The regulation of digital platforms has emerged as one of the most contested areas of contemporary data protection law. Governments across the globe have moved, with increasing assertiveness, to impose localisation obligations, enhanced accountability requirements, and systemic risk assessments on entities that control large volumes of personal data. India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules) constitute India's most comprehensive attempt to regulate this space. Central to that effort is the Significant Data Fiduciary (SDF) framework, which imposes elevated obligations on platforms designated on account of the scale, sensitivity, or systemic risk of their data processing activities. This blog examines the SDF framework in the context of India's broader data localisation policy, evaluates the compliance obligations that designation imposes, and considers the interaction between the DPDP framework and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules 2021), which continue to govern the operational obligations of significant social media intermediaries.
The Architecture of the Significant Data Fiduciary Designation
The DPDP Act grants the Central Government broad authority under Section 10 to designate a Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciaries. The designation criteria include the volume of personal data processed; the sensitivity of such data, including its potential to infringe the rights of Data Principals; the risk to electoral democracy, security of the state, or public order; and the potential impact on sovereignty and integrity of India.¹ The criteria are intentionally broad, affording the Central Government considerable discretionary latitude in designation decisions.
A Data Fiduciary designated as a Significant Data Fiduciary bears several additional obligations beyond those applicable to ordinary Data Fiduciaries. It must appoint a Data Protection Officer (DPO) who is ordinarily resident in India and who reports directly to the board of directors or equivalent governing body of the fiduciary. It must appoint an independent data auditor to conduct a periodic audit of its compliance with the Act. It must undertake periodic Data Protection Impact Assessments (DPIAs) of its processing activities. It must register with the Data Protection Board of India. The DPO residency requirement is particularly significant: unlike the GDPR's DPO framework, which permits the DPO to be based anywhere within the EU, India requires physical presence in India, a requirement that large foreign-headquartered platform companies may need to address through dedicated compliance infrastructure rather than centralised global functions.
This blog contends that the SDF framework is best understood not as a pure privacy instrument but as a hybrid regulatory mechanism that blends privacy accountability with systemic risk governance. The designation criteria – electoral integrity, national security, sovereignty – extend well beyond traditional privacy law territory and situate the SDF framework alongside China's Critical Information Infrastructure regime and the EU's Digital Services Act (DSA) as expressions of platform governance through data law.
Data Localisation: Policy History and Current Architecture
India has pursued a fragmented data localisation agenda across multiple regulatory domains. Prior to the DPDP Act, the most significant localisation mandate came from the Reserve Bank of India, which, by circular dated 6 April 2018, required all payment system data to be stored exclusively in India.² The RBI subsequently clarified that an overseas copy was permissible for cross-border transactions, but the domestic storage obligation remained. The Insurance Regulatory and Development Authority of India similarly mandates that insurance sector data be stored domestically. The Securities and Exchange Board of India has imposed data localisation requirements on market infrastructure institutions.
The DPDP Act does not establish a general data localisation mandate. The negative-list approach to cross-border transfers in Rule 15 of the DPDP Rules reflects a policy choice in favour of permissive data flows, at least as a default position. However, the sectoral localisation norms described above continue to apply alongside the DPDP framework, creating a tiered compliance environment: entities in regulated sectors face both the general DPDP obligations and sector-specific localisation requirements that the DPDP Act does not disturb.
The key question for data governance practitioners is whether SDF designation will function, in practice, as a mechanism for imposing de facto localisation. Nothing in the DPDP Act expressly requires SDFs to store data domestically. However, the combination of DPO residency requirements, local registration obligations, mandatory DPIAs, and the Central Government's authority under Section 16 to restrict outbound transfers for designated fiduciaries creates a regulatory environment in which localisation pressure on SDFs is material and should be planned for in structuring cross-border data architectures.
The Interaction With IT Rules 2021 and Significant Social Media Intermediaries
The DPDP framework does not operate in a vacuum. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 continue in force and impose a parallel set of obligations on significant social media intermediaries (SSMIs), defined as intermediaries with over five million registered users in India. The IT Rules 2021 require SSMIs to appoint a Resident Grievance Officer (in India), a Chief Compliance Officer (ordinarily resident in India), and a Nodal Contact Person for coordination with law enforcement. They also require SSMIs to publish monthly compliance reports, respond to government orders about content removal and user identification within prescribed timelines, and enable the identification of the first originator of information in certain categories of unlawful content – a traceability obligation that has generated significant constitutional controversy.³
Digital platforms that qualify both as Data Fiduciaries under the DPDP framework and as significant social media intermediaries under the IT Rules 2021 face a layered regulatory burden that, at its outer edges, creates potential conflicts. The IT Rules 2021's traceability obligation, which requires platforms to break end-to-end encryption in specified circumstances, sits in tension with the DPDP Act's consent and purpose-limitation requirements – a user whose data is disclosed through a traceability order has not consented to that processing purpose. Courts and the Data Protection Board will eventually need to navigate the relationship between these instruments, and platforms ought to seek legal advice on the hierarchy of norms applicable to their specific activities.
The Ministry of Electronics and Information Technology has indicated that the IT Act and the DPDP Act are intended to operate as complementary instruments, with the DPDP Act governing personal data and the IT Rules governing intermediary liability. In practice, however, the two frameworks share jurisdictional terrain in respect of user data, and careful legal analysis is required to determine which instrument governs a given compliance question.
Children's Data: The Most Demanding Compliance Category
The DPDP Act establishes a particularly stringent set of obligations in respect of personal data of children (defined as individuals under the age of eighteen years). A Data Fiduciary processing children's data must verify the child's age and obtain verifiable parental consent before processing.⁴ The Act prohibits the targeting of advertising to children. It prohibits the tracking and monitoring of children's behaviour. It prohibits the collection of data likely to cause a detrimental effect on the wellbeing of children.
Rule 9 of the DPDP Rules addresses the verification of age and parental consent. The practical implementation of age verification at scale is one of the most technically demanding aspects of the DPDP compliance programme for consumer-facing platforms. The Rules contemplate the use of a trust-based system for age verification through approved mechanisms, but as of June 2026, the detailed technical standards for age verification mechanisms have not yet been prescribed. SDFs that process children's data must actively monitor the Central Government's supplementary notifications in this regard and implement compliant verification mechanisms as soon as standards are prescribed.
The children's data obligations mirror, in structure, the approach of the UK's Age Appropriate Design Code (Children's Code), implemented under the UK Data Protection Act 2018, and the protections for children's data under the GDPR's recital 38 and the US Children's Online Privacy Protection Act (COPPA). Indian counsel advising technology companies that already operate in the UK or US would benefit from mapping their existing children's data compliance programmes against the DPDP Act's requirements, identifying gaps and applying those learnings to the India compliance design.
Conducting a Data Protection Impact Assessment Under the DPDP Framework
SDFs are required to conduct Data Protection Impact Assessments under Section 10(2)(b) of the DPDP Act. While the DPDP Rules do not yet prescribe detailed DPIA procedural rules comparable to those in Article 35 of the GDPR, the objectives of the DPIA are implicit in the Act: to identify and assess the risks to Data Principals arising from the proposed processing activity, and to evaluate whether those risks can be mitigated by technical or organisational measures.
A DPIA methodology appropriate for the Indian context should address: the nature, scope, context, and purpose of the processing activity; the necessity and proportionality of the processing relative to the stated purpose; the categories of personal data involved and their sensitivity; the likely impact on the rights and freedoms of Data Principals; the technical and organisational measures proposed to mitigate identified risks; and the adequacy of consent mechanisms.
Firms developing DPIA templates for India operations may usefully draw on the ICO's DPIA guidance under the UK GDPR and the CNIL's methodology under the French data protection framework, adapting these to the DPDP Act's specific consent and purpose-limitation architecture. The absence of equivalent Indian regulatory guidance at this stage means that adopting best international practice is both commercially prudent and likely to be viewed favourably by the Data Protection Board in any subsequent inquiry.
Penalties, Enforcement and the Adjudicatory Timeline
The DPDP Act's penalty structure is graduated and creates significant financial exposure for non-compliant SDFs. The Act provides for penalties of up to Rs. 250 crore for breach of obligations applicable to a Data Fiduciary (including, for SDFs, the enhanced obligations described above), Rs. 200 crore for breach of obligations relating to children's data, and Rs. 50 crore for breach of notice and consent requirements, among other heads.⁵
The Data Protection Board of India is empowered to conduct inquiries of its own motion or on complaint. Its proceedings are designed to be summary and digital in nature. However, as of June 2026, the DPB is in the process of operationalisation, and its secretariat and procedural framework are still being constituted. This transitional period does not diminish the substantive compliance obligation: the DPDP Act's provisions are in force, and the phased commencement structure the Central Government adopted in November 2025 has progressively activated compliance obligations.
Practitioners and in-house counsel should note that the penalty sums, while large by Indian standards, are modest relative to GDPR sanctions (which may reach four per cent of global annual turnover for the most serious violations). However, the reputational consequences of a public DPB inquiry, and the Board's authority to direct cessation of processing and deletion of data, mean that the practical stakes of non-compliance extend well beyond the monetary penalty ceiling.
Conclusion
The Significant Data Fiduciary framework under the DPDP Act 2023 and the DPDP Rules 2025 represents India's most sophisticated instrument of platform governance. This blog has argued that the SDF designation criteria, taken in context with the sectoral data localisation norms and the parallel obligations under the IT Rules 2021, create a complex compliance environment for digital platforms operating at scale in India. The framework is not yet fully operationalised: DPIA procedural rules, age verification standards, and the restricted countries list under Rule 15 remain to be prescribed. Platforms that await comprehensive regulatory guidance before initiating compliance planning do so at material risk. The prudent course is to begin SDF risk assessment, DPO appointment planning, DPIA methodology development, and children's data audit now, treating the current regulatory landscape as the floor rather than the ceiling of compliance obligation.
Endnotes
1. Digital Personal Data Protection Act 2023 (India), s 10(1).
2. Reserve Bank of India, 'Storage of Payment System Data' (Circular RBI/2017-18/153, 6 April 2018).
3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (India), r 4(2); WhatsApp LLC v Union of India Writ Petition (Civil) No 3592 of 2021 (Delhi HC, pending).
4. Digital Personal Data Protection Act 2023 (India), s 9.
5. Digital Personal Data Protection Act 2023 (India), s 33, Schedule.
Authors

Related insights
View moreArtificial Intelligence Regulation in India: The Emerging Framework, Sectoral Obligations, and Global Comparisons
An analysis of the patchwork AI governance architecture in India, including MeitY advisories, DPDP Act relevance, and sectoral guidelines.
Infrastructure Investment Trusts in India: Structuring, SEBI Regulation, and the InvIT as a Capital Markets Instrument
Examining the InvIT structure, SEBI's 2026 amendments, NAMP pipeline asset monetisation, and debt financing dynamics under Indian trust laws.
ESG-Linked Fundraising in India: Regulatory Expectations, Investor Demands and Structuring Considerations
ESG considerations have moved from the margins of the alternative investment landscape to its center in India.