Last updated: April 29, 2026
Why this module exists. §10(2)(c) requires Significant Data Fiduciaries (SDFs) to conduct DPIAs. The Rules (when published) will likely extend DPIA expectations to high-risk processing by all Data Fiduciaries. Most Indian businesses have never done one. The methodology is more practical than the legal text suggests.
What a DPIA is
A structured assessment of a processing activity:
- What data do you process, why, how?
- Is the processing necessary and proportionate?
- What risks does it pose to data principals?
- What mitigations bring the risks to acceptable levels?
- What residual risk remains?
Output: a document. Reviewed periodically. Available to the regulator on request.
When DPIA is required
Currently mandatory for SDFs. Best-practice triggers for any Data Fiduciary:
- New product or service that processes personal data at scale
- Processing of children’s data (§9 — verifiable parental consent required)
- Processing of sensitive categories: health, biometric, financial, location, sexual orientation, caste, religion
- Automated decision-making with significant effect (loan approval, hiring)
- Large-scale monitoring (CCTV at scale, employee monitoring, public-area analytics)
- Use of AI / ML on personal data (model training, inference)
- Cross-border transfers to non-routine destinations
- New vendor / data processor handling sensitive data
The 10-section DPIA template
- Project description — what business activity, why, who’s the stakeholder.
- Data inventory — categories, volumes, sources, recipients.
- Lawful basis — consent, contract, legal obligation, legitimate use under §7.
- Data flow diagram — where data goes, including processors and cross-border.
- Necessity and proportionality — is this the minimum data needed? Is there a less-intrusive alternative?
- Risk identification — what could go wrong (re-identification, breach, discrimination, surveillance creep, lock-in).
- Risk assessment — likelihood × impact for each risk.
- Mitigation — controls that reduce risk.
- Residual risk — what remains after mitigation; sign-off by accountable executive.
- Review schedule — when DPIA will be revisited (annually or on material change).
The Significant Data Fiduciary designation
The Central Government can notify entities as SDFs based on:
- Volume and sensitivity of personal data processed
- Risk to electoral democracy / sovereignty
- Risk to national security / public order
- Other relevant factors
SDFs have additional obligations:
- Appoint a Data Protection Officer (DPO) based in India
- Conduct annual independent audit
- DPIA + periodic risk assessment
- Other measures as may be prescribed
As of 2026 mid, no SDF list has been notified. Likely candidates: large e-commerce, social media, banks, telecom, healthtech with population-scale data.
The risk-assessment matrix
| Risk | Likelihood (1-5) | Impact (1-5) | Score | Mitigation |
|---|---|---|---|---|
| Re-identification of pseudonymised data via link to other datasets | 3 | 4 | 12 | k-anonymity ≥ 5; differential privacy on aggregates |
| Breach of stored personal data via cloud misconfiguration | 2 | 5 | 10 | Encryption at rest; CSPM scanning; MFA on console |
| Vendor sub-processor compromise | 3 | 3 | 9 | DPA with notification; sub-processor list audit |
| Discrimination from automated decision (credit scoring) | 3 | 4 | 12 | Fairness testing pre-launch; human-in-loop for adverse decisions |
| Disproportionate surveillance via location collection | 4 | 3 | 12 | Reduce granularity; opt-in; on-device processing |
Score > 12 = explicit executive sign-off required. Score > 16 = redesign before proceeding.
Real-world case study
Hypothetical: Indian healthtech building an AI model that predicts disease risk from patient records.
DPIA findings:
- Processing: highly sensitive (health data per ABDM)
- Lawful basis: consent + legitimate use for healthcare (§7)
- Risks: model bias by demographic, re-identification of “anonymised” training data, third-party processor (cloud GPU vendor) gaining access
- Mitigations: differential privacy on training; on-device or India-region inference; specific consent UX with revocation; DPA with cloud GPU provider including audit right
- Residual risk: medium; quarterly review
- Sign-off: CTO + Chief Medical Officer + DPO
Defender’s checklist
- DPIA template documented and approved by legal + privacy team.
- DPIA triggered automatically as part of new-feature / new-vendor / major-change process.
- Reviewed annually for the same processing activity.
- Available on request to DPB during inspection.
- Linked to risk register — DPIA risks tracked in your enterprise risk system.
- DPO sign-off on every DPIA (if SDF; recommended for all).
- Public summary for high-stakes processing — increasingly an industry expectation.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.