Section 10 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Section 10(1) lets the Central Government notify any Data Fiduciary, or a class of Data Fiduciaries, as a Significant Data Fiduciary, based on an assessment of relevant factors. It lists six of them, but the list is not closed. If you want to gauge whether your business could be assessed as one, a legal consultation is a sensible first step.
The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary, on the basis of an assessment of relevant factors "including" six listed ones: volume and sensitivity of data, risk to Data Principals' rights, impact on India's sovereignty and integrity, risk to electoral democracy, security of the State and public order (section 10(1)). Nobody is a Significant Data Fiduciary until notified (section 2(z)). Once notified, the extra duties in section 10(2) apply, with a penalty of up to Rs 150 crore for breach.
Section 10(1) at a glance
| Factor in section 10(1) | Clause |
|---|---|
| Volume and sensitivity of personal data processed | (a) |
| Risk to the rights of Data Principal | (b) |
| Potential impact on the sovereignty and integrity of India | (c) |
| Risk to electoral democracy | (d) |
| Security of the State | (e) |
| Public order | (f) |
A status conferred by notification
Section 2(z) defines a Significant Data Fiduciary as "any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10". That has three practical consequences:
- Status is by notification, not by size alone. A business does not become a Significant Data Fiduciary merely by crossing a volume of data. The Central Government must notify it.
- It can be a class. A notification may name a Data Fiduciary or a whole class, for instance by type of activity. The Act does not name any class.
- The Act sets no numbers. It gives no volume threshold, turnover figure or number of users. The factors are qualitative.
Section 2(r) says "notification" means a notification published in the Official Gazette. Watch the Gazette and the Ministry's announcements for notifications. The DPDP Rules, 2025 (notified November 2025) prescribe detail and different provisions commence on different dates; check the Rules and the commencement notifications to see what applies and from when. This article states nothing from them.
The word "including": the list is not exhaustive
The Government assesses "such relevant factors as it may determine, including" the six in the list. The word "including" means the six are examples, and the Government may weigh other factors that it finds relevant. The sections do not say what they are. So a business that thinks it is clear of all six factors should not conclude it cannot be notified.
Reading the six factors
- (a) Volume and sensitivity of personal data processed. Two separate measures. A business with a small set of highly sensitive data (for example, health or financial details) and one with a large set of routine data can both attract attention. The Act does not define "sensitive"; it does not create a category of sensitive personal data.
- (b) Risk to the rights of Data Principals. The danger that processing could harm individuals' rights, such as through profiling, exposure or misuse. The assessment looks at risk, not at past breaches.
- (c) Potential impact on the sovereignty and integrity of India. A state-level concern; it will matter for large or strategic platforms and infrastructure.
- (d) Risk to electoral democracy. Processing that can influence or disrupt elections, for example by micro-targeting voters.
- (e) Security of the State.
- (f) Public order.
Factors (c) to (f) are worded at the level of the nation, not the individual. The Act does not explain how the Government will assess them. It does not say whether a hearing is given before notification, or whether a notification can be challenged; the text is silent, so do not assume either.
What follows from being notified
Section 10(2) then requires a Significant Data Fiduciary to appoint a Data Protection Officer based in India, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessment, periodic audit and other prescribed measures. See the article on section 10(2) and the overview on special obligations.
Being a Significant Data Fiduciary does not remove ordinary obligations. Sections 5 to 9 and the rest of the Act still apply, together with the additional duties.
Who is not caught: section 17(3)
Section 17(3) allows the Central Government to notify certain Data Fiduciaries or classes, including startups, having regard to the volume and nature of personal data processed, as Data Fiduciaries to whom section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 do not apply. The Act defines "startup" for this purpose in an Explanation: a private limited company, partnership firm or limited liability partnership incorporated in India, eligible to be and recognised as such under criteria and process notified by the department handling startups. So a notified entity is exempt from section 10, even if it would otherwise meet the factors. This is a notification-dependent relief and not an automatic one. See section 17(3).
Consequence of breach
Notification itself is not a penalty. The penalty arises if a Significant Data Fiduciary breaches its additional obligations. Item 4 of the Schedule: breach in observance of additional obligations of Significant Data Fiduciary under section 10 may extend to one hundred and fifty crore rupees. The Board imposes it after an inquiry, a hearing and a finding that the breach is significant (section 33(1)). See penalties.
Practical examples
Example 1: large platform. A platform holding identity and financial details of a very large user base is a likely candidate for assessment under factors (a) and (b). Whether it is notified is for the Government; the Act sets no automatic rule.
Example 2: small clinic chain. A small chain holds sensitive health records. The Act does not say small size rules out notification, because volume and sensitivity are separate measures and the list is non-exhaustive.
Example 3: class notification. The Government notifies a class of Data Fiduciaries. A business falling within the class definition becomes a Significant Data Fiduciary without being named individually.
Common mistakes
- Assuming a fixed turnover or user-count threshold exists in the Act.
- Treating the six factors as the only ones.
- Preparing for section 10 duties without checking whether a notification covers you.
- Assuming a startup is automatically exempt; section 17(3) needs a notification.
Need help assessing your position?
It is better to test early whether your data profile could attract a notification, and to plan for the added duties if it does. Through our legal consultation service, we can walk through the factors and your data map.
Key takeaways
- A Significant Data Fiduciary is one notified by the Central Government; the status is not automatic.
- A single Data Fiduciary or a class can be notified.
- Six factors are listed, but "including" keeps the list open.
- The Act sets no numeric thresholds.
- Breach of section 10 duties may attract up to Rs 150 crore.
Read next
- Section 10 of the DPDP Act, 2023: duties of a Significant Data Fiduciary
- Section 17 of the DPDP Act, 2023: startups and notified Data Fiduciaries
- Section 2 of the DPDP Act, 2023: definitions of Data Principal, Data Fiduciary and Data Processor
- Significant Data Fiduciary: special obligations
Disclaimer: Based on the Digital Personal Data Protection Act, 2023 (official text as enacted, No. 22 of 2023) as on 30 September 2026. The DPDP Rules, 2025 were notified in November 2025 and different provisions commence on different dates; this article does not state rule-level detail. Verify the current position in the Rules and the commencement notifications before acting.
