DATA PROTECTION

DPDP Data Protection Officer: When It's Mandatory

The DPDP Act requires a Data Protection Officer only for entities classified as Significant Data Fiduciaries. Most foreign-owned Indian entities are not automatically in that category -- but the criteria are worth checking properly, not assumed.

The Digital Personal Data Protection Act creates a distinct, heavier compliance tier for entities classified as Significant Data Fiduciaries (SDFs) -- a designation based on factors including the volume and sensitivity of personal data processed, and risk to data principals, as notified by the government. A mandatory Data Protection Officer, based in India, is one of the specific obligations that applies to SDFs, not to every data fiduciary.

Why this matters before assuming you need one

Many foreign-owned Indian entities process meaningful volumes of employee and customer personal data without coming close to SDF thresholds, which are calibrated for large-scale processors. Appointing a full DPO role prematurely is a real cost -- a dedicated, appropriately qualified, India-based role -- that isn't legally required until the SDF threshold is actually met.

What an SDF designation actually requires

  • A Data Protection Officer based in India, who represents the SDF for the purposes of the Act and is the point of contact for data principals' grievances.
  • An independent data auditor to conduct periodic data protection impact assessments and audits.
  • Periodic data protection impact assessments, reviewed by the DPO.

What non-SDF entities still need

Even without SDF designation, every data fiduciary has baseline obligations -- valid consent, purpose limitation, reasonable security safeguards, and breach notification. A grievance redressal mechanism is required generally, though the DPO-specific role is an SDF obligation. Many companies conflate "we need a compliance contact for data grievances" with "we need a formally designated DPO" -- the first is broadly required, the second is not, until SDF status applies.

The practical approach

Assess your actual SDF exposure based on data volumes and categories processed, rather than assuming either extreme -- that a foreign subsidiary is automatically exempt, or that any meaningful data processing automatically requires a DPO. If you are not currently an SDF but are scaling data processing volume quickly, it is worth monitoring proximity to the threshold rather than being caught by a designation after the fact.

Written for general information, not as legal or tax advice, and it does not create an advisor–client relationship. Indian tax and regulatory positions change at least annually — check the date above, then talk to someone before acting on it.
Structure first. Control early. Scale efficiently.
23+ years structuring India operations for global business.
Talk to an Expert