Resources & FAQs
Checklists, the acts and circulars this field runs on, and plain answers on Social Impact Assessment, the Social Stock Exchange, and beneficiary-data obligations under the DPDPA.
Checklists
Downloadable PDF guides.
SSE Registration for NPOs
Download PDFSSE Annual Disclosures by NPOs & all Social Enterprises
Download PDFAnnual Impact Report
Download PDFInformative
DPDPA & Beneficiary Data: What NPOs Need to Know
Acts, circulars & guidelines
The primary texts governing CSR, the Social Stock Exchange, and the protection of beneficiary data. Published by SEBI, the Ministry of Corporate Affairs, and the Ministry of Electronics and Information Technology.
- SEBI (Issue of Capital and Disclosure Requirements) Regulations, 2018Last amended 8 March 2025
- SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015Last amended 22 January 2026
- Master Circular for Framework on Social Stock ExchangeSEBI
- CSR through Zero Coupon Zero Principal InstrumentG.S.R. 415(E)
- Insertion of ZCZP as item (xiii) in Schedule VII of the Companies Act, 2013G.S.R. 416(E)
- The Digital Personal Data Protection Act, 2023MeitY
- The Digital Personal Data Protection Rules, 2025MeitY
Frequently asked questions
What is Social Impact Assessment (SIA)?
Social Impact Assessment is a process used to analyse and evaluate social interventions undertaken by Non-Profit Organisations (NPOs), For-Profit Social Enterprises (FPSEs), CSR-funded entities, and Development Finance Institutions (DFIs). It assesses both the intended and unintended impacts of interventions, examining social intent, alignment with the Sustainable Development Goals, regulatory compliance, and measurable outcomes.
What does an SIA Report include?
An SIA Report covers: project background and objectives, stakeholder profile, assessment methodology and framework, study findings, impact indicators, outputs and outcomes, impact score, limitations and risks, beneficiary feedback, evidence documentation, recommendations, and an impact management plan.
Why should an organisation conduct SIA?
SIA helps assess whether a programme is creating intended social change, reaching the right beneficiaries, using resources effectively, and generating measurable outcomes. Organisations gain evidence for strategic decision-making, programme realignment, regulatory compliance, and donor reporting.
Who is qualified to conduct SIA?
SIA is conducted by qualified Social Impact Assessors certified by NISM (Series XXIII) and registered with a Self-Regulatory Organisation (SRO) under bodies such as ICAI (Institute of Social Auditors of India), ICSI (ICSI Institute of Social Auditors), or ICMAI (ICMAI Social Auditors Organisation). SRO registration is required for empanelled assessment under the SSE framework. Samvedana Analytics LLP is led by a NISM-certified Social Impact Assessor (ISAI/SA-674) and CRISIL-certified ESG Risk Analyst.
When is SIA mandatory?
Under the Companies (CSR Policy) Amendment Rules, 2021, Rule 8(3), social impact assessment of CSR projects is mandatory for companies with an average CSR obligation of ten crore rupees or more under Section 135(5) of the Companies Act, 2013, in the three immediately preceding financial years, for CSR projects with outlays of one crore rupees or more that have been completed not less than one year before undertaking the impact study. For NPOs, SIA is not legally mandatory but is required for SSE compliance and is increasingly expected by institutional funders.
What is the DPDPA and why does it matter for SIA?
The Digital Personal Data Protection Act, 2023, governs how organisations collect, store, process, and delete personal data, including beneficiary data gathered during impact assessments. When an SIA firm handles beneficiary data on behalf of a client organisation, the SIA firm acts as a Data Processor under Section 2(k), DPDPA. Its obligations arise from a written agreement made under Section 8(2), DPDPA and Rule 6 of the DPDP Rules, 2025, including access controls, encryption, processing logs, and data retention periods. The obligations to obtain consent, determine the purpose of processing, and fulfil requests for erasure under Section 12 rest with the client organisation acting as the Data Fiduciary; the Data Processor implements these obligations in accordance with the instructions of the Data Fiduciary. Substantive provisions of the DPDPA (including Data Principal rights and breach notification) commence on 13 May 2027.
Samvedana Analytics handles all beneficiary data through verifiable trust infrastructure licensed by Axiomaera, designed to meet DPDPA requirements, with clear Data Processor accountability.
To whom is the SIA report submitted?
The SIA Report is typically submitted to the commissioning organisation, CSR funders, board or trustees, regulators, SEBI/SSE (where applicable), and other authorised stakeholders.