India DPDP Act DPDP-SignificantDataFiduciary-SDF-Sec10-DPO-IndependentAuditor-DPIA-Algorithmic: DPDP Act Sections 10-11 + Significant Data Fiduciary (SDF) + Data Protection Officer + Independent Data Auditor + DPIA + Algorithmic Software Audit + Privacy by Design + Records of Processing Activities
Sections 10-11 of DPDP Act 2023 establish enhanced obligations on entities designated as Significant Data Fiduciaries (SDFs). Section 10 Significant Data Fiduciary: Central Government may notify Data Fiduciary or class of Data Fiduciaries as SDF having regard to such factors as may be relevant including (a) volume and sensitivity of personal data processed; (b) risk to rights of Data Principal; (c) potential impact on sovereignty + integrity of India; (d) risk to electoral democracy; (e) security of the State; (f) public order. SDF determination criteria operationalised through DPDP Rules 2025 quantitative thresholds. Enhanced SDF obligations: (a) appoint a Data Protection Officer (DPO) who shall be an individual responsible for representing the SDF + based in India + report directly to Board of Directors or similar governing body + be the point of contact for the grievance redressal mechanism + business contact info published; (b) appoint an independent Data Auditor to evaluate the compliance of the SDF with the provisions of the Act - independent + qualified + audit periodic per DPDP Rules 2025 cadence; (c) undertake periodic Data Protection Impact Assessment (DPIA) - process comprising a description of the rights of Data Principals and the purpose of processing of their personal data + assessment and management of the risk to the rights of Data Principals + such other matters regarding such process as may be prescribed; (d) undertake periodic audit; (e) other measures consistent with the provisions of the Act as may be prescribed. Section 11 Algorithmic Software Audit (per DPDP Rules 2025): for SDFs whose processing involves algorithmic decision-making or AI/ML systems + audit of algorithmic software for fairness + bias + discrimination + explainability + accuracy + impact on Data Principals. Privacy by Design and Default: built into business processes + system design + product development + data minimisation + purpose limitation + storage limitation + integrity + confidentiality. Records of Processing Activities (ROPA): comprehensive records of processing activities + categories + purpose + Data Principals + recipients + retention + TOMs + cross-border + DPIA outcomes + breach register. Coordinates with GDPR Arts 35 + 36 + 37 + 38 + 39 + ISO 27701 PIMS + Privacy Impact Assessment + India CERT-In + RBI Cyber Framework + ISMS 27001 alignment + AI Risk Management Frameworks (NIST AI RMF + ISO 42001) + EU AI Act + Algorithmic Accountability requirements. DPDP Sec 10-11 SDF + DPO + DPIA + Algorithmic Audit applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 158 controls across 64 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33