DPDPA 2023 — From Awareness to Compliance
Module 6 of 9 · 7 min read

Significant Data Fiduciaries, children's data and cross-border transfers

Extra duties for high-risk organisations, the under-18 rules, and where data may go.

Significant Data Fiduciaries (SDFs)

The Government may notify any Fiduciary or class as an SDF considering: volume and sensitivity of data, risk to Data Principals' rights, potential impact on sovereignty/integrity, electoral democracy, security of the State and public order. Expect large consumer platforms, telecom, BFSI and health players to be notified early.

SDF duties on top of everything else:

  • Appoint a Data Protection Officer based in India, reporting to the board, who is the grievance point of contact.
  • Appoint an independent data auditor and undergo a data protection audit (the Rules require this annually, with a report to the Board).
  • Conduct a Data Protection Impact Assessment annually.
  • Verify that the algorithmic software used for processing does not pose a risk to Data Principals' rights.
  • Comply with any data-localisation condition the Government notifies for specified data/traffic — SDFs may be told certain personal data must not leave India.

Penalty for SDF-specific failures: up to ₹150 crore.

Children (under 18) and persons with disabilities

  • Obtain verifiable consent of the parent/lawful guardian before processing a child's data. The Rules describe the verification approaches (reliable identity/age details already held, virtual tokens from a Digital Locker, etc.) and require due diligence that the consenting adult is an adult.
  • Prohibited: processing likely to cause detrimental effect on a child's well-being; tracking or behavioural monitoring of children; targeted advertising directed at children.
  • Limited exemptions exist (e.g., healthcare providers, educational institutions, for specified purposes) and the Government may exempt classes of Fiduciaries who process children's data in a verifiably safe manner.
  • Penalty: up to ₹200 crore.

For HR teams: interns and apprentices under 18 are children under this Act.

Cross-border transfers

  • Transfers outside India are permitted by default, except to countries/territories the Central Government restricts by notification (a "blacklist", not a whitelist).
  • Sectoral rules that are stricter still apply — e.g., RBI's payment-data localisation continues.
  • SDFs may face localisation conditions for notified categories.
  • Contractually, you remain responsible: Processors abroad must meet the same safeguards, and your notice should say that data may be processed outside India.

Government and exemptions

The Act allows the Government to exempt its instrumentalities on specified grounds, and exempts processing for research/statistical purposes (not directed at individual decisions), legal claims, court functions, prevention/investigation of offences, and certain corporate restructurings. It can also exempt startups and other classes from specific provisions (notice, some rights, SDF duties) for a period.