DPDP Act 2023 · Glossary

What Is a Data Protection Officer (DPO) in India?

A plain-English, India-native definition — what a DPO is under the Digital Personal Data Protection Act, 2023, when one is actually required, and how the role differs from a CISO.

Last reviewed: August 2026 · Based on the DPDP Act 2023 and the DPDP Rules 2025.

The short answer

Definition

A Data Protection Officer (DPO) is an individual appointed to lead or coordinate an organisation’s personal-data protection governance. Under India’s Digital Personal Data Protection (DPDP) Act, 2023, the term has a specific legal meaning: a Significant Data Fiduciary must appoint a DPO who is based in India, represents the Significant Data Fiduciary, is responsible to its Board of Directors or similar governing body, and acts as the point of contact for its grievance-redressal mechanism.

Source: DPDP Act, 2023 (MeitY), Sections 2(l), 8(9) and 10.

Not every Data Fiduciary needs a DPO. The statutory duty to appoint one applies only to a Significant Data Fiduciary that the Central Government notifies — not to every business that handles personal data.

What it means

What a DPO actually is

In everyday use, a DPO — Data Protection Officer — is the person who leads or coordinates how an organisation governs personal data: translating privacy obligations into working controls, acting as the point of contact for people raising privacy concerns, and escalating material privacy risk to leadership before it becomes a problem.

Under the DPDP Act, though, the term has a narrower, specific meaning — it is the individual a Significant Data Fiduciary must appoint under Section 10 (more on that below). Much of what people describe as “the DPO role” — impact assessments, audits, training, retention engineering, AI review — is sound operating practice that organisations layer on top, rather than a word-for-word statutory duty. This page keeps the two apart on purpose.

Do you need one?

When is a DPO required in India?

Not every company needs a DPO. The statutory duty attaches only to a Significant Data Fiduciary (SDF) under Section 10. The Act sets no numerical threshold; instead it lets the Central Government notify a Data Fiduciary — or a class of them — as an SDF after weighing the factors in Section 10(1), including the volume and sensitivity of personal data, the risk to the rights of Data Principals, and risks to the sovereignty and integrity of India, electoral democracy, the security of the State and public order. As of August 2026, no organisation should assume it is — or isn’t — an SDF without checking the current MeitY / Gazette notifications.

Every other Data Fiduciary still has to provide a working grievance-redressal mechanism and publish the contact details of a DPO (if it has one) or of a person able to answer questions about its processing. So even where a formal DPO isn’t mandatory, a named privacy contact is.

Timing. The SDF and DPO obligations in Section 10 come into force on 13 May 2027 — 18 months after the DPDP Rules, 2025 were notified on 13 November 2025. (If a later commencement notification changes this, we update the page.) That is why the live conversation is “build the operating model now, before designation and full obligations take effect,” not “wait for the deadline.”

Source: DPDP Act, 2023, Sections 8 and 10; DPDP Rules, 2025 (commencement).

What they do

What does a DPO do?

It helps to separate what the law expressly requires from what a DPO does in practice.

Statutory (for an SDF)

The express requirements

Represent the Significant Data Fiduciary, be based in India, be the point of contact for the grievance-redressal mechanism, and be responsible to the Board. Separately, SDFs must appoint an independent data auditor and carry out periodic Data Protection Impact Assessments and audits.

Operating practice

What the role usually covers

Data mapping, consent and notice design, data-principal rights handling, breach readiness, vendor and processor oversight, DPIAs, training, product and AI review, and Board-level reporting — tailored to the organisation’s processing and risk.

Not the DPO’s job alone

Shared with others

Security controls sit with the CISO; contracts and filings with legal. The DPO governs whether personal-data use is appropriate and lawful, and coordinates across teams — it does not absorb every adjacent function.

Source: DPDP Act, 2023, Section 10(2).

The four requirements

DPO requirements under the DPDP Act

For a Significant Data Fiduciary, Section 10(2)(a) sets four attributes for the DPO.

1

Based in India

The DPO must be an individual located in India — not a purely offshore or global appointment.

2

Represents the SDF

The DPO acts on behalf of the Significant Data Fiduciary on data-protection matters.

3

Grievance-redressal contact

The DPO is the point of contact for the grievance-redressal mechanism for Data Principals.

4

Responsible to the Board

The DPO is responsible to the Board of Directors or a similar governing body — not merely an IT line.

Source: DPDP Act, 2023, Section 10(2)(a).

Role boundaries

DPO vs CISO vs legal/compliance

Practical role distinction — the DPDP Act defines the DPO role, but not the CISO or legal/compliance roles
RoleCore question it answersPrimary focus
DPOShould we collect, use, share, retain or automate decisions with this personal data — and can we govern and explain it?Lawful, accountable personal-data processing and data-principal rights
CISOAre our systems and data protected from unauthorised access, loss and attack?The security programme and technical defence across the whole organisation
Legal / ComplianceDo our contracts, disclosures and filings meet the applicable law?Contracts, regulatory filings and dispute risk

This is a practical distinction, not a statutory one: the DPDP Act establishes the DPO role but does not define a CISO. The roles overlap on breach readiness, vendor risk, access controls and audit evidence — but neither substitutes for the others.

Ahead of the mandate

Who tends to appoint one early?

This is a governance decision, not legal advice — but some profiles have a stronger case for building a privacy-lead function before designation.

Consumer scale

Platforms, e-commerce, telecom

Consent notices, rights requests, retention, children’s data and ad-tech profiling at volume.

BFSI

Banks, NBFCs, insurers, fintech

Reconciling DPDP with RBI, KYC/AML and mandated retention and data-sharing.

Health

Healthcare & healthtech

Sensitive medical data, long retention, partner labs and hospitals, high-stakes trust.

SaaS / GCC

SaaS, IT services, GCCs

Fiduciary-vs-processor questions, client contract clauses, cross-border transfers and audits.

AI

AI & data-rich firms

Training data, automated decisions, model vendors and DPIA evidence before launch.

Early-stage

Startups & MSMEs

Often a part-time or shared privacy lead first — a dedicated role formalised as scale and scrutiny grow.

Getting started

How to appoint a DPO

Appointing a DPO is less about a job title and more about giving one accountable person real scope and authority. A workable sequence:

  • Define the mandate — scope, authority, budget and a reporting line to the Board.
  • Map your data first — a personal-data inventory and data-flow map (an industry practice often called a RoPA), so the DPO governs reality, not assumptions.
  • Choose the model — dedicated, shared, or outsourced/fractional, based on data footprint and jurisdictions.
  • Set the escalation path and a stakeholder map across legal, security, product, HR and procurement.
  • Build the evidence — data maps, consent and notice flows, DPIAs, vendor contracts, deletion evidence, a breach playbook and Board reporting.
Answers

Data Protection Officer FAQs

What is a Data Protection Officer in India?

A Data Protection Officer (DPO) is an individual appointed to lead or coordinate an organisation’s data-protection governance. Under India’s DPDP Act 2023, a Significant Data Fiduciary must appoint a DPO who is based in India, represents the SDF, is responsible to its Board of Directors or similar governing body, and is the point of contact for its grievance-redressal mechanism.

Is a DPO mandatory under the DPDP Act?

Not for every organisation. Appointing a DPO is a statutory duty only for a Significant Data Fiduciary (SDF) — a Data Fiduciary, or class of them, that the Central Government notifies. Other Data Fiduciaries are not obliged to appoint a DPO, though they must still run a grievance-redressal mechanism and publish a contact for questions about their processing.

Which companies need to appoint a DPO in India?

Only those notified as Significant Data Fiduciaries. The Act sets no numerical threshold; the Central Government makes the designation under Section 10(1) after weighing factors including the volume and sensitivity of personal data and the risk to Data Principals’ rights. There is no fixed list — so check the official notifications rather than assuming.

Who can be a Data Protection Officer?

The DPDP Act requires an SDF’s DPO to be an individual based in India who represents the organisation and is responsible to its Board. The Act does not prescribe a specific degree, certification or number of years of experience, so the choice is a governance decision based on the role’s authority and the organisation’s risk profile.

Must a DPO be based in India?

Yes, for a Significant Data Fiduciary. The DPDP Act 2023 requires the SDF’s DPO to be based in India. This is a key difference from the GDPR, which allows a DPO to sit anywhere, so a generic global DPO arrangement may not satisfy the Indian requirement on its own.

What are the responsibilities of a DPO?

Statutorily, an SDF’s DPO represents the organisation, is based in India, is responsible to the Board, and is the point of contact for grievance redressal. In practice the role usually extends to data mapping, consent and notice design, data-principal rights, DPIAs, breach readiness, vendor oversight, training and Board reporting — operating responsibilities that go beyond the express statutory text.

Can a CISO also be a DPO?

The DPDP Act does not expressly prohibit combining the roles or mandate their separation, so it is possible — but the two are distinct and can conflict. A CISO owns security and technical defence; a DPO governs whether personal data is used lawfully. A combined role works only where the DPO keeps genuine independence, authority, bandwidth and escalation access; combining them is not automatically compliant.

What is the difference between a DPO and a CISO?

A DPO asks whether the organisation should collect, use, share or automate decisions with personal data — and whether it can govern and explain that. A CISO asks whether systems and data are protected from unauthorised access, loss and attack. They overlap on breach readiness and vendor risk, but neither role substitutes for the other.

What is the difference between a DPO and a privacy officer?

In India the terms are often used interchangeably. “DPO” is the specific role the DPDP Act requires for Significant Data Fiduciaries, with defined statutory attributes. “Privacy officer” is a broader, informal title organisations may use for whoever leads privacy — which may or may not meet the Act’s SDF requirements.

Does a startup need a DPO in India?

Usually not as a separate statutory role, unless it is notified as a Significant Data Fiduciary. Many startups place the privacy remit with a legal, security or compliance lead first, or use a shared or outsourced (fractional) DPO, and formalise a standalone role as data volume, risk and customer scrutiny grow.

Does a data processor need a DPO?

The Act’s DPO obligation is tied to being a designated Significant Data Fiduciary, not to the label “processor.” Whether an entity is a Data Fiduciary turns on whether it determines the purpose and means of processing — alone or with others. A pure processor’s duties flow mainly from its contract with the Data Fiduciary.

Who should a DPO report to?

For a Significant Data Fiduciary, the DPO must be responsible to the Board of Directors or a similar governing body — not merely to an IT or security reporting line. That independence, together with clear authority and budget, is what lets a DPO challenge risky data use before it happens rather than administer policies after the fact.

What is a Significant Data Fiduciary?

A Significant Data Fiduciary (SDF) is a Data Fiduciary, or class of them, that the Central Government notifies as significant under Section 10(1) of the DPDP Act, weighing factors such as the volume and sensitivity of personal data and the risk to Data Principals’ rights. SDFs carry extra duties: a DPO, an independent data auditor, and periodic DPIAs and audits.

How does a DPO handle data-principal grievances?

The DPO is the published point of contact for the grievance-redressal mechanism. A working process logs each request, verifies identity proportionately, routes it to the right systems, and answers within the applicable timelines — covering access, correction, erasure, nomination and grievances — with the reasoning recorded so decisions are defensible.

Does the DPDP Act require a DPO to conduct a DPIA?

Data Protection Impact Assessments and independent data audits are duties the Act places on Significant Data Fiduciaries (Section 10(2)), and the Rules require them at least once every twelve months. The Act frames these as SDF obligations rather than personal duties of the DPO, but in practice the DPO usually owns or coordinates the DPIA programme.

Find your footing

See which DPDP obligations actually apply to you

A short readiness assessment maps the systems, vendors and data flows that create your privacy exposure — and shows what to build first.

Methodology

Sources & how this page is maintained

This glossary entry is based on Government of India primary sources and is reviewed when new notifications are issued:

This page is decision-support, not legal advice. It separates statutory requirements from recommended operating practice, and does not assert which organisations are Significant Data Fiduciaries — that designation is made by the Central Government.

Follow DPOIndia in Google SearchAdd as a preferred source on Google