SDF Determination

Know Your SDF Status Under DPDP Act Section 10

The government can designate organizations as Significant Data Fiduciaries (SDFs) based on scale, sensitivity, and risk. SDFs face heightened obligations, including mandatory DPO appointment, periodic DPIAs, and independent data audits. dcomply's SDF Determination Tool helps you assess your status before the government does.

Not SDF Standard obligations apply
Likely SDF. Monitor Prepare for designation
Significant Data Fiduciary Immediate compliance required
SDF Score: 75% High scale + sensitive data
The Problem

Most Organizations Don't Know Their SDF Risk

DPDP Act Section 10 designates SDFs with significantly heavier obligations, and penalties up to ₹150 Crore per violation for non-compliance

Most Organizations Don't Know Their SDF Risk

The DPDP Act doesn't provide a self-assessment tool. Organizations processing crores of records may already qualify as SDFs without realizing it, and face penalties for non-compliance with Section 10 obligations.

SDF Obligations Are Significantly Heavier

SDFs must appoint a DPO based in India, conduct periodic DPIAs, undergo independent data audits, and ensure algorithmic accountability. Missing these triggers penalties up to ₹150 Crore per violation.

Risk Factors Are Interconnected

SDF determination depends on multiple factors: data principal count (1 crore threshold), data sensitivity, national security risk, and market influence. Understanding which factors apply requires a structured assessment.

Capabilities

Structured SDF Assessment & Compliance Planning

12-Question Structured Assessment

Evaluate your SDF risk across 4 dimensions: Scale of Processing (user count, data principal threshold), Data Sensitivity (health, financial, children's data), National Security Risk, and Market Influence (dominant platform status).

Weighted Scoring Engine

Each question carries a weight based on regulatory significance. National security risk (40 pts) and public order risk (35 pts) automatically trigger SDF designation. Scale and sensitivity scores determine the overall SDF probability.

Three-Tier Determination

Results fall into three tiers: "Significant Data Fiduciary" (immediate compliance required), "Likely SDF. Monitor" (prepare for designation), or "Not an SDF" (standard Data Fiduciary obligations apply).

SDF Obligations Breakdown

If designated as an SDF, the tool outputs all 8 Section 10 obligations: DPO appointment, DPIA schedule, independent data audit, algorithmic accountability, processing restrictions, enhanced security, cross-border controls, and children's data policy.

Compliance Roadmap

Receive a prioritized action plan specific to your determination. SDF-designated organizations get a 90-day compliance roadmap covering DPO appointment, DPIA commissioning, and audit scheduling.

Annual Reassessment

SDF status can change as your organization scales. Run reassessments annually or when your user base crosses a significant threshold. Track determination history over time.

How It Works

Know Your SDF Status in 4 Steps

From a 10-minute assessment to a full compliance roadmap, dcomply gives you the clarity to act before the regulator does.

Complete the 12-question assessment

Answer questions about your data principal count, data types processed, national security exposure, and market position. Takes under 10 minutes.

Review AI-calculated score

The weighted scoring engine calculates your SDF score and applies instant-SDF triggers (national security risk, public order risk, or high scale + sensitive data combination).

Get your determination

Receive a clear determination: SDF, Likely SDF, or Not SDF, with the specific factors that drove the result and the confidence level.

Act on your obligations

If you're an SDF or likely SDF, download your personalized compliance roadmap with DPO appointment template, DPIA checklist, and audit preparation guide.

FAQ

Frequently Asked Questions

Under Section 10 of the DPDP Act, the Central Government designates SDFs based on: the volume and sensitivity of personal data processed, risk to data principals' rights, potential impact on national security or public order, and the organization's significance to the economy, democracy, or rule of law. Key thresholds include processing data of over 1 crore data principals, or processing highly sensitive data (health, biometric, financial) at scale.

SDFs must: (1) Appoint a Data Protection Officer (DPO) based in India, (2) Conduct periodic Data Protection Impact Assessments (DPIAs), (3) Undergo independent data protection audits, (4) Ensure algorithmic accountability and explainability, (5) Comply with additional processing restrictions imposed by the Central Government, and (6) Meet stricter cross-border transfer controls under Section 16.

Yes. SDF designation is based on your current scale of processing, data types, and risk profile, all of which evolve. An organization that doesn't qualify today may become an SDF as it scales its user base. dcomply recommends running the SDF assessment annually and immediately after any significant business change such as a new product line, acquisition, or expansion into sensitive data categories.

Assess Your SDF Status in 10 Minutes

Know your obligations before the regulator decides for you

View All Features