InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Data protection nodal officer

Central government: ministries and departments

DPDP for the Data protection nodal officer in Central government

In a ministry, you are often the first officer to look at personal data as something the department owes duties on, not just files it holds.

Open this seat in the interactive tool

What is different here

Consent is rarely the basis. The questions are different: is each scheme's processing within Section 7(b) or 7(c), does it meet the Second Schedule standards, who are the processors, and how are breaches and grievances handled. Erasure follows public records rules because of Section 17(4).

The first four things to sort out

  1. List each scheme or service that processes personal data, with its legal basis and processors.
  2. Check each against the Second Schedule standards and note gaps.
  3. Publish a contact for questions and rights on every portal.
  4. Set up one breach procedure that reaches the Data Protection Board as well as CERT-In.

A worked example: A beneficiary asks why her name appeared in a public list

  1. Day 1Her grievance arrives on the portal. The nodal officer logs it and asks the scheme division where the list came from.
  2. Day 3The division confirms a district office uploaded a beneficiary list with names, villages and amounts to a public page.
  3. Day 4The page is taken down. The nodal officer assesses it as a breach and informs the Data Protection Board and affected beneficiaries.
  4. Week 2Lists are now published with masked names and no amounts, as the scheme head approved.

Evidence kept: Grievance entry; Breach assessment; Board intimation; Revised publishing rule.

Transparency and privacy can both be served by publishing less detail.

What others in the sector usually do. Departments that have started keep a one-page register per scheme: data held, basis, processors, hosting, retention schedule and contact.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Ministry of Ports, Shipping and Waterways and its officesPort entry passes with ID copies held by many parties; Seafarer records shared with training institutes and agencies; Terminal operator systems outside the ministry's direct control
Ministry of Road Transport and Highways and its officesBulk or API access by private entities; Accident and challan data; Toll and FASTag transaction data with vendors
Ministry of Chemicals and Fertilizers and its departmentsAadhaar authentication at retailer PoS devices; Farmer purchase data visible to companies and dealers; Kendra operators holding prescriptions and customer details
Other line ministries and departmentsBeneficiary lists published or shared in spreadsheets; System integrators with admin access; Grievance records with personal details
Citizen portals and DBT schemesAadhaar numbers stored outside a data vault; Bulk beneficiary data sent to states by email; Dashboards showing names and amounts publicly
Regulators and statutory bodiesOrders and filings published with personal details; Complaint data shared with regulated entities; Investigation files on shared drives

10 guides for the Data protection nodal officer, in full

Do we need citizens' consent to run a scheme?

Short answer: Usually not; Section 7(b) or 7(c) with Rule 5 standards

Usually not. Section 7(b) allows the State to process personal data to give a subsidy, benefit, service, certificate, licence or permit, and Section 7(c) covers functions under law. Rule 5 then asks that this processing meet the Second Schedule standards. Consent is still needed for uses outside these, such as publicity stories or surveys not tied to the scheme.

From your seat: Data protection nodal officer. Own the basis register.
What the law says

Section 7(b) and 7(c) set the bases. Rule 5 and the Second Schedule set the standards. Section 7 · Section 4

Steps
  1. Write the basis for each scheme: 7(b), 7(c) or consent.
  2. Check each scheme against the Second Schedule standards.
  3. Remove fields not needed for the benefit.
  4. Publish a contact for questions and rights.
  5. Take consent for extra uses.
Evidence to keep
  • Basis register
  • Standards check
  • Published contact
Common mistakes
  • Taking 'consent' that citizens cannot refuse
  • Collecting extra fields 'for analysis'
  • No contact for questions
Related questions

What do the Second Schedule standards ask of a scheme?

Short answer: Seven practical standards, each needing evidence

Process lawfully and only for the scheme's purpose, collect only the data needed, keep it accurate, keep it only as long as needed or required by law, protect it with reasonable safeguards, give people a contact for questions and rights, and be accountable for meeting these standards.

From your seat: Data protection nodal officer. Keep one checklist per scheme.
What the law says

Rule 5 and the Second Schedule apply to State processing under Section 7(b). Section 7 · Section 8(5) · Rule 6 · Section 8(3)

Steps
  1. Field review: needed or not.
  2. Accuracy: how errors are corrected.
  3. Retention: which schedule applies.
  4. Security: who can access.
  5. Contact: published on the portal.
  6. Accountability: a named officer.
Evidence to keep
  • Standards checklist per scheme
  • Correction process
  • Retention schedule
Common mistakes
  • Treating standards as a formality
  • No correction route
  • No named officer
Related questions

Must a ministry delete data when a citizen asks?

Short answer: No, but correction and security still apply

No. Section 17(4) says the erasure duty in Section 8(7) and the erasure right in Section 12(3) do not apply to processing by the State. Retention follows public records rules and schedules. Correction rights and all other duties, including security and breach reporting, still apply.

From your seat: Data protection nodal officer. Use this in replies to erasure requests.
What the law says

Section 17(4) lifts DPDP erasure for the State. Public records rules govern destruction. Section 8(7) · Rule 8 · Sections 11–14 · Rule 14 · Section 8(3)

Steps
  1. Apply record retention schedules.
  2. Correct errors when asked.
  3. Tell the citizen why data is kept.
  4. Destroy records as the schedule allows.
  5. Keep access limited while records are kept.
Evidence to keep
  • Retention schedule
  • Correction log
  • Destruction register
Common mistakes
  • Thinking no duties apply
  • Ignoring correction requests
  • Keeping open access to old records
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Data protection nodal officer. You own the wording and the version history. Keep a folder with every live notice, its date and who approved it; that folder is usually the first thing an auditor asks for.
In Central government

A scheme portal should show what data is collected, why, and a contact for questions and corrections, even where consent is not the basis.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your citizens and beneficiaries actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: Data protection nodal officer. Requests land with you even when the data sits with other teams. Agree a turnaround with each system owner in advance, so you are not chasing people on day 25.
In Central government

A beneficiary can ask what the department holds and who it was shared with, such as states and banks.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

From your seat: Data protection nodal officer. Count the days yourself. A short monthly note to management with open complaints and their age keeps the 90-day limit visible.
In Central government

Data complaints often arrive through CPGRAMS or the scheme helpline. Tag them.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: Data protection nodal officer. Draft the schedule, but get Legal and each department head to sign their rows. Your role is to make sure deletion actually happens.
In Central government

Record retention schedules under public records rules decide periods.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Data protection nodal officer. Ask every team, not only marketing. Dependants, interns, scholarship applicants and visitors are where children's data usually hides.
In Central government

Scholarship, nutrition and school schemes involve children; Fourth Schedule exemptions may apply to some purposes.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Data protection nodal officer. You decide whether people and the Data Protection Board must be told, so you must be on the first call, not informed the next morning.
In Central government

A leaked beneficiary list is a breach; CERT-In and the Data Protection Board both need to hear.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for central government: ministries and departments.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 7(b) and 7(c) with Rule 5 and the Second ScheduleThe State may process personal data without consent to provide a subsidy, benefit, service, certificate, licence or permit, and to perform functions under law. Rule 5 asks that this processing follow the Second Schedule standards: lawful, for the stated use, limited to necessary data, accurate, kept only as long as needed, secured, and with a contact for questions and rights.Consent is not the basis for most scheme work. The standards are, and they need evidence.MeitY
DPDP Act, Section 17(4)For processing by the State, Section 8(7) (erasure) and Section 12(3) (erasure on request) do not apply, and where no decision affecting the person is made, Section 12(2) does not apply either.Retention follows public records rules rather than DPDP erasure. Security, accuracy, breach reporting and grievance duties still apply.MeitY
DPDP Act, Section 17(2)The Central Government may exempt notified instrumentalities for sovereignty, security, public order and related interests, and processing for research, archiving or statistics that does not lead to decisions about individuals.An exemption applies only if notified. Do not assume it.MeitY
RTI Act, Section 8(1)(j), as amended by DPDP Section 44(3) (in force 13 November 2025)Personal information is now exempt from disclosure under RTI, without the earlier public-interest test.Train CPIOs on the new wording; the amendment is being challenged before the Supreme Court, so watch for changes.SFLC.in summary
Public Records Act, 1993 and Public Records Rules, 1997Central government records may be destroyed only under approved record retention schedules.Erasure of personal data in files follows these schedules, since Section 17(4) lifts DPDP erasure for the State.National Archives of India
Aadhaar Act, 2016Section 7 allows Aadhaar for subsidies and benefits. Section 29 limits sharing of Aadhaar numbers and core biometric information. UIDAI asks entities storing Aadhaar numbers to keep them in an Aadhaar Data Vault.Scheme systems should store Aadhaar numbers only in a vault and show them masked.UIDAI
CERT-In Directions, 2022 and IT Act Section 70Report cyber incidents within six hours; keep ICT logs 180 days in India. Systems declared as protected systems under Section 70 come under NCIIPC.Ministries and their portals follow these in addition to DPDP.CERT-In
MeitY Email Policy and IT resources policy for GovernmentOfficial communication should use government email and approved resources.Personal email and chat apps for files with citizen data break both these policies and DPDP safeguards.MeitY
Guidelines for Indian Government Websites (GIGW)Government websites must carry standard policies, including a privacy policy.Update website privacy policies to DPDP notice standards with the contact person.MeitY / NIC
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.