From the blog · 5 October 2026

Not every company
owes a DPIA.

Privacy consultants hand out Data Protection Impact Assessments like a universal prescription. Under India's DPDP Act, that advice is sometimes just wrong — and knowing which case you're in matters more than filling in the template.

A boundary drawn around one part of the field, with reviewed points lit inside it and a sign-off mark beside it.
A boundary drawn around one part of the field — not the whole field assumed reviewed.

01 · What the Act actually says

The DPIA duty sits in one specific place in the DPDP Act: Section 10(2)(c)(i), worked out further by Rule 13(1)–(3). It doesn't apply to every organisation that processes personal data. It applies to Significant Data Fiduciaries — a category the government notifies, based on factors like the volume and sensitivity of data handled and the risk to individuals, to democracy, or to electoral integrity.

Being an SDF isn't a status you decide about yourself with a self-assessment quiz. It's a government notification. Nobody is an SDF by inference.

02 · Where the confusion comes from

Most DPDP checklists treat a DPIA the way GDPR treats one — close to universal, required whenever processing carries meaningful risk. That isn't how this Act is built. If you haven't been notified as an SDF, Rule 13's specific DPIA duty doesn't bind you yet.

What the Act does ask of every data fiduciary, SDF or not, is the general diligence in Section 8(4) — reasonable security safeguards and sound practice appropriate to the processing. A DPIA is a good way to demonstrate that discipline. It just isn't the Act's word for "any company handling personal data."

03 · What an SDF specifically owes

For a notified SDF, Rule 13 is concrete: appoint a Data Protection Officer based in India, engage an independent data auditor, and carry out a DPIA and an audit at least once every twelve months. Not once, filed, and forgotten — a standing obligation with a clock attached to it.

04 · What good practice looks like either way

Whether or not you're an SDF, a DPIA that's actually useful isn't a template filled in by whoever drew the short straw. It names the specific data flows in scope, names the third parties actually touching the data, and gets reviewed by someone other than the person who wrote it — not as a formality, but because a second, different reader is what catches the gap the author couldn't see in their own work.

That's the version of a DPIA we built Consent Tree to produce: a living record of scope and sign-off, not a PDF that was technically completed once and never opened again.

What the Act actually says — Rule 13's DPIA + audit cycle runs at least once every 12 months — it's a standing obligation, not a one-time filing.