Version 1.0 • CURRENT
DPDP Rules 2025 Significant Data Fiduciary & Rights
RULE 13

Additional obligations of Significant Data Fiduciary

Official Statutory Text MeitY Gazette Notified Section 40 Delegated Authority
Plain-Language Compliance Breakdown (Editorial Analysis)

What this means: Large companies (SDFs) have very strict compliance deadlines. They must conduct a massive Data Protection Impact Assessment and independent audit every 12 months, and submit the findings directly to the Board.

Crucially, they must ensure their "algorithmic software" (like AI recommendation engines) does not pose a risk to users' privacy rights.

Key Practical Takeaways for Compliance Teams

  • Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
  • Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 13.
  • Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.
← PREVIOUS RULE Rule 10: Verifiable consent for processing of personal data of child NEXT RULE → Rule 14: Rights of Data Principals
Statutory text reproduced under open access public domain principles. This reader is designed for educational and compliance decision support.