Skip to main content

The Significant Data Fiduciary's Four Duties Under Rule 13

Rule 13's four duties for a Significant Data Fiduciary: a twelve-month DPIA and audit, a Board report, algorithmic due diligence, an India-only restriction.

On this page (8)

Rule 13 of the Digital Personal Data Protection Rules, 2025 runs to five sub-rules. Four impose duties on a Significant Data Fiduciary; the fifth defines the committee behind the fourth. Two are governance work. Two redraw a network diagram.

Rule 13 The duty What closes it
(1) DPIA and audit, once in every twelve months from notification A dated DPIA and audit against an evidenced anniversary
(2) Cause the assessor to furnish the Board a report of significant observations A filing clause in the engagement letter; a materiality test
(3) Due diligence to verify technical measures, algorithmic software included A record of what was checked, against what, by whom, when
(4) Specified personal data and its traffic data stay inside India A per-pipeline flow map and a control at each hop

Head 4 of the Act's Schedule prices a breach of the section 10 obligations under section 33(1): a penalty that "May extend to one hundred and fifty crore rupees" — a ceiling, not a tariff.

Rule 13 commences eighteen months after publication of the Rules; section 10 of the Act runs its own eighteen-month clock under clause (c) of G.S.R. 843(E). Two start dates are defensible: a masthead date of 13 November 2025 on both notifications, and an e-gazette identifier printed on page 1 of each encoding 14 November (CG-DL-E-14112025-267650 for the Rules, CG-DL-E-14112025-267647 for the Act notification), the date the PIB release of 17 November 2025 gives twice. Programme to the earlier reading; the tranche map is in our companion piece on rule 6.

The clock is an anniversary

Rule 13(1) counts "once in every period of twelve months from the date on which it is notified as such", and names a second route in: a fiduciary "included in the class of Data Fiduciaries notified as such".

Each designation carries its own anniversary, so a group designated entity by entity collects clocks one at a time; consolidating them onto one financial-year cycle means running a round early. A class notification starts every member's clock on the same day, and a sector then competes for assessor capacity in one quarter.

Rule 13(1) also fixes the object as "effective observance of the provisions of this Act and the rules made thereunder", which makes the Rules the scope document. Section 10(2)(c) separates the two artefacts, a periodic DPIA and a periodic audit; 10(2)(b) requires an independent data auditor.

Who furnishes the report, and what "significant" has to mean

Rule 13(2) has two parties in it. The fiduciary's duty is to cause the report to be furnished; the party that furnishes it to the Board is "the person carrying out" the DPIA and audit. So the engagement letter carries a filing obligation running from your assessor to the regulator, and the fiduciary stays accountable for it.

What travels is a report of "significant observations". The characterisation is the assessor's, and the assessor signs it. Settle two things before fieldwork: the materiality test (severity, volume and sensitivity of the data reached, rights impairment) and the factual-accuracy cycle, a window in which the fiduciary corrects facts while the assessor's characterisation stands.

Sub-rule (4): the traffic data problem

Rule 13(4) has the largest engineering blast radius of the four. The trigger is personal data "specified by the Central Government, on the basis of the recommendations of a committee constituted by it", processed subject to the restriction that:

"the personal data and the traffic data pertaining to its flow is not transferred outside the territory of India"

DPDP Rules, 2025, rule 13(4)

Seven words do the work: "the traffic data pertaining to its flow". A residency control built around records at rest will not reach it. Traffic data is the metadata of movement, held by systems an inventory records as infrastructure.

Where flow data sits

  • Edge and CDN. Request logs at points of presence, WAF events and origin-shield telemetry.
  • Observability. Traces, error trackers and log shipping, terminating in a vendor region chosen at onboarding.
  • Managed services. Telemetry from databases, queues and identity providers, returned to the vendor by default.
  • Replicas, backups and DR. Cross-region replication, snapshot vaults, the secondary region in the runbook.
  • Support paths. Remote sessions and diagnostic bundles exported to an overseas support tier.

The retention interaction

Rule 6(1) item (e) requires the fiduciary to "retain such logs and personal data for a period of one year", so the estate holds a year of logs by obligation and rule 13(4) governs where the flow data in them sits. Answer both per pipeline, not per application: one application's traffic data usually splits across four or five pipelines with different destinations.

What closes sub-rule (4) is a flow map at pipeline granularity — for each system, where the personal data rests, where its traffic data is generated, and which hop leaves Indian territory. Most estates produce the first and stall on the second.

Sub-rule (3): verification, and what it verifies against

The duty is "due diligence to verify", so the deliverable is a record: dated, attributable, repeatable next anniversary. The sweep is "technical measures including algorithmic software" adopted for nine operations, "hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing". A recommendation engine, a ranking model and a fraud-scoring service sit in the same sentence as the storage layer.

The test is whether they are "not likely to pose a risk to the rights of Data Principals", keyed to the Chapter III rights: access (section 11), correction and erasure (12), grievance redressal (13), nomination (14). That makes it answerable by technical assessment, because rights impairment surfaces as ordinary findings.

  • An export endpoint returning more fields than the request was scoped to, or authorising on a client-supplied identifier.
  • A model feature store where data assembled for scoring is reachable by a role the application never granted.
  • Erasure that stops at the primary store, leaving copies in caches, search indexes, training sets and embeddings.
  • A grievance route that fails under load, a rights failure with a control cause.

Test against the rights, and the verification record writes itself.

Our position

We will sign a rule 13(2) engagement letter naming the filing obligation, the materiality test and the signing individual, before fieldwork rather than at reporting. An assessor who wants the characterisation to be theirs should accept a standard agreed in advance.

We will also say which of the four sub-rules an engagement covers: 13(1)'s DPIA and audit, 13(3)'s verification record and 13(4)'s flow mapping are three different exercises.

Security Brigade has been CERT-In empanelled since 2008, and we scope DPDP work sub-rule by sub-rule with the evidence named for each.

What to put in your next statement of work

  1. Fix the filing date first. Fieldwork, draft, factual-accuracy cycle, sign-off and filing all land inside twelve months of the notification date.
  2. Define "significant observations" before fieldwork. A written materiality test agreed by the DPO and the assessor, attached to the engagement letter.
  3. Commission the verification record as a deliverable. Sub-rule (3) wants what was checked, the measure, the method, the date and the tester, comparable next year.
  4. Buy a flow map, not an application inventory. Sub-rule (4) turns on traffic data: source, transport, destination region, retention, and the control holding each hop inside India.
  5. Reconcile the breach runbook to every clock. An Indian fiduciary reports incidents to CERT-In within six hours under the CERT-In Directions of 28 April 2022, and rule 7(2) adds the Board, owed a description without delay under (a) and detailed information within seventy-two hours under (b). Our rule 7 piece works through them.

The four sub-rules are one programme with one date on it. The long pole is the flow map sub-rule (4) turns on, so start there.

Talk to Security Brigade about scoping a rule 13 programme: the DPIA and audit on your anniversary, a sub-rule (3) verification record, and the flow mapping sub-rule (4) needs.

About the authors

Founder & Chief Technology Officer

Founded Security Brigade in 2006 with the thesis that security assessment quality should be structural, not dependent on individual testers. 16+ years building platforms, teams, and methodologies that make enterprise security consistent.

Photo of Security Brigade Research Team

Offensive Security Research · Security Brigade

A rotating byline for collaborative analysis pieces from Security Brigade's offensive security and threat-research practice.