DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

‹ All questions

Rights and duties

Do I need to appoint a Data Protection Officer?

Short answer
Only if you are notified as a Significant Data Fiduciary. A DPO based in India, answerable to the board, is an SDF obligation. Every other Data Fiduciary must still publish a contact point for questions about processing, which is a lighter duty.

The distinction matters because appointing someone and calling them a DPO implies a statutory role you may not hold, with obligations attached that you may not have considered.

What every Data Fiduciary needs is a published means of contact for data protection questions and grievances. A named person and a working email address satisfies that.

If you are notified as an SDF, the requirements step up considerably: a DPO in India responsible to the board, an annual Data Protection Impact Assessment, an independent audit, and algorithmic due diligence.

Where this comes from

The mistake people make

Advertising a Data Protection Officer in a privacy notice when the organisation is not an SDF and the role carries no statutory backing.

Related