Which industries are most likely to be designated
The Act does not enumerate industries — the Central Government does. But the published criteria map cleanly onto these sectors. If you operate in any of them at scale, plan as if designated and budget for the four obligations now.
Large social and consumer platforms
Volume + electoral-democracy risk + public-order risk all trip simultaneously above roughly 50 million Indian users.
Examples: Major social networks, large messaging platforms, video-sharing networks
Banking, payments, fintech at scale
Volume + sensitivity (financial data) + RBI sector overlay (master directions on data localisation, breach reporting) mean any large BFSI firm should plan for SDF designation, not hope to avoid it.
Examples: Large private banks, top-5 payment aggregators, top-10 NBFCs
Healthcare and diagnostics at scale
Health data is intrinsically sensitive under Section 2(t). Diagnostics chains, hospital groups, and digital-health platforms above a few million records will be designated even at modest volumes.
Examples: Pan-India hospital chains, large diagnostic networks, telemedicine platforms
EdTech with under-18 users at scale
Children-data (Section 9) automatically elevates risk-to-Data-Principals scoring. Any EdTech with millions of student records is a near-certain SDF.
Examples: K-12 learning platforms, large coaching platforms, language-learning apps for children
Telecom service providers
Subscriber metadata, location, call records — all sovereignty-implicating categories. Telcos sit at the intersection of DoT licence conditions and DPDP.
Examples: Major telcos, ISPs above a threshold subscriber base
Aadhaar-linked services at scale
UIDAI authentication or Aadhaar e-KYC at volume couples national-ID exposure with biometric-derived data. The sovereignty and security-of-the-State factors apply directly.
Examples: KYC service providers, identity-verification platforms, government-tech intermediaries
Large e-commerce and D2C platforms
Volume thresholds apply; behavioural-profiling and address-graph data raise rights-to-Data-Principals risk. Most top-10 e-commerce platforms by GMV should plan as if SDF.
Examples: Top 5 horizontal marketplaces, top quick-commerce platforms
AdTech and DMPs
Cross-site profiling, audience segments, lookalike modelling — all explicitly listed by international privacy regulators as high-risk processing. Indian AdTech at scale will be designated.
Examples: Large DSPs/SSPs operating in India, profile-aggregation platforms