Legal Register
Legal Register
ACT-10 Tranche 3 (13 May 2027) — Core Operating Cliff Status: scheduled, not yet operative

Section 10: Notification of fiduciary or class following relevant-factor assessment

Voluntary readiness is not a legal designation; independence is not an express firm-wide ban here.

Regulated Actor: Central Government; notified SDF
Gazette Baseline: Lines 404–438
Statutory Trigger

Notification of fiduciary or class following relevant-factor assessment

Applies to: Central Government; notified SDF

Substantive Conditions

India-based individual DPO responsible to governing body; independent auditor; periodic DPIA/audit and prescribed measures.

Statutory Exceptions

Not automatic from scale/sensitivity; designation and effective timing matter.

Official Gazette Text (Verbatim Publication)

Ministry of Law and Justice publication, Digital Personal Data Protection Act, 2023.

ACT-10
Additional 10. (1) The Central Government may notify any Data Fiduciary or class of Data obligations of Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant Significant Data factors as it may determine, including— Fiduciary. SEC. 1] THE GAZETTE OF INDIA EXTRAORDINARY 9 (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order. (2) The Significant Data Fiduciary shall— (a) appoint a Data Protection Officer who shall— (i) represent the Significant Data Fiduciary under the provisions of this Act; (ii) be based in India; (iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and (iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act; (b) appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and (c) undertake the following other measures, namely:— (i) periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed; (ii) periodic audit; and (iii) such other measures, consistent with the provisions of this Act, as may be prescribed.