Rule 13, Significant Data Fiduciary obligations
In short
Rule 13 attaches four obligations to a Data Fiduciary that has been notified as a Significant Data Fiduciary, or that falls within a class notified as such. They run from the date of that notification or inclusion, not from any earlier point.
01The four obligations
| Sub rule | Obligation |
|---|---|
| 13(1) | Once in every period of twelve months from the date of notification or inclusion, undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the Act and the rules made under it |
| 13(2) | Cause the person carrying out that assessment and audit to furnish to the Board a report containing significant observations |
| 13(3) | Observe due diligence to verify that technical measures, including algorithmic software, adopted for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals |
| 13(4) | Undertake measures to ensure that personal data specified by the Central Government, and the traffic data pertaining to its flow, is not transferred outside the territory of India |
02The two provisions with open scope
Two of the four are not yet fully determinate on the face of the rule.
- Rule 13(2). The report goes to the Board. What constitutes a significant observation is left to the person carrying out the assessment and audit, which makes the choice of that person a governance decision rather than a procurement one.
- Rule 13(4). The categories of personal data covered are to be specified by the Central Government on the basis of the recommendations of a committee it constitutes for the purpose, which under Rule 13(5) includes officials from the Ministry of Electronics and Information Technology and may include officials from other Ministries or Departments. Until that specification exists, the scope of the localisation restriction is not known.
The work that holds its value in the meantime is a data flow map fine grained enough to answer the restriction once its scope is published.
03Common questions
How often is the DPIA and audit required?
Once in every period of twelve months from the date on which the Data Fiduciary is notified as a Significant Data Fiduciary or is included in a class notified as such.
Does the audit report stay internal?
No. Rule 13(2) requires a report containing significant observations to be furnished to the Board.
Which data cannot be transferred outside India?
Personal data specified by the Central Government on the recommendation of a committee constituted for the purpose, together with the traffic data pertaining to its flow. That specification has not been published.
Ask an AI assistant about this page
Each button opens the assistant with the prompt below already written.
Answers are generated by third party systems and are not published or verified by this site. Check anything load bearing against the gazette text.