Data Protection Officer (DPO)
The India-based officer appointed by a Significant Data Fiduciary under the DPDP Act 2023 to serve as the point of contact for grievance redressal.
The Data Protection Officer role is created by Section 10(2)(a) of the Digital Personal Data Protection Act 2023 for entities notified as Significant Data Fiduciaries. The DPO must be based in India, must be responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary, and must be the point of contact for the grievance redressal mechanism under the Act.
Rule 12 of the DPDP Rules 2025 sets out the DPO's functional requirements: the SDF must publish the DPO's business contact information on its website, must reference the DPO in every notice given under Section 5, and must ensure the DPO reports directly to the Board. The DPO's role includes overseeing DPIAs required under Section 10(2)(b) and the periodic data protection audit conducted by the appointed independent data auditor.
For non-SDF Data Fiduciaries, appointing a formal DPO is not mandatory — Section 8(9) requires only a grievance officer whose contact must be published. In practice, most mid-market and larger Data Fiduciaries appoint a DPO voluntarily to build the muscle before an eventual SDF notification. The dcomply Academy DPDP Rules 2025 / DPO Practitioner Certification is written to the working DPO's day-to-day toolkit.