer: section 10(2)(a)
Section 2(l) defines the Data Protection Officer as an individual appointed by the Significant Data Fiduciary under section 10(2)(a), so the term in this Act is tied to Significant Data Fiduciaries. The four attributes listed in the Act:
- Represents the Significant Data Fiduciary under the Act. The DPO is its face for purposes of the Act.
- Based in India. The DPO must be located in India. The Act does not say the DPO must be a citizen, or an employee; it says "based in India".
- An individual responsible to the Board of Directors or similar governing body. The DPO is a natural person, not a firm or a team, and is answerable at the top. "Or similar governing body" covers entities without a board. The Act does not say the DPO must be a board member or a senior manager, nor that the post cannot be combined with other work; these points are not stated.
- Point of contact for the grievance redressal mechanism. This ties to section 8(10) and section 13. The DPO's business contact information is published under section 8(9). See section 8(9) and (10).
The Act does not list qualifications, independence safeguards or what the DPO may not do. If the Rules add any, they will be in the Rules, so check them.
The independent data auditor: section 10(2)(b)
The Significant Data Fiduciary must "appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act". Notes:
- Independent. The auditor must be independent of the fiduciary. The Act does not define independence or name a qualification, so the selection should be defensible: no role in the processing being audited, no conflict.
- Data audit. The audit evaluates compliance with the Act's provisions, which is wider than a security audit.
- Frequency and report. The Act states no timetable for the audit under (b), and does not say the audit report must be filed with the Board. Those points, if any, are in the Rules.
Other measures: section 10(2)(c)
Three more duties:
- (i) Periodic Data Protection Impact Assessment. The Act defines this: "a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed". So it has three elements: describe the rights and purpose, assess and manage risk to rights, and any further matters prescribed. "Periodic" means it is repeated; the Act does not give a number of months.
- (ii) Periodic audit. The Act does not say how this differs from the data audit in (b). A reasonable reading is an ongoing audit activity by the fiduciary, in addition to the independent auditor's audit, but the text does not spell it out. Check the Rules.
- (iii) Such other measures, consistent with the Act, as may be prescribed. The Rules can add to the list, but only consistently with the Act.
The DPDP Rules, 2025 (notified November 2025) prescribe the detail, and different provisions commence on different dates; this article states no rule-level detail. Check the Rules for timing, content and reporting.
How section 10 interacts with the rest of the Act
- Exemption for some fiduciaries. Under section 17(3), the Central Government may notify Data Fiduciaries or classes, including startups, to which section 10 does not apply. See section 17(3).
- Section 17(1) and (2). Section 17(1) excludes Chapter II, other than section 8(1) and (5), in its listed situations; that takes out section 10. Section 17(2) excludes the Act for the situations it lists.
- Normal duties continue. Notice, consent, security safeguards, breach intimation and erasure duties apply as for any fiduciary. The overview post on special obligations covers the combined picture.
Consequence of breach
Item 4 of the Schedule: breach in observance of additional obligations of Significant Data Fiduciary under section 10 may extend to one hundred and fifty crore rupees. The Board imposes it after an inquiry, a hearing, and a finding that the breach is significant (section 33(1)), looking at the factors in section 33(2). See penalties.
Practical examples
Example 1: DPO outside India. A notified fiduciary names an employee of its foreign parent as DPO. The Act requires the DPO to be based in India, so the appointment does not meet section 10(2)(a)(ii).
Example 2: a team as DPO. A fiduciary names a "privacy team" without an individual. The Act speaks of "an individual".
Example 3: auditor who built the systems. The firm that designed and runs the fiduciary's data systems is named auditor. The Act requires an independent data auditor, and this choice invites the question.
Common mistakes
- Appointing a DPO without a reporting line to the board or similar body.
- Choosing an auditor with no independence.
- Treating DPIA as a one-time project rather than periodic.
- Waiting for a notification before any preparation.
Need help getting ready?
If you think you may be notified, or sell to customers that are, it helps to prepare the governance side early. Our legal due diligence team can review your data practices, contracts and reporting lines and point out gaps against section 10.
Key takeaways
- A notified Significant Data Fiduciary must appoint an India-based DPO who is an individual responsible to the board or similar body.
- It must appoint an independent data auditor to evaluate compliance.
- It must run periodic Data Protection Impact Assessment and periodic audit, and take other prescribed measures.
- The Act sets no frequencies or qualifications; check the Rules.
- Breach may attract up to Rs 150 crore.
Read next
- Section 10 of the DPDP Act, 2023: notifying a Significant Data Fiduciary
- Section 8 of the DPDP Act, 2023: contact information and grievance redressal
- Section 17 of the DPDP Act, 2023: startups and notified Data Fiduciaries
- Significant Data Fiduciary: special obligations
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
