How to Appoint a Data Protection Officer Under the DPDPA 2023 in India
- Kaustav Chowdhury

- Jul 10
- 4 min read
Updated: Jul 17
The Digital Personal Data Protection Act, 2023 (DPDPA) requires every Significant Data Fiduciary (SDF) to appoint a Data Protection Officer (DPO). This guide explains who must appoint a DPO, the qualifications and responsibilities involved, and the step-by-step process for compliance under Section 10 of the Act.
Who Must Appoint a DPO?
Only organisations that have been officially notified as Significant Data Fiduciaries by the Central Government are required to appoint a DPO. The Central Government designates SDFs based on factors including the volume and sensitivity of personal data processed, the risk to the rights of data principals, potential impact on the sovereignty and integrity of India, risks to electoral democracy, and considerations of security of the state and public order.
Regular Data Fiduciaries that do not fall within the SDF classification are not legally required to appoint a DPO, though doing so is considered a best practice for data governance.
Key Requirements for the DPO
Under Section 10(2)(a) of the DPDPA, the DPO must be an individual (not an entity or outsourced firm), must be based in India, must be responsible to the Board of Directors or the governing body of the organisation, and must serve as the point of contact for grievance redressal and for representing the organisation before the Data Protection Board of India.
Step-by-Step Appointment Process
Step 1: Determine SDF Status. Check whether your organisation has been notified as a Significant Data Fiduciary by the Central Government. Monitor official gazette notifications and MeitY communications for SDF classification orders.
Step 2: Define the DPO Role. Draft a detailed job description covering the DPO's responsibilities, which include overseeing compliance with the DPDPA, handling data principal grievances, conducting or overseeing Data Protection Impact Assessments (DPIAs), liaising with the Data Protection Board, and ensuring periodic audits of data processing activities.
Step 3: Select and Appoint. Identify a suitable individual with knowledge of data protection law, information security, and the organisation's data processing operations. Pass a formal board resolution appointing the DPO and ensure the appointment is documented in the organisation's records.
Step 4: Publish Contact Details. Make the DPO's contact information accessible to data principals through the organisation's website and privacy policy. The DPO must be reachable for grievance redressal as mandated under the Act.
Step 5: Integrate the DPO into Governance. Ensure the DPO has direct reporting access to the Board of Directors, is involved in all decisions affecting personal data processing, and has adequate resources and independence to perform their role effectively.
Penalties for Non-Compliance
Failure to appoint a DPO when required under Section 10 can attract penalties of up to Rs 150 crore from the Data Protection Board of India. Organisations should ensure timely compliance once notified as an SDF.
For related guidance on AI governance in legal proceedings and filing regulatory complaints, see our other guides.
Practical Considerations for Organisations
The appointment of a Data Protection Officer is a critical compliance requirement under India's data protection framework. Organisations that process significant volumes of personal data or that fall within the categories designated as Significant Data Fiduciaries must appoint a DPO who is based in India and who serves as the primary point of contact for the Data Protection Board and for data principals exercising their rights.
When selecting a DPO, organisations should look for individuals who combine legal knowledge with a practical understanding of data management systems and information security. The DPO should have sufficient seniority within the organisation to influence decision-making and should have direct access to the board of directors or the highest management body. Independence is also important: the DPO should be able to raise concerns about data protection practices without fear of retaliation.
Organisations should also consider the scope of the DPO's responsibilities and ensure that adequate resources are allocated to support the function. This includes access to legal counsel, technology tools for data mapping and breach detection, and training budgets to keep the DPO current with evolving regulatory requirements. Understaffing the data protection function is a common compliance failure that can result in delayed breach notifications, inadequate responses to data principal requests, and ultimately regulatory action.
Finally, organisations should establish clear internal reporting mechanisms so that the DPO is notified promptly of any personal data breaches, new processing activities, or changes to existing data processing systems. The DPO's role is not limited to responding to regulatory inquiries; it encompasses ongoing monitoring of the organisation's data protection posture and proactive identification of compliance gaps before they escalate into formal complaints or enforcement actions.
Organisations should also consider the contractual implications of the DPO appointment when engaging with data processors and third-party service providers. Data processing agreements should clearly identify the DPO as the contact point for data protection matters and should specify the obligations of the data processor to cooperate with the DPO in responding to data principal requests, conducting data protection impact assessments, and reporting personal data breaches within the timelines prescribed by the Act.
For related guidance, see our guide on how to register a company in India under the Companies Act 2013 and how to apply for MSME Udyam registration online in India.

Comments