Your credit model works. Approval rates are up, delinquency is down, the risk team is happy, and the board deck shows a clean AUC. Nobody has any complaints.
Then someone asks a question nobody in the room can answer: can you demonstrate that this model does not pose a risk to the rights of the people it decides on?
Across Episodes 1 to 4 we built the base: the law and how it collides with RBI and SEBI; continuous governance; the retention register; the four-clock breach runbook. This episode is about the tier above , and the single most under-prepared obligation in Indian financial services.
What an SDF is, and the first mistake everyone makes
Under Section 10(1), the Central Government may notify a Data Fiduciary, or an entire class of Data Fiduciaries, as a Significant Data Fiduciary, based on factors including:
Any one factor can be enough. They are not cumulative.
The first mistake: assuming you designate yourself. You do not. SDF status is conferred only by a Central Government notification under Section 10(1). At the time of writing, no SDF list or class has been notified. That is not a reprieve. It means the designation, when it lands, lands on your existing systems.
Financial institutions process exactly the combination the section is written around , very high volume, high sensitivity, and direct impact on individuals' rights. The rational posture is to operate SDF-ready without waiting: the obligations take time to build, and most of it is converging on you anyway through RBI and SEBI.
The five obligations
Section 10(2) and Rule 13 impose five duties on an SDF, over and above everything in Episodes 1 to 4. Plus a conditional sixth: targeted localisation under Rule 13(4).
Appoint a Data Protection Officer based in India, responsible to the Board.
Appoint an independent data auditor to evaluate compliance with the Act.
Undertake a DPIA and an audit once every twelve months from designation.
Furnish significant DPIA and audit observations to the Data Protection Board.
Verify algorithmic software is not likely to pose a risk to Data Principals' rights.
Breach of an SDF's additional obligations attracts up to ₹150 crore, a separate head from the ₹250 crore (safeguards) and ₹200 crore (breach notification) ceilings. They stack.
The DPO, the appointment most organisations get wrong
The DPO must be based in India, responsible to the Board, represent the SDF under the Act, and be the point of contact for grievance redressal. Three errors recur:
Fails the statutory test outright. Common in multinational banks and foreign-owned NBFCs running a global privacy function.
The role is a representative office with Board accountability, it does not sit comfortably with a third party on a retainer.
They must be separate; the auditor must be independent. Your DPO cannot audit their own programme.
Rule 9 requires every Data Fiduciary, not just SDFs, to publish the business contact information of the DPO (or a person able to answer processing questions) on its website or app and in every notice and response. A generic support@ address with no named contact is a live gap today.
The independent data auditor
Section 10(2)(b) requires an independent data auditor to evaluate compliance with the Act. Use the governance model your Board already understands: IS Audit under ITGRCA , risk-based, independent of the function being audited, policy approved by the Audit Committee.
Scope covers consent, notice, purpose limitation, retention and erasure, rights fulfilment, breach handling, security safeguards, processor governance, and algorithmic due diligence.
Under Rule 13(2), significant observations go to the Data Protection Board, from the auditor. This is proactive disclosure. An SDF cannot afford an audit finding it has no remediation plan for. The finding and the plan should arrive together.
The DPIA, annual, not one-time
A DPIA is a structured process: rights of Data Principals, purpose of processing, and assessment and management of risk to those rights. Rule 13(1) is explicit: once every twelve months from designation. Not once. Annually, on the clock.
Run a DPIA before you launch, not just annually. The Rules do not mandate a pre-processing DPIA, but a new credit model, co-lending partner, or data source is exactly when risk enters the system. Discovering it eleven months later is an expensive way to find out.
Rule 13(3), algorithmic due diligence. This is the one.
An SDF shall observe due diligence to verify that algorithmic software deployed by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals.
This is the first provision in Indian law to explicitly mandate due diligence on algorithmic and AI/ML systems processing personal data. A rule, in the Gazette, with a ₹150 crore penalty head behind it. And it is the obligation Indian financial services is least prepared for, because RBI measured it.
RBI already surveyed you, FREE-AI, 13 August 2025
Credit underwriting is the second-largest AI use case in Indian finance, and 90% of entities using AI have no bias mitigation protocol. That is the gap Rule 13(3) is about to be enforced against.
Accuracy is not fairness. A model that maximises AUC by learning that applicants from certain pincodes, devices, phone-number series or employer categories default more often may be statistically correct and simultaneously a proxy for caste, religion, region, or gender. The model never sees the protected attribute. It does not need to. It reconstructs it. That is proxy discrimination, and alternative-data sources Indian fintech relies on are unusually rich in those proxies.
FREE-AI is advisory, not binding. But it is the clearest signal of where RBI supervision is heading. Building to it now is cheap. Retrofitting after a Master Direction is not.
Regulation 16C (SEBI Intermediaries Amendment, 10 February 2025): a regulated entity using AI/ML, whether in-house or procured, irrespective of scale, is solely responsible for the privacy, security and integrity of data, and for the output of those tools. "The vendor's model did it" is not a defence.
Three regulators, three instruments, one destination: you must be able to show that your models are governed, tested for bias, explainable, monitored, and owned by a named human being.
What an algorithmic due-diligence file contains
Two collisions from earlier episodes: erasure of training data (Episode 3) and purpose limitation when fraud data trains a collections model (Episode 2). Silence is the worst answer to either.
Rule 13(4), targeted localisation, not blanket localisation
Only categories the Government specifies. All other personal data follows the general cross-border rule. Reading Rule 13(4) as blanket localisation is a common and expensive error.
Metadata about the flow, not just the data itself. That reaches your logging, monitoring and observability stack, not just your database.
Payment-data localisation and SEBI data-residency expectations are stricter and already in force. Rule 13(4) is an additional layer, not a replacement.
The six SDF mistakes
Assuming you self-designate. Only a Central Government notification under Section 10(1) confers SDF status.
A non-resident or vendor DPO. Fails Section 10(2)(a).
DPO and data auditor as one appointment. They must be separate; the auditor must be independent.
A one-time DPIA. Rule 13(1) requires a fresh one every twelve months.
Ignoring Rule 13(3). Algorithmic due diligence applies to scoring models, fraud engines, ranking systems, any automated system processing personal data.
Reading Rule 13(4) as blanket localisation. It is targeted, category-specific.
The 12-month SDF-readiness plan
Against a 13 May 2027 commencement for the SDF regime, a twelve-month build started now finishes with time to spare. Started in 2027, it does not finish at all.
The argument for doing this even if you are never designated
FREE-AI's recommendations, board-approved AI policy, lifecycle governance, independent validation, AI incident reporting, annual-report disclosures, are advisory today and plausibly Master Direction material tomorrow.
Regulation 16C makes you solely liable for AI outputs, including procured models. Today.
Model governance is entering vendor due-diligence questionnaires. An evidenced answer closes deals faster than a promise.
To a regulator, to a court, or to a customer who was declined. Explainability for Rule 13(3) is the same explainability you will want the first time a lending decision is challenged.
Drift monitoring, bias testing and audit logs are things a well-run credit function should want anyway. Rule 13(3) is mostly asking you to do what you already claim you do.
The series, in one line
DPDP does not ask whether you have controls. It asks whether you can prove they work, on a timeline, in a format your regulator accepts.
The obligations stack across DPDP, RBI, SEBI, PMLA and CERT-In.
EP 2Which is why you run one control set, not five programmes.
EP 3Retention is a field-level engineering problem, and deletion you cannot prove did not happen.
EP 4A breach starts four clocks, and only evidence lets you meet them.
EP 5At the top tier, you must show your workings, to an independent auditor, to the Board, and now, for the first time, for your algorithms.
- Map DPDP Rule 13, RBI ITGRCA, SEBI CSCRF, CERT-In, ISO 27001 and SOC 2 onto one control backbone
- Collect DPIA and audit evidence continuously, annual cycle as review, not scramble
- Track model governance as live state: inventory, bias testing, drift, explainability, vendor due diligence
- Produce a Cyber Maturity Score substantiated by linked evidence, because a score an auditor cannot verify is worse than none at all
Compliance stopped being a document exercise. It is an evidence exercise. That is the whole story.
Sources: DPDP Act, 2023 (Sections 10, and the Schedule for penalties) and DPDP Rules, 2025 (G.S.R. 846(E), 13 Nov 2025), particularly Rules 9 and 13; RBI FREE-AI Committee Report, "Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector," 13 August 2025 (advisory, not binding); RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023; SEBI (Intermediaries) (Amendment) Regulations, 2025 (notified 10 February 2025, inserting Regulation 16C) and parallel SECC and Depositories amendments (binding); SEBI AI/ML reporting circulars, 2019; and SEBI's Consultation Paper on guidelines for responsible usage of AI/ML in Indian securities markets, 20 June 2025 (a proposal, not yet binding).
At the time of writing, no Significant Data Fiduciary has been notified under Section 10(1). Obligations vary by entity class and the regulatory position on AI is moving quickly , verify against the primary instrument applicable to your entity before relying on any of this. General information only; not legal advice.