InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Secretary / Head of Department

Central government: ministries and departments

DPDP for the Secretary / Head of Department in Central government

As Secretary or Head of Department, you own the department's duty to citizens whose data it holds.

Open this seat in the interactive tool

What is different here

The public expects government to set the example. A breach in a scheme portal becomes news quickly. The work is mostly in contracts with integrators, access control and the grievance process.

The first four things to sort out

  1. Name a data protection nodal officer with authority across divisions.
  2. Ask for a register of schemes and systems holding personal data.
  3. Require integrator contracts to carry data protection terms.
  4. Make data protection a standing item in monthly reviews.

A worked example: The Secretary orders a data protection review

  1. Month 1A nodal officer is named and each division lists its schemes with personal data.
  2. Month 2Integrator contracts are reviewed; four have no data terms.
  3. Month 4Amendments are signed. Admin access is moved to named accounts.
  4. MonthlyThe nodal officer reports in the Secretary's review meeting.

Evidence kept: Office order; Scheme register; Contract amendments; Review minutes.

An office order and a monthly review make it happen.

What others in the sector usually do. Departments that have started give the nodal officer a direct line to the Secretary's office.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Ministry of Ports, Shipping and Waterways and its officesPort entry passes with ID copies held by many parties; Seafarer records shared with training institutes and agencies; Terminal operator systems outside the ministry's direct control
Ministry of Road Transport and Highways and its officesBulk or API access by private entities; Accident and challan data; Toll and FASTag transaction data with vendors
Ministry of Chemicals and Fertilizers and its departmentsAadhaar authentication at retailer PoS devices; Farmer purchase data visible to companies and dealers; Kendra operators holding prescriptions and customer details
Other line ministries and departmentsBeneficiary lists published or shared in spreadsheets; System integrators with admin access; Grievance records with personal details
Citizen portals and DBT schemesAadhaar numbers stored outside a data vault; Bulk beneficiary data sent to states by email; Dashboards showing names and amounts publicly
Regulators and statutory bodiesOrders and filings published with personal details; Complaint data shared with regulated entities; Investigation files on shared drives

What a good answer from management sounds like

Question to askA good answer sounds likeEffort and time
Do we need citizens' consent to run a scheme?“Each scheme has a written basis and a standards check, and every portal shows a contact.”Medium · 6 to 10 weeks
Can we share data with states, banks or other ministries?“Every outgoing flow has an MoU, minimum fields and a log.”Medium
What do the Second Schedule standards ask of a scheme?“Each scheme has a one-page standards checklist with evidence, reviewed yearly.”Medium · per scheme
Do we need a DPO?“We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”Light · 2 to 4 weeks
How much effort and time will it take to be ready by 13 May 2027?“We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”Programme · six to nine months
Something has gone wrong. What happens in the first 72 hours?“We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”Medium · 4 to 8 weeks, then a yearly drill
What must a vendor contract say about personal data?“Our top vendors have data terms with a short incident-notice time, and we review them every year.”Medium · 8 to 16 weeks for the top vendors
Could we be a Significant Data Fiduciary?“We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”Medium if you are a likely candidate

8 guides for the Secretary / Head of Department, in full

Do we need citizens' consent to run a scheme?

Short answer: Usually not; Section 7(b) or 7(c) with Rule 5 standards

Usually not. Section 7(b) allows the State to process personal data to give a subsidy, benefit, service, certificate, licence or permit, and Section 7(c) covers functions under law. Rule 5 then asks that this processing meet the Second Schedule standards. Consent is still needed for uses outside these, such as publicity stories or surveys not tied to the scheme.

From your seat: Secretary / Head of Department. Approve the register at your level.
What the law says

Section 7(b) and 7(c) set the bases. Rule 5 and the Second Schedule set the standards. Section 7 · Section 4

What a good answer from management sounds like: “Each scheme has a written basis and a standards check, and every portal shows a contact.”
Effort and time: Medium · 6 to 10 weeks.
Steps
  1. Write the basis for each scheme: 7(b), 7(c) or consent.
  2. Check each scheme against the Second Schedule standards.
  3. Remove fields not needed for the benefit.
  4. Publish a contact for questions and rights.
  5. Take consent for extra uses.
Evidence to keep
  • Basis register
  • Standards check
  • Published contact
Common mistakes
  • Taking 'consent' that citizens cannot refuse
  • Collecting extra fields 'for analysis'
  • No contact for questions
Related questions

Can we share data with states, banks or other ministries?

Short answer: Yes, with a written basis, minimum fields and a log

Yes, where the scheme or a law needs it, through a written MoU or order that sets the purpose, the fields, security and retention. Share the minimum, through logged channels, and record each transfer. Bulk sharing with private parties needs a clear legal basis and should mask personal details where possible.

What the law says

Section 7 bases, Section 8(1) for processors, Section 8(5) for safeguards. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6

What a good answer from management sounds like: “Every outgoing flow has an MoU, minimum fields and a log.”
Effort and time: Medium.
Steps
  1. List every outgoing data flow.
  2. Write an MoU or order for each.
  3. Cut fields to the minimum.
  4. Use logged channels.
  5. Review flows yearly.
Evidence to keep
  • Flow register
  • MoUs
  • Transfer logs
Common mistakes
  • Email attachments
  • Full data when counts would do
  • No MoU
Related questions

What do the Second Schedule standards ask of a scheme?

Short answer: Seven practical standards, each needing evidence

Process lawfully and only for the scheme's purpose, collect only the data needed, keep it accurate, keep it only as long as needed or required by law, protect it with reasonable safeguards, give people a contact for questions and rights, and be accountable for meeting these standards.

What the law says

Rule 5 and the Second Schedule apply to State processing under Section 7(b). Section 7 · Section 8(5) · Rule 6 · Section 8(3)

What a good answer from management sounds like: “Each scheme has a one-page standards checklist with evidence, reviewed yearly.”
Effort and time: Medium · per scheme.
Steps
  1. Field review: needed or not.
  2. Accuracy: how errors are corrected.
  3. Retention: which schedule applies.
  4. Security: who can access.
  5. Contact: published on the portal.
  6. Accountability: a named officer.
Evidence to keep
  • Standards checklist per scheme
  • Correction process
  • Retention schedule
Common mistakes
  • Treating standards as a formality
  • No correction route
  • No named officer
Related questions

Do we need a DPO?

Short answer: Not required by law unless notified as an SDF, but name one person

Only a Significant Data Fiduciary must appoint a DPO, based in India. Every other organisation must publish the contact of a person who can answer questions about personal data. In practice, most organisations of any size name one accountable person anyway, because someone has to own requests, complaints and breaches.

From your seat: Secretary / Head of Department. The person you name needs your visible backing. Give the role a budget line and ask for a short report every month.
In Central government

A nodal officer with authority across divisions is the practical choice.

What the law says

Section 8(9) and Rule 9 require a published contact person for every Data Fiduciary. Section 10 requires a DPO in India for Significant Data Fiduciaries. Section 8(9)–(10) · Rules 9, 14 · Section 10 · Rule 13

What a good answer from management sounds like: “We have named an accountable person with a deputy, published the contact, and that person reports to management every month.”
Effort and time: Light · 2 to 4 weeks.
Steps
  1. Name one accountable person, with a deputy.
  2. Publish the contact on your website, app and notices.
  3. Give the role time, a budget line and a route to management.
  4. Set a short monthly report: requests, complaints, incidents, actions.
  5. Review the role if you are notified as an SDF.
Evidence to keep
  • Appointment letter
  • Published contact
  • Monthly report
Common mistakes
  • Giving the job to IT as a side task
  • A contact email nobody reads
  • No authority to make changes
Related questions

How much effort and time will it take to be ready by 13 May 2027?

Short answer: Six to nine months of steady work for most

For most organisations it is a programme of six to nine months, not a single project. The heavy parts are the data inventory, vendor contracts, access control and the request process. Notices, the contact person and training are lighter. Starting now leaves time to fix what you find.

From your seat: Secretary / Head of Department. Treat it as a nine-month programme with one owner. The cost is mostly people's time and some system changes, not a single tool.
In Central government

Most effort goes into integrator contracts, access control and data flows.

What the law says

Most duties under the DPDP Rules start on 13 May 2027. Section 8(5) · Rule 6 · Section 8(1)–(2) · Sections 11–14 · Rule 14

What a good answer from management sounds like: “We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.”
Effort and time: Programme · six to nine months.
Steps
  1. Month 1: name the owner, set a budget line, start the inventory.
  2. Months 2 to 3: notices, consent records, contact person, request register.
  3. Months 3 to 6: vendor contracts, access control, logs, retention schedule.
  4. Months 6 to 8: breach rehearsal, training, internal review.
  5. Month 9: management review with evidence.
Evidence to keep
  • Programme plan with owners
  • Monthly status with evidence
  • Management minutes
Common mistakes
  • Leaving it to the last quarter
  • Buying a tool before knowing the gaps
  • Status colours with no evidence behind them
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Secretary / Head of Department. You will be the public face if something goes wrong. Know who calls you, at what hour, and who speaks to customers and the media.
In Central government

A leaked beneficiary list is a breach; CERT-In and the Data Protection Board both need to hear.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

What a good answer from management sounds like: “We have one plan that meets every clock. It was rehearsed this year, and the next rehearsal date is fixed.”
Effort and time: Medium · 4 to 8 weeks, then a yearly drill.
Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Secretary / Head of Department. Ask for the top ten vendors by personal data held. If the list takes weeks to produce, that is the first gap.
In Central government

System integrators, NIC, state agencies and field operators process data for the department.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

What a good answer from management sounds like: “Our top vendors have data terms with a short incident-notice time, and we review them every year.”
Effort and time: Medium · 8 to 16 weeks for the top vendors.
Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Could we be a Significant Data Fiduciary?

Short answer: Only by notification; none notified yet

Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.

From your seat: Secretary / Head of Department. Ask management for a short note on whether you could be notified, and what it would take to be ready.
In Central government

No government body had been notified as an SDF when this page was last reviewed. Large public data holders should prepare.

What the law says

Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India. Section 10 · Rule 13 · Section 16 · Rule 15

What a good answer from management sounds like: “We have estimated our exposure. If we are notified, we can appoint a DPO and an auditor within weeks, because the groundwork is done.”
Effort and time: Medium if you are a likely candidate.
Steps
  1. Estimate how many people's data you hold and how sensitive it is.
  2. Note any public or security role your data plays.
  3. If you are a likely candidate, run a trial impact assessment this year.
  4. Identify an auditor you could appoint.
  5. Watch MeitY notifications.
Evidence to keep
  • Volume and sensitivity note
  • Trial impact assessment
  • Board note
Common mistakes
  • Assuming 'not notified' means 'never'
  • Waiting for notification to start
  • Thinking only tech companies will be notified
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for central government: ministries and departments.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 7(b) and 7(c) with Rule 5 and the Second ScheduleThe State may process personal data without consent to provide a subsidy, benefit, service, certificate, licence or permit, and to perform functions under law. Rule 5 asks that this processing follow the Second Schedule standards: lawful, for the stated use, limited to necessary data, accurate, kept only as long as needed, secured, and with a contact for questions and rights.Consent is not the basis for most scheme work. The standards are, and they need evidence.MeitY
DPDP Act, Section 17(4)For processing by the State, Section 8(7) (erasure) and Section 12(3) (erasure on request) do not apply, and where no decision affecting the person is made, Section 12(2) does not apply either.Retention follows public records rules rather than DPDP erasure. Security, accuracy, breach reporting and grievance duties still apply.MeitY
DPDP Act, Section 17(2)The Central Government may exempt notified instrumentalities for sovereignty, security, public order and related interests, and processing for research, archiving or statistics that does not lead to decisions about individuals.An exemption applies only if notified. Do not assume it.MeitY
RTI Act, Section 8(1)(j), as amended by DPDP Section 44(3) (in force 13 November 2025)Personal information is now exempt from disclosure under RTI, without the earlier public-interest test.Train CPIOs on the new wording; the amendment is being challenged before the Supreme Court, so watch for changes.SFLC.in summary
Public Records Act, 1993 and Public Records Rules, 1997Central government records may be destroyed only under approved record retention schedules.Erasure of personal data in files follows these schedules, since Section 17(4) lifts DPDP erasure for the State.National Archives of India
Aadhaar Act, 2016Section 7 allows Aadhaar for subsidies and benefits. Section 29 limits sharing of Aadhaar numbers and core biometric information. UIDAI asks entities storing Aadhaar numbers to keep them in an Aadhaar Data Vault.Scheme systems should store Aadhaar numbers only in a vault and show them masked.UIDAI
CERT-In Directions, 2022 and IT Act Section 70Report cyber incidents within six hours; keep ICT logs 180 days in India. Systems declared as protected systems under Section 70 come under NCIIPC.Ministries and their portals follow these in addition to DPDP.CERT-In
MeitY Email Policy and IT resources policy for GovernmentOfficial communication should use government email and approved resources.Personal email and chat apps for files with citizen data break both these policies and DPDP safeguards.MeitY
Guidelines for Indian Government Websites (GIGW)Government websites must carry standard policies, including a privacy policy.Update website privacy policies to DPDP notice standards with the contact person.MeitY / NIC
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.