DPDPA requires Significant Data Fiduciaries to appoint a DPO based in India — but even organisations not yet classified as SDFs should understand the independence standards and operational mandate the role requires.
Does Your Organisation Need a DPO Under DPDPA?
The Digital Personal Data Protection Act 2023 does not require every Data Fiduciary to appoint a Data Protection Officer. The DPO obligation applies specifically to Significant Data Fiduciaries — organisations notified as such by the central government under Section 10 of the Act.
This is different from GDPR, where the DPO obligation applies to all public authorities and to private organisations conducting high-risk or large-scale processing — a category that captures a significant proportion of large enterprises. Under DPDPA, until the government notifies your organisation as an SDF, you are not legally required to have a DPO.
But "not legally required" is not the same as "not advisable." Any organisation that:
- Processes personal data at significant scale
- Handles sensitive personal data (financial, health, biometric)
- Operates in multiple regulated sectors
- Has a reasonable expectation of SDF classification
...should be building DPO-equivalent governance capacity now, because standing up that function after SDF notification — with the clock ticking on DPO appointment — is significantly harder than building it proactively.
The SDF Trigger: When DPO Appointment Becomes Mandatory
Section 10(2)(b) of DPDPA requires Significant Data Fiduciaries to appoint a Data Protection Officer. The DPO must be:
- Based in India — not a DPO sitting in a European headquarters or a shared regional role; a person physically located and operationally based in India
- Responsible to the Board of Directors or equivalent governing body — not reporting to the CTO, CEO, or General Counsel, but to the Board directly
- The point of contact for the Data Protection Board for all DPDPA-related matters
The India-based requirement is harder than it sounds for multinational organisations. If your GDPR DPO is in London or Singapore and also carries the DPDPA DPO designation, you have a non-compliant arrangement once SDF notification is received. You need either a dedicated India-based DPO or a senior data protection professional in India with formal DPO designation.
The timeline for SDF compliance following notification is not specified in the Act itself but is expected to be set in the SDF-specific directions issued at the time of notification. Organisations should plan for a 6–12 month implementation window but not rely on it.
DPO Independence: What DPDPA Requires vs What Most Companies Do
The independence requirement for the DPDPA DPO is more stringent in structure than what most organisations currently have. The DPO must report to the Board of Directors — not to a business unit head, not to Legal, not to the CISO, not even to the CEO.
Why this matters: a DPO who reports to the business cannot be truly independent. If the DPO's assessment is that a proposed data processing activity violates DPDPA, but they report to the executive sponsor of that activity, the structural conflict undermines the independence the role is supposed to provide. DPDPA's Board-reporting requirement is designed to eliminate this conflict.
In practice, most organisations currently position data protection as a Legal or Compliance function that reports to the GC or CLO. For SDF compliance, this structure needs to change — or at minimum, the DPO needs a formal reporting line to the Board with documented access rights that override the operational reporting line.
The DPO also cannot hold a position that conflicts with the data protection function. A DPO who simultaneously holds a business development role that involves selling data products, or an IT role that involves implementing the very processing activities they're supposed to oversee, has a structural conflict that compromises independence.
DPO vs CPO vs Compliance Head: The Structural Difference
Three roles often get conflated in Indian enterprises: the Data Protection Officer, the Chief Privacy Officer, and the Compliance Head. Under DPDPA, these are distinct in both legal status and operational mandate.
Data Protection Officer (DPO): A legally designated role under DPDPA (for SDFs), with specific obligations to the Data Protection Board, independence requirements, and Board-level reporting. A specific named individual must hold this designation and be registered with the Board.
Chief Privacy Officer (CPO): A business role, not a legal designation under DPDPA. The CPO owns the privacy programme, sets strategy, and manages the compliance function. The CPO may or may not be the same person as the DPO, but if they are the same person, that person's DPO obligations take precedence over any conflicting business directives.
Compliance Head: Typically owns regulatory compliance across multiple domains — not just data protection but also anti-money laundering, financial regulations, labour law. Under DPDPA, a general compliance head cannot fulfil the DPO function without specific data protection expertise and the structural independence the DPO role requires.
DPO Responsibilities Under DPDPA: The Operational Mandate
The DPDPA DPO's responsibilities, as implied by the Act and elaborated in the Rules, include:
- Point of contact for the Data Protection Board: All formal communications from the Board to the organisation should route through the DPO. This includes inquiry notices, penalty proceedings, and compliance directions.
- Oversight of the DPDPA compliance programme: The DPO must ensure the organisation has functional consent management, rights fulfilment, breach notification, and processor accountability systems.
- Data Protection Impact Assessment oversight: For SDFs, periodic DPIAs are mandatory. The DPO oversees the DPIA process and is responsible for the quality and integrity of the assessments.
- Training and awareness: The DPO is responsible for ensuring that employees who handle personal data understand their obligations under DPDPA.
- Grievance escalation: The DPO is the senior escalation point for data protection grievances that the operational team cannot resolve within the 30-day window.
Building a DPDPA-Ready Data Governance Function
Whether or not you are currently classified as an SDF, building a data governance function that is DPO-ready has tangible benefits: it demonstrates to the Data Protection Board that you take compliance seriously, it reduces the risk of individual grievances escalating to Board proceedings, and it positions you to absorb SDF classification without a scramble.
A DPO-ready governance function has four components: a named data protection lead with documented authority and independence; a functional compliance infrastructure (consent management, rights fulfilment, breach response); an up-to-date records of processing activities; and a direct Board reporting line for data protection matters.
Consentica by OpenBlockAI provides the compliance infrastructure layer — the consent management, rights fulfilment workflows, and audit trails that the DPO needs to demonstrate compliance to the Board and to manage their own oversight responsibilities. A DPO operating with a compliant consent infrastructure under them can focus on governance and strategy rather than spending their time on data archaeology and manual rights request handling.
