InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Finance department

Central government: ministries and departments

DPDP for the Finance department in Central government

Accounts hold salaries, pensions and beneficiary payments.

Open this seat in the interactive tool

What is different here

Ministries and departments run some of the largest personal data systems in the country: scheme beneficiaries, licences, registrations, permits and grievances. The DPDP Act applies to the State too, with specific room for its functions: Section 7(b) and 7(c) allow processing for benefits, services and functions under law without consent, and Rule 5 sets the standards that processing must meet. Section 17(4) also lifts some erasure duties. The duties of security, breach reporting, accuracy and grievance redressal still apply in full.

The first four things to sort out

  1. Limit payment data access.
  2. Secure PFMS and bank files.
  3. Retention schedules.
  4. Report misdirected files.

A worked example: A beneficiary payment file sent to the wrong bank

  1. Hour 1The error is noticed.
  2. Hour 3The bank confirms deletion.
  3. Day 1Nodal officer records it.
  4. AfterFiles move only through PFMS.

Evidence kept: Confirmation; Record.

Use the system, not email.

What others in the sector usually do. Payment files move only through PFMS or bank portals.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Ministry of Ports, Shipping and Waterways and its officesPort entry passes with ID copies held by many parties; Seafarer records shared with training institutes and agencies; Terminal operator systems outside the ministry's direct control
Ministry of Road Transport and Highways and its officesBulk or API access by private entities; Accident and challan data; Toll and FASTag transaction data with vendors
Ministry of Chemicals and Fertilizers and its departmentsAadhaar authentication at retailer PoS devices; Farmer purchase data visible to companies and dealers; Kendra operators holding prescriptions and customer details
Other line ministries and departmentsBeneficiary lists published or shared in spreadsheets; System integrators with admin access; Grievance records with personal details
Citizen portals and DBT schemesAadhaar numbers stored outside a data vault; Bulk beneficiary data sent to states by email; Dashboards showing names and amounts publicly
Regulators and statutory bodiesOrders and filings published with personal details; Complaint data shared with regulated entities; Investigation files on shared drives

7 guides for the Finance department, in full

Can we share data with states, banks or other ministries?

Short answer: Yes, with a written basis, minimum fields and a log

Yes, where the scheme or a law needs it, through a written MoU or order that sets the purpose, the fields, security and retention. Share the minimum, through logged channels, and record each transfer. Bulk sharing with private parties needs a clear legal basis and should mask personal details where possible.

What the law says

Section 7 bases, Section 8(1) for processors, Section 8(5) for safeguards. Section 7 · Section 8(1)–(2) · Section 8(5) · Rule 6

Steps
  1. List every outgoing data flow.
  2. Write an MoU or order for each.
  3. Cut fields to the minimum.
  4. Use logged channels.
  5. Review flows yearly.
Evidence to keep
  • Flow register
  • MoUs
  • Transfer logs
Common mistakes
  • Email attachments
  • Full data when counts would do
  • No MoU
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: Finance department. Tax and audit rules require keeping some records for years. List them so they are kept, and the rest is deleted.
In Central government

Record retention schedules under public records rules decide periods.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Finance department. Payroll, payment and collection vendors hold sensitive data. Check their contracts.
In Central government

System integrators, NIC, state agencies and field operators process data for the department.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

From your seat: Finance department. Limit who can see bank details and salary data, and log access.
In Central government

Vendor admin accounts and district-level logins are the usual weak points.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6

Steps
  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.
Evidence to keep
  • Role matrix
  • Quarterly review sign-offs
  • Leaver removal report
Common mistakes
  • Generic logins on shared machines
  • Access that only grows
  • No review of vendor accounts
Related questions

Do we need consent for employee data?

Short answer: Not for employment purposes; yes for anything extra

Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.

From your seat: Finance department. Salary and bank details are employment data; sharing them beyond employment needs care.
In Central government

Service records and APARs are employment data; access should be tight.

What the law says

Section 7(i) covers employment purposes and safeguarding the employer from loss or liability. Notice, security, retention and rights still apply to employees. Section 7 · Section 5 · Rule 3 · Section 8(7) · Rule 8 · Sections 11–14 · Rule 14

Steps
  1. List what you collect from staff and why.
  2. Mark which items are employment purposes and which are extra.
  3. Take consent for the extras, separately.
  4. Give staff a short employee privacy notice.
  5. Set retention for ex-employee records.
Evidence to keep
  • Employee data list with basis
  • Employee privacy notice
  • Consent for extras
Common mistakes
  • A blanket consent clause in the offer letter
  • Keeping candidate data forever
  • Sharing staff data with vendors without terms
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Finance department. A misdirected salary file or payment list is a breach. Report it to the DPO at once.
In Central government

A leaked beneficiary list is a breach; CERT-In and the Data Protection Board both need to hear.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: Finance department. Check where finance and payroll SaaS is hosted.
In Central government

Hosting is usually in India; check support access by vendors' overseas teams.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for central government: ministries and departments.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 7(b) and 7(c) with Rule 5 and the Second ScheduleThe State may process personal data without consent to provide a subsidy, benefit, service, certificate, licence or permit, and to perform functions under law. Rule 5 asks that this processing follow the Second Schedule standards: lawful, for the stated use, limited to necessary data, accurate, kept only as long as needed, secured, and with a contact for questions and rights.Consent is not the basis for most scheme work. The standards are, and they need evidence.MeitY
DPDP Act, Section 17(4)For processing by the State, Section 8(7) (erasure) and Section 12(3) (erasure on request) do not apply, and where no decision affecting the person is made, Section 12(2) does not apply either.Retention follows public records rules rather than DPDP erasure. Security, accuracy, breach reporting and grievance duties still apply.MeitY
DPDP Act, Section 17(2)The Central Government may exempt notified instrumentalities for sovereignty, security, public order and related interests, and processing for research, archiving or statistics that does not lead to decisions about individuals.An exemption applies only if notified. Do not assume it.MeitY
RTI Act, Section 8(1)(j), as amended by DPDP Section 44(3) (in force 13 November 2025)Personal information is now exempt from disclosure under RTI, without the earlier public-interest test.Train CPIOs on the new wording; the amendment is being challenged before the Supreme Court, so watch for changes.SFLC.in summary
Public Records Act, 1993 and Public Records Rules, 1997Central government records may be destroyed only under approved record retention schedules.Erasure of personal data in files follows these schedules, since Section 17(4) lifts DPDP erasure for the State.National Archives of India
Aadhaar Act, 2016Section 7 allows Aadhaar for subsidies and benefits. Section 29 limits sharing of Aadhaar numbers and core biometric information. UIDAI asks entities storing Aadhaar numbers to keep them in an Aadhaar Data Vault.Scheme systems should store Aadhaar numbers only in a vault and show them masked.UIDAI
CERT-In Directions, 2022 and IT Act Section 70Report cyber incidents within six hours; keep ICT logs 180 days in India. Systems declared as protected systems under Section 70 come under NCIIPC.Ministries and their portals follow these in addition to DPDP.CERT-In
MeitY Email Policy and IT resources policy for GovernmentOfficial communication should use government email and approved resources.Personal email and chat apps for files with citizen data break both these policies and DPDP safeguards.MeitY
Guidelines for Indian Government Websites (GIGW)Government websites must carry standard policies, including a privacy policy.Update website privacy policies to DPDP notice standards with the contact person.MeitY / NIC
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.