Compliance calendar
e-GazetteExchanges and other

Significant Data Fiduciary annual DPIA and audit

A notified Significant Data Fiduciary completes a DPIA and audit once in each 12-month period measured from its notification date.

How this is timed

Annual DPIA and audit

Regulator
e-Gazette
Category
Exchanges and other
Form
Not specified
Last verified
2026-09-01

The rule starts on 13 May 2027, but it applies only after the Central Government notifies the entity or its class as a Significant Data Fiduciary. From that notification date, complete a data protection impact assessment and audit once in every 12-month period. No SDF notification existed on 1 September 2026.

What changed

This is conditional, not a general annual listed-company duty. Rule 4 starts on 2026-11-13 for Consent Managers. Rule 13 starts on 2027-05-13, and its 12-month cycle starts only when the entity is notified as an SDF.

Deadlines counted from an event

These have no calendar date. The clock starts when the event happens.

Annual DPIA and audit

Complete the DPIA and audit once in every 12 months from the SDF notification date.

Applies when: The entity or its class has been notified as a Significant Data Fiduciary.

The rule

Stated as the law states it, so you can work out any period yourself.

Annual DPIA and audit

Complete the DPIA and audit once in every 12 months from the SDF notification date.

Applies when: The entity or its class has been notified as a Significant Data Fiduciary.

Who must comply

  • Only a listed company or class notified as a Significant Data Fiduciary under section 10(1)

Statutory basis

Read the provision here where we hold it, or on the regulator's site.

Last verified 2026-09-01. Confirm against the official source before you rely on it.