Rights and duties
Do I need to appoint a Data Protection Officer?
- Short answer
- Only if you are notified as a Significant Data Fiduciary. A DPO based in India, answerable to the board, is an SDF obligation. Every other Data Fiduciary must still publish a contact point for questions about processing, which is a lighter duty.
The distinction matters because appointing someone and calling them a DPO implies a statutory role you may not hold, with obligations attached that you may not have considered.
What every Data Fiduciary needs is a published means of contact for data protection questions and grievances. A named person and a working email address satisfies that.
If you are notified as an SDF, the requirements step up considerably: a DPO in India responsible to the board, an annual Data Protection Impact Assessment, an independent audit, and algorithmic due diligence.
Where this comes from
- Section 8(9) and Section 10, DPDP Act 2023
- Rule 13, DPDP Rules 2025
The mistake people make
Advertising a Data Protection Officer in a privacy notice when the organisation is not an SDF and the role carries no statutory backing.