WikiFrameworksIndia's DPDPSDF - Data Protection Officer

SDF - Data Protection Officer

Updated: 2026-02-08

Plain English Translation

Under Section 10(2)(a) of the Act, organizations designated as a Significant Data Fiduciary (SDF) must legally appoint a Data Protection Officer based in India. This is not just a standard compliance role; the DPO appointment DPDP mandate requires this individual to report directly to the Board of Directors, ensuring high-level accountability. The role of DPO under DPDP Act is to represent the fiduciary, ensuring significant data fiduciary obligations are met, and acting as the primary point of contact for the grievance redressal mechanism.

Executive Takeaway

Significant Data Fiduciaries must appoint a senior, India-based officer directly accountable to the Board to oversee privacy strategy. Failure to appoint this specific role violates Section 10, attracting penalties up to INR 150 crore.

ImpactHigh
ComplexityHigh

Why This Matters

  • The DPO is the statutory face of the organization for both the Data Protection Board and Data Principals.
  • Direct reporting to the Board ensures that data privacy risks are treated as critical business risks, not just IT issues.

What “Good” Looks Like

  • A formal Board Resolution appointing the DPO with a clear charter of authority and reporting lines.
  • The DPO's contact information is prominently published on the website and app, serving as the accessible contact point for data protection board inquiries.

Only organizations notified by the Central Government as a 'Significant Data Fiduciary' (SDF) under Section 10(1) are legally required to appoint a Data Protection Officer.

The Act does not specify academic qualifications, but Section 10(2)(a) requires them to be an individual responsible to the Board, implying senior executive standing and expertise to represent the fiduciary.

Yes, Section 10(2)(a)(ii) explicitly mandates that the Data Protection Officer must be based in India.

Section 10(2)(a) states the SDF shall 'appoint' a DPO who is 'an individual'. While the Act doesn't explicitly ban outsourcing, the requirement to report to the Board and be based in India suggests an internal or closely integrated role is expected.

The DPO must be responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary, as per Section 10(2)(a)(iii).

For an SDF, the DPO *is* the point of contact for the grievance redressal mechanism (Section 10(2)(a)(iv)). Non-SDFs need only publish details of an authorized person to answer questions (Section 8(9)).

The Act does not prohibit this, but the DPO must report to the Board. Best practice suggests separating the roles to ensure the independent DPO requirement is met without conflict of interest between security execution and compliance oversight.

Failure to observe additional obligations of a Significant Data Fiduciary, including appointing a DPO, can attract a penalty extending to one hundred and fifty crore rupees under the Schedule.

DPDP Section 10(2)(a)

"The Significant Data Fiduciary shall— (a) appoint a Data Protection Officer who shall— (i) represent the Significant Data Fiduciary under the provisions of this Act; (ii) be based in India; (iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and (iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act;"

VersionDateAuthorDescription
1.0.02026-02-08WatchDog Security GRC Wiki TeamInitial publication from DPDP Workbook