Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Section 10 of the Digital Personal Data Protection Act, 2023: Duties of a Significant Data Fiduciary

A Significant Data Fiduciary must appoint a Data Protection Officer who represents it, is based in India, is an individual responsible to the Board of Directors or similar...

Published
Updated
Reading time
7 min
Views
9
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
Topic
Data Protection
Published
September 30, 2026
Last updated
Oct 9, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Section 10(2) sets extra duties for a notified Significant Data Fiduciary: appoint a Data Protection Officer who is based in India and answerable to the board, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessment, periodic audit and other prescribed measures. A legal due diligence review can test whether your organisation is ready for these.

Section 10(2) at a glance

ClauseDutyDetail in the text
(a)Appoint a Data Protection OfficerRepresents the fiduciary; based in India; an individual responsible to the Board of Directors or similar governing body; point of contact for grievance redressal
(b)Appoint an independent data auditorCarries out data audit; evaluates compliance with the Act
(c)(i)Periodic Data Protection Impact AssessmentDescription of rights and purposes, assessment and management of risk to rights, other matters prescribed
(c)(ii)Periodic auditFrequency not stated in the Act
(c)(iii)Other measures, consistent with the ActAs prescribed

These duties arise only for a Data Fiduciary notified under section 10(1). See notifying a Significant Data Fiduciary.

The Data Protection Officer: section 10(2)(a)

Section 2(l) defines the Data Protection Officer as an individual appointed by the Significant Data Fiduciary under section 10(2)(a), so the term in this Act is tied to Significant Data Fiduciaries. The four attributes listed in the Act:

  1. Represents the Significant Data Fiduciary under the Act. The DPO is its face for purposes of the Act.
  2. Based in India. The DPO must be located in India. The Act does not say the DPO must be a citizen, or an employee; it says "based in India".
  3. An individual responsible to the Board of Directors or similar governing body. The DPO is a natural person, not a firm or a team, and is answerable at the top. "Or similar governing body" covers entities without a board. The Act does not say the DPO must be a board member or a senior manager, nor that the post cannot be combined with other work; these points are not stated.
  4. Point of contact for the grievance redressal mechanism. This ties to section 8(10) and section 13. The DPO's business contact information is published under section 8(9). See section 8(9) and (10).

The Act does not list qualifications, independence safeguards or what the DPO may not do. If the Rules add any, they will be in the Rules, so check them.

The independent data auditor: section 10(2)(b)

The Significant Data Fiduciary must "appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act". Notes:

  • Independent. The auditor must be independent of the fiduciary. The Act does not define independence or name a qualification, so the selection should be defensible: no role in the processing being audited, no conflict.
  • Data audit. The audit evaluates compliance with the Act's provisions, which is wider than a security audit.
  • Frequency and report. The Act states no timetable for the audit under (b), and does not say the audit report must be filed with the Board. Those points, if any, are in the Rules.

Other measures: section 10(2)(c)

Three more duties:

  • (i) Periodic Data Protection Impact Assessment. The Act defines this: "a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed". So it has three elements: describe the rights and purpose, assess and manage risk to rights, and any further matters prescribed. "Periodic" means it is repeated; the Act does not give a number of months.
  • (ii) Periodic audit. The Act does not say how this differs from the data audit in (b). A reasonable reading is an ongoing audit activity by the fiduciary, in addition to the independent auditor's audit, but the text does not spell it out. Check the Rules.
  • (iii) Such other measures, consistent with the Act, as may be prescribed. The Rules can add to the list, but only consistently with the Act.

The DPDP Rules, 2025 (notified November 2025) prescribe the detail, and different provisions commence on different dates; this article states no rule-level detail. Check the Rules for timing, content and reporting.

How section 10 interacts with the rest of the Act

  • Exemption for some fiduciaries. Under section 17(3), the Central Government may notify Data Fiduciaries or classes, including startups, to which section 10 does not apply. See section 17(3).
  • Section 17(1) and (2). Section 17(1) excludes Chapter II, other than section 8(1) and (5), in its listed situations; that takes out section 10. Section 17(2) excludes the Act for the situations it lists.
  • Normal duties continue. Notice, consent, security safeguards, breach intimation and erasure duties apply as for any fiduciary. The overview post on special obligations covers the combined picture.

Consequence of breach

Item 4 of the Schedule: breach in observance of additional obligations of Significant Data Fiduciary under section 10 may extend to one hundred and fifty crore rupees. The Board imposes it after an inquiry, a hearing, and a finding that the breach is significant (section 33(1)), looking at the factors in section 33(2). See penalties.

Practical examples

Example 1: DPO outside India. A notified fiduciary names an employee of its foreign parent as DPO. The Act requires the DPO to be based in India, so the appointment does not meet section 10(2)(a)(ii).

Example 2: a team as DPO. A fiduciary names a "privacy team" without an individual. The Act speaks of "an individual".

Example 3: auditor who built the systems. The firm that designed and runs the fiduciary's data systems is named auditor. The Act requires an independent data auditor, and this choice invites the question.

Common mistakes

  • Appointing a DPO without a reporting line to the board or similar body.
  • Choosing an auditor with no independence.
  • Treating DPIA as a one-time project rather than periodic.
  • Waiting for a notification before any preparation.

Need help getting ready?

If you think you may be notified, or sell to customers that are, it helps to prepare the governance side early. Our legal due diligence team can review your data practices, contracts and reporting lines and point out gaps against section 10.

Key takeaways

  • A notified Significant Data Fiduciary must appoint an India-based DPO who is an individual responsible to the board or similar body.
  • It must appoint an independent data auditor to evaluate compliance.
  • It must run periodic Data Protection Impact Assessment and periodic audit, and take other prescribed measures.
  • The Act sets no frequencies or qualifications; check the Rules.
  • Breach may attract up to Rs 150 crore.

Read next

Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.

Quick recapKey facts & short answers

Key Facts About Section 10

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Who must appoint a Data Protection Officer?

A Significant Data Fiduciary, under section 10(2)(a). The term is defined in section 2(l) by reference to that appointment.

Must the DPO be in India?

Yes. The Act says the DPO shall be based in India.

Compliance is cheapest on the day it falls due and gets more expensive every day after.

— TaxClue Compliance Desk

Section 10: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

A Significant Data Fiduciary, under section 10(2)(a). The term is defined in section 2(l) by reference to that appointment.

Yes. The Act says the DPO shall be based in India.

Section 10(2)(a)(iii) requires an individual responsible to the Board of Directors or similar governing body.

Yes. Section 10(2)(b) says "independent data auditor". The Act does not define independence.

Under section 10(2)(c)(i), a process describing the rights of Data Principals and the purpose of processing, assessing and managing risk to those rights, and other prescribed matters.

Item 4 of the Schedule: up to one hundred and fifty crore rupees, subject to section 33.