Meeting Significant Data Fiduciary Obligations
What the additional duties are, and what governance they call for

How a Company Becomes a Significant Data Fiduciary
Designation comes from the government
A company does not adopt the status of Significant Data Fiduciary for itself. The government notifies a company or a class of companies as significant, and the notification is what brings the additional duties into effect.
The Digital Personal Data Protection Act 2023 sets out the factors that inform that decision. The volume and sensitivity of personal data being processed, the risk to the rights of the individuals concerned, the potential effect on the sovereignty and integrity of India, the risk to electoral democracy, the security of the State, and the maintenance of public order.
Reading that list tells a company something useful about its own likelihood. A payment platform holding financial records for millions of people sits in different territory from a regional manufacturer holding employee records. A social platform whose recommendation systems shape what people see sits in different territory again.
No company should assume it will never be notified, and none should treat notification as imminent without a reason. What the list supports is a judgement, and a company near any of those factors benefits from knowing what the additional duties involve before a notification arrives.
Why preparation ahead of designation is sensible
The additional duties go beyond adjusting existing practice. They introduce a named officer, an independent audit, an annual assessment and a review of automated systems, and each of those takes time to establish properly.
A company notified with a compliance window ahead of it can meet the duties. A company that treats the notification as the moment to begin faces recruitment, procurement of an auditor, and a first assessment cycle running simultaneously.
A further argument for preparing early has nothing to do with designation at all. Most of the additional duties are good practice for any company handling substantial volumes of personal data, and a company that has an annual assessment and a named privacy officer stands in a stronger position whether or not the notification ever comes.
The Data Protection Officer
What the Act requires of the role
A Significant Data Fiduciary has to appoint a Data Protection Officer who is based in India, who is an individual responsible to the board or the equivalent governing body, and who acts as the point of contact for the grievance redressal mechanism.
Three parts of that requirement deserve attention. The officer has to be in India, so the role cannot sit with a group privacy function abroad. The officer is answerable to the board, which places the role above the operational layer and gives it standing. And the officer is the contact point for grievances, so the role carries a public face that individuals can reach.
The reporting line is the part companies find hardest to arrange, because it cuts across normal structure. A privacy officer reporting to a technology director sits inside the function whose work they may need to challenge. The Act intends the role to have independence, and a reporting line to the board is how that independence is established.
TrustOS supports the role by giving it the view of the programme the Act implies. Open obligations across the company, where ownership is missing, which reviews have slipped, where exceptions are accumulating, and how requests and grievances are being handled. An officer answerable to the board needs a position they can state to it.
The grievance route and its records
Because the officer is the contact point for grievances, the grievance mechanism becomes part of the role instead of something operations handles separately. An individual who is dissatisfied has to exhaust that mechanism before approaching the Data Protection Board, so its quality determines whether a complaint escalates.
TrustOS records each grievance with its intake, assignment, investigation, response and closure, and the officer can see the whole set. That view matters for a reason beyond individual cases, since a pattern in grievances usually points at a process that needs changing and not at a series of unrelated complaints.
The record also supports the officer when a matter does reach the Board. A company able to show what the individual asked, when, what was investigated and what was said in reply is answering from evidence.
The Annual Impact Assessment
An obligation and not a practice
For companies outside the significant category, a data protection impact assessment is a working tool applied where risk warrants it. For a Significant Data Fiduciary it becomes an annual obligation, undertaken alongside a periodic audit.
That change in status changes what the assessment has to be. A discretionary assessment can be scoped to the processing that concerns the company most. An annual obligation has to cover the processing the company actually carries out, so the operations set the scope and preference does not.
The assessment describes the processing, evaluates the risk to the individuals whose data is involved, considers the measures available to reduce that risk, and settles the controls the processing will operate under. Those controls then become requirements that the systems have to meet.
TrustOS holds the assessment against the processing activities it covers, and turns each resulting control into assigned work with an owner and a date. A finding that a data flow needs stronger protection reaches a technology owner. A finding that a retention period is too long changes the retention rule.
Why the annual cycle needs the inventory
An annual assessment covering the processing a company carries out depends on knowing what that processing is. A company without a purpose register and a data inventory has to build both before it can assess anything, and doing that inside the assessment cycle stretches the cycle well past its natural length.
Companies that already maintain those records find the annual assessment becomes a review of what has changed since the last one. New purposes, new processors, new data flows, changed volumes. That is a manageable annual exercise.
Companies without them find the assessment becomes a discovery project every year, because the previous year work was never captured in a form the next year could build on. TrustOS keeps the assessment connected to the records it was based on, so the following cycle starts from the current position.
The Independent Audit
What an independent auditor examines
A Significant Data Fiduciary has to appoint an independent data auditor to evaluate its compliance. Independent here means outside the company, and the appointment is a procurement exercise with its own timeline.
An auditor examines whether the controls the company describes actually operate. They will select a sample of rights requests and follow each one through. They will ask for evidence that retention rules run. They will test whether processor reviews happened on the dates claimed. They will look for decisions taken without recorded reasoning.
What they test is the gap between the described programme and the operating one, and companies that keep documentation separately from their operations usually have a gap they were unaware of. An auditor finds it quickly, because they ask for records and not descriptions.
A company running its obligations through TrustOS can respond to those requests from operating records. The article on evidence in this series covers what an audit package contains and how it is assembled.
Reporting significant observations
Where an audit produces significant observations, those have to be reported, and the reporting brings the audit into the governance of the company instead of leaving it as a document filed with the privacy team.
That obligation has a practical effect on how a company should treat findings. An observation reported to the board and left unremediated becomes visible in the next cycle, so the finding and the work it generates have to stay connected.
TrustOS holds audit findings with their remediation actions, owners and completion dates. A company reporting to its board can state what was found, what has been done, what remains open and when it will close. A report of that kind carries far more weight than one listing findings with no status against them.
Algorithmic Due Diligence and Transfers
Verifying that algorithmic systems are not likely to cause harm
A Significant Data Fiduciary has to observe due diligence to verify that any algorithmic software it deploys for hosting, display, uploading or sharing of personal data is not likely to pose a risk to the rights of data principals.
That duty reaches further than companies generally expect. Recommendation systems, ranking systems, automated decision systems, content moderation and personalisation all involve algorithmic processing of personal data, and each can affect the individuals concerned.
What due diligence means here is a documented review. What the system does with personal data, what outcomes it produces, what could go wrong for an individual, and what controls limit that. The review needs repeating when the system changes materially.
TrustOS holds those reviews as records attached to the systems concerned, with the controls they produced turned into assigned work. A company asked how it satisfies this duty can point at reviews with dates and owners.
Restrictions on specified transfers
The Act allows the government to restrict transfers of personal data by a Significant Data Fiduciary to a country or territory outside India. Where such a restriction applies, the company has to know where its data actually goes.
That knowledge comes from the data movement records described in the inventory article. A company that has mapped its outbound flows can answer a question about transfers directly. A company that has not will be investigating its own architecture under a deadline.
TrustOS records the destination of each flow alongside the processors involved, so a transfer restriction can be assessed against the actual position. Where a flow falls within a restriction, the platform creates the work to address it and holds the record of what was done.
Governance and Where to Begin
What ties the additional duties together
Read as a set, the additional duties describe a governance arrangement and not a list of tasks. An officer with standing and a reporting line to the board. An annual assessment covering actual processing. An independent examination of whether controls operate. Findings reported upward. Automated systems reviewed. Transfers known and controlled.
Running through all of them is an expectation that leadership knows the position and answers for it. A privacy programme that operates below board attention does not satisfy that, however competent the operations are.
TrustOS supports the arrangement by producing the position from the operating records. Board reporting stops being a quarterly assembly exercise and becomes a view, and that changes how often it can happen and how accurate it is.
Preparing without a notification
A company that considers designation plausible has a sensible order of preparation. Establish the inventory and the purpose register first, because the assessment and the transfer duties both depend on them. Name a privacy officer and settle their reporting line, even before the Act requires it. Run an impact assessment on the processing that carries the most risk, to learn what the exercise involves at a manageable scale.
Reviewing the algorithmic systems comes next, and companies frequently find it the most useful of the additional duties regardless of designation, since it surfaces questions nobody had asked about systems built for other reasons.
The audit is the piece to leave until the rest is in place, since an auditor examining an immature programme produces a long list of findings the company already knew about. Bringing the programme to a defensible state first makes the audit useful instead of merely uncomfortable.
Take the Next Step with TrustOS
TrustOS is a DPDPA compliance platform developed and operated by Code Colonies Private Limited. It gives privacy, legal, security, technology, operations and audit teams a single system for personal data records, purposes and notices, consent and withdrawal, requests and grievances from individuals, retention and erasure, breach response, processor oversight and compliance evidence. Every obligation is connected to a responsible owner, turned into assigned work, tracked through to completion, and left with the records that an audit or a regulatory response will call for.
The platform can be deployed inside infrastructure that you control, and the agreed scope can include source code handover, environment setup, security configuration, technical documentation, integration support and knowledge transfer. A scoped gap assessment establishes your current position, the responsible teams, the priority gaps, the technical dependencies and a practical order in which to implement.
To see the platform or to discuss your requirements, continue to the product overview or start a gap assessment. To learn more about our consulting and engineering work, visit codecolonies.com. To start a conversation, write to us at consulting@codecolonies.com.