0% found this document useful (0 votes)
4 views17 pages

Module 3

The document outlines compliance and governance requirements under the DPDPA, focusing on the designation of Significant Data Fiduciaries (SDFs) and their enhanced obligations such as appointing a Data Protection Officer (DPO) and conducting Data Protection Impact Assessments (DPIAs). It details the criteria for SDF designation, the consequences of non-compliance, and the need for meticulous record-keeping and independent audits. The document emphasizes a proportionate regulation approach, ensuring that larger organizations face stricter compliance requirements to protect Data Principals' rights.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views17 pages

Module 3

The document outlines compliance and governance requirements under the DPDPA, focusing on the designation of Significant Data Fiduciaries (SDFs) and their enhanced obligations such as appointing a Data Protection Officer (DPO) and conducting Data Protection Impact Assessments (DPIAs). It details the criteria for SDF designation, the consequences of non-compliance, and the need for meticulous record-keeping and independent audits. The document emphasizes a proportionate regulation approach, ensuring that larger organizations face stricter compliance requirements to protect Data Principals' rights.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

DPDPA Sections DPDP Rules BLOGS CASE LAWS Templates Poster's Certificate Course Tools ▼ DPDPA QUIZ FAQ's

5
02
-2
24
Module 3 of 4

20
Compliance & Governance

©
Building Robust Data Protection Programs

M
Estimated Reading Time: 20-25 minutes

O
.C
PA

Table of Contents
PD

1. Significant Data Fiduciary Designation

2. Data Protection Impact Assessment (DPIA)


D

3. Data Protection Officer (DPO)

4. Cross-Border Data Transfer Rules

5. Record-Keeping & Audit Obligations

1. Significant Data Fiduciary (SDF) Designation


Not all Data Fiduciaries are created equal. Organizations processing large volumes of personal data or handling sensitive information face
enhanced obligations under DPDPA. These are designated as Significant Data Fiduciaries (SDFs).

What Makes a Data Fiduciary "Significant"?

Section 10(1) empowers the Central Government to notify Data Fiduciaries as "Significant" based on assessment of these factors:

1. Volume and Sensitivity: Amount and nature of personal data processed


2. Risk to Rights: Potential harm to Data Principals' rights
3. Sovereignty Impact: Effect on India's sovereignty and integrity
4. Electoral Democracy: Risk to democratic processes
5. Security of State: National security implications
6. Public Order: Impact on public order and safety

Who is Likely to be Designated as SDF?

Likely SDFs (Based on Criteria):

Large Tech Platforms: Google, Meta, Amazon, Microsoft (billion+ Indian users)
Telecom Operators: Airtel, Jio, Vi (comprehensive location and communication data)
Major E-commerce: Flipkart, Amazon India, Paytm (transaction data at scale)
Large Banks & Financial Institutions: SBI, HDFC, ICICI (sensitive financial data)
Healthcare Platforms: Apollo 24/7, Practo (health data)
Major EdTech: BYJU'S, Unacademy (children's data)

Possibly NOT SDFs:

Small e-commerce with limited user base


Local healthcare clinics with manual records
SMEs processing minimal personal data
Enhanced Obligations for SDFs (Section 10(2) & Rule 13)

Once notified as SDF, the organization MUST:

1. Appoint Data Protection Officer (DPO) - Must be based in India, responsible to Board
2. Conduct Periodic DPIA - Data Protection Impact Assessment annually
3. Conduct Independent Audits - External auditor evaluates compliance annually
4. Submit Reports to Board - Furnish DPIA and audit findings to Data Protection Board
5. Algorithm Due Diligence - Verify algorithmic software doesn't pose risks to Data Principals
6. Data Localization (if notified) - Certain sensitive data categories may be restricted from cross-border transfer

Consequences of SDF Non-Compliance

SDFs face the highest penalties under DPDPA:

Up to ₹250 crores + ₹150 crores for violations and additional obligations


Failure to appoint DPO → Penalty
Not conducting DPIA/audit → Penalty
Non-compliance with data localization → Severe penalty

The designation as SDF is a serious matter that transforms compliance requirements fundamentally.

Philosophy: Proportionate Regulation

DPDPA follows the principle of proportionate regulation: Greater power comes with greater responsibility. Organizations with
massive data processing capabilities and potential to cause large-scale harm face correspondingly stricter obligations.

This approach balances:

Not overburdening small businesses (SMEs get lighter compliance)


Ensuring big tech and platforms are held to highest standards
Protecting Data Principals from systemic risks
Key Takeaways - Section 1

Central Government notifies SDFs based on 6 statutory factors


Volume, sensitivity, and risk to rights are primary considerations
SDFs include large tech platforms, telecoms, major e-commerce, banks
Enhanced obligations: DPO, DPIA, audits, algorithmic due diligence
Penalties up to ₹250 crores + ₹150 crores for SDF violations
Proportionate regulation: Bigger organizations = stricter compliance

↑ Back to Top

2. Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is a systematic evaluation of data processing activities to identify and mitigate risks to Data
Principals' rights. Under Section 10(2)(c)(i) and Rule 13, SDFs must conduct periodic DPIAs.

What is a DPIA?

DPIA is a structured process comprising:

1. Description of Rights: Identify Data Principals' rights that may be affected


2. Purpose of Processing: Document why personal data is being processed
3. Risk Assessment: Evaluate risks to Data Principals (privacy breaches, discrimination, etc.)
4. Risk Management: Identify measures to mitigate identified risks
5. Other Prescribed Matters: As per DPDP Rules

Frequency: At least once every 12 months from SDF notification date


DPIA Example: Social Media Platform

Scenario: A social media platform (SDF) introduces a new AI-powered "friend recommendation" feature that analyzes user behavior,
location, and interests.

DPIA Process:

1. Describe Rights Affected:

Right to access (users may not know what data is analyzed)


Right to correction (algorithm may use outdated preferences)
Right to object to profiling

2. Purpose: Improve user experience by suggesting relevant connections

3. Risk Assessment:

High Risk: Sensitive inferences (religion, political views) may be derived


Medium Risk: Location tracking may reveal home/work addresses
Low Risk: Basic interest matching (e.g., both like cricket)

4. Mitigation Measures:

Implement consent mechanism specifically for this feature


Allow users to opt-out of behavioral analysis
Provide transparency report showing what data is used
Regular algorithm audits to detect bias
Data minimization: Use only necessary attributes

5. Submit Report: Significant findings submitted to Data Protection Board

DPIA Compliance Checklist

Conduct DPIA within 12 months of SDF notification

Document all processing activities comprehensively


Identify high-risk processing (profiling, children's data, sensitive data)

Assess risks: likelihood and severity

Design mitigation strategies for each identified risk

Engage independent assessor (external consultant/auditor)

Submit DPIA report with significant observations to Board

Review and update DPIA annually

Implement recommended safeguards

Maintain DPIA records for audit

Key Takeaways - Section 2

DPIA is mandatory for SDFs, conducted annually


Systematic process: Describe rights, purpose, assess risks, manage risks
Must be conducted by independent assessor
Significant findings reported to Data Protection Board
DPIA is proactive risk management, not reactive compliance
Helps organizations identify privacy issues before they become violations

↑ Back to Top

3. Data Protection Officer (DPO)


The Data Protection Officer (DPO) is the linchpin of an SDF's compliance program. Under Section 10(2)(a), every SDF must appoint a
DPO.

Who is the Data Protection Officer?

Legal Requirements (Section 10(2)(a)):

1. Represent the SDF: Acts as official representative under DPDPA


2. Based in India: Must be resident in India (not remote from another country)
3. Report to Board: Responsible to Board of Directors or similar governing body
4. Point of Contact: Interface for grievance redressal with Data Principals
5. Liaison with Data Protection Board: Primary contact for regulatory interactions

DPO Duties & Responsibilities

1. Compliance Oversight: Monitor SDF's adherence to DPDPA and DPDP Rules


2. Training & Awareness: Educate employees on data protection obligations
3. Policy Development: Develop and update data protection policies
4. Grievance Handling: Manage Data Principal complaints and grievances
5. DPIA Coordination: Oversee Data Protection Impact Assessments
6. Audit Facilitation: Coordinate independent data audits
7. Breach Response: Lead data breach notification and remediation
8. Board Reporting: Regular compliance updates to leadership
9. Regulatory Liaison: Interface with Data Protection Board
10. Record-Keeping: Maintain comprehensive compliance documentation

A Day in the Life of a DPO

Morning (9 AM - 12 PM):

Review overnight data breach alerts (none today, thankfully)


Meeting with engineering team about new feature launch - conduct quick DPIA review
Approve updated privacy notice for mobile app
Respond to 3 Data Principal access requests

Afternoon (2 PM - 5 PM):

Training session for customer support team on handling data requests


Review quarterly DPIA report prepared by external consultant
Call with legal team about cross-border data transfer agreement
Update Board presentation on compliance status

Evening (5 PM - 6 PM):

Review Data Protection Board circular on consent management


Email to CEO: Recommend additional budget for security upgrades

DPO: Skills and Qualifications

DPDPA does NOT prescribe specific qualifications, but effective DPOs typically have:

Legal Knowledge: Understanding of DPDPA, IT Act, relevant laws


Technical Expertise: Familiarity with data systems, security, encryption
Business Acumen: Balance compliance with business objectives
Communication Skills: Interface with Board, employees, regulators, Data Principals
Independence: Ability to report concerns without fear

Emerging certifications: CIPP/E (Certified Information Privacy Professional), CIPM (Certified Information Privacy Manager)

Key Takeaways - Section 3

DPO mandatory only for SDFs (not all Data Fiduciaries)


Must be based in India and report to Board of Directors
Represents SDF in all DPDPA matters
Primary responsibilities: compliance oversight, training, DPIA, grievances
No specific qualifications prescribed, but legal + technical knowledge essential
DPO ensures accountability at highest organizational level

↑ Back to Top

4. Cross-Border Data Transfer Rules

Section 16 grants the Central Government power to restrict cross-border transfer of personal data to specific countries or territories. This is
one of the most debated provisions of DPDPA.

Cross-Border Transfer Framework

Section 16(1): Central Government may, by notification, restrict transfer of personal data to specific countries/territories outside India.

Default Position: Until government issues restrictions, cross-border transfers are generally permitted (subject to consent and other
obligations).

Rule 13(4) - SDF Data Localization: SDFs must ensure that certain personal data categories (as notified by government) are
processed only in India with restrictions on cross-border flow.

What We're Waiting For

As of December 2025, the Central Government has NOT YET NOTIFIED:

Which countries/territories are restricted for data transfers


Which personal data categories must be localized for SDFs
Criteria for "safe" vs. "unsafe" countries

Until notifications are issued, organizations should:

Continue existing cross-border transfers (with valid consent)


Monitor MeitY website for notifications
Prepare contingency plans for potential restrictions
Document all cross-border data flows

Cross-Border Transfer Scenarios

Scenario 1: Cloud Storage

Indian startup uses AWS servers in Singapore for customer data storage.

Current Status: Permitted (no restrictions notified yet)


Requirements: Valid consent, security safeguards, data processing agreement with AWS
Future Risk: If government restricts transfers to Singapore, must migrate to Indian servers

Scenario 2: SDF Healthcare Platform

Major health-tech platform (SDF) processes patient data.

Current Status: Can use global cloud providers


Likely Future: If "health data" is notified under Rule 13(4), must localize in India
Preparation: Architect systems to enable rapid localization if needed

Scenario 3: Multinational HR System

Global company with Indian employees uses centralized HR system in USA.

Current Status: Permitted with employee consent


Compliance: Data processing agreement, security measures, employee informed consent

Comparison: DPDPA vs. GDPR on Cross-Border Transfers

Aspect DPDPA (India) GDPR (EU)

Default Permitted until restricted Restricted unless adequate safeguards


Mechanism Government notification (blacklist) Adequacy decisions, SCCs, BCRs (whitelist)

Localization Possible for SDFs (Rule 13(4)) No mandatory localization

Current Status No restrictions notified yet 100+ adequacy decisions in place

Key Takeaways - Section 4

Section 16: Government can restrict transfers to specific countries


No restrictions notified yet - transfers currently permitted (with consent)
SDFs may face data localization for certain sensitive categories (Rule 13(4))
Organizations should map and document all cross-border data flows
Monitor MeitY notifications for updates
DPDPA uses "restriction" model vs. GDPR's "adequacy" model

↑ Back to Top

5. Record-Keeping & Audit Obligations

Effective compliance requires meticulous documentation. DPDPA imposes record-keeping obligations to ensure accountability and enable
audits.

Record-Keeping Requirements
Essential Records Every Data Fiduciary Must Maintain

1. Consent Logs:
When consent was obtained
How consent was obtained (method)
What consent was for (purpose)
Consent withdrawal records
2. Processing Records:
Data inventory (what personal data is held)
Processing activities log
Purpose and legal basis for each processing activity
Data retention periods
3. Data Sharing Records:
List of third parties with whom data is shared
Data processing agreements with processors
Cross-border transfer documentation
4. Data Principal Requests:
Access requests and responses
Correction/erasure requests and actions taken
Grievances filed and resolutions
5. Breach Register:
Details of all data breaches (even minor ones)
Actions taken to remediate
Notifications sent (to Board and Data Principals)
6. Security Measures:
Documentation of security safeguards implemented
Vulnerability assessment reports
Employee training records

Independent Data Audits (SDFs Only)

Data Audit Requirements (Section 10(2)(b) & Rule 13)


Who Must Conduct: All Significant Data Fiduciaries

Frequency: At least once every 12 months

Auditor: Must be independent (external auditor, not internal team)

Scope: Evaluate compliance with ALL DPDPA provisions and DPDP Rules

Reporting: Submit audit report with significant observations to Data Protection Board

Audit Checklist for SDFs

Pre-Audit Preparation:

Appoint independent auditor (external firm)

Define audit scope and timeline

Gather all compliance documentation

Prepare data flow maps and inventories

During Audit:

Review consent mechanisms and logs

Test security safeguards (technical + organizational)

Verify Data Principal rights exercise processes

Assess DPIA quality and implementation

Review third-party processor agreements

Check compliance with children's data protections

Evaluate breach response procedures

Post-Audit:
Receive audit report with findings

Address identified gaps

Submit significant observations to Board

Implement remediation measures

Plan next annual audit

Best Practices: Building an Audit-Ready Organization

1. Maintain Real-Time Records: Don't scramble before audit; maintain records continuously
2. Use Technology: Implement consent management platforms, data mapping tools
3. Assign Ownership: Clear responsibility for each compliance area (e.g., DPO owns DPIA, CISO owns security)
4. Regular Internal Audits: Don't wait for annual external audit; conduct quarterly internal reviews
5. Training: Ensure all employees understand their data protection responsibilities
6. Third-Party Management: Audit processors and vendors periodically
7. Documentation Culture: "If it's not documented, it didn't happen"

Key Takeaways - Section 5

All Data Fiduciaries must maintain comprehensive records (consent, processing, sharing, breaches)
SDFs must conduct independent data audits annually
Audit reports with significant findings submitted to Data Protection Board
Records enable accountability and facilitate compliance verification
Best practice: Real-time documentation, not pre-audit scramble
Technology tools (consent management, data mapping) are essential at scale
↑ Back to Top

Recommended Reading & Resources

Primary Legislation:
DPDPA 2023 - Section 10 (SDF), Section 16 (Cross-border)

DPDP Rules:
Rule 13: SDF Additional Obligations (DPIA, Audit, DPO)

Government Resources:
MeitY - Monitor for SDF notifications and cross-border restrictions

Self-Assessment Quiz

Test your understanding of Module 3 concepts:

1. What are the 6 factors for designating a Significant Data Fiduciary?

Show Answer

2. What is a DPIA and how often must SDFs conduct it?

Show Answer

3. What are the key requirements for a Data Protection Officer?

Show Answer

4. Can personal data currently be transferred outside India freely?

Show Answer

5. What records must all Data Fiduciaries maintain?


Show Answer

← Previous: Module 2 Back to Course Home Next: Module 4 - Enforcement →

Completed Module 3? Only one more module to go!


Continue to Module 4 to learn about Enforcement & Penalties
DPDPA Certificate Course - Version 1.1

Course Modules Resources Legal Feedback

Help us improve!
Module 1: Foundations DPDPA Sections Privacy Policy
Module 2: Rights & Obligations DPDP Rules 2025 Cookie Policy Send Feedback
Module 3: Compliance & Governance Blog Disclaimer
Email: info@[Link]
Module 4: Enforcement & Penalties Case Laws
Copyright © 2024-2025
Module 5: DPDPA Skills Templates & Policies
[Link]
Module 6: AI & DPDPA
Final Exam

DPDPA Certificate Course Version 1.1 | Last Updated: December 2024


Created by Dr. Prashant Mali | Authentic Source of DPDPA Knowledge
All content is protected by copyright. Unauthorized copying, distribution, or reproduction is strictly prohibited and can be prosecuted under section 43(b) read with Section 66 of The IT Act,2000

You might also like