InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Legal cell

Central government: ministries and departments

DPDP for the Legal cell in Central government

The legal cell decides which basis each scheme rests on and what contracts must say.

Open this seat in the interactive tool

What is different here

You must read DPDP alongside the scheme's own law or guidelines, the Aadhaar Act, the RTI amendment and public records rules.

The first four things to sort out

  1. Record the legal basis for each scheme.
  2. Add DPDP processor terms to integrator and MoU templates.
  3. Brief CPIOs on the amended Section 8(1)(j).
  4. Check whether any Section 17(2) exemption is notified for your bodies.

A worked example: An integrator contract comes up for renewal

  1. Week 1The legal cell finds no data protection terms.
  2. Week 2A schedule is added: purpose, security, admin access, six-hour incident notice, no sub-contracting without approval, data return.
  3. Week 4The integrator signs.
  4. AfterThe schedule becomes the template for all contracts.

Evidence kept: Contract schedule; Template.

Renewal is the moment to fix contracts.

What others in the sector usually do. Legal cells are preparing a model data schedule for all integrator contracts.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Ministry of Ports, Shipping and Waterways and its officesPort entry passes with ID copies held by many parties; Seafarer records shared with training institutes and agencies; Terminal operator systems outside the ministry's direct control
Ministry of Road Transport and Highways and its officesBulk or API access by private entities; Accident and challan data; Toll and FASTag transaction data with vendors
Ministry of Chemicals and Fertilizers and its departmentsAadhaar authentication at retailer PoS devices; Farmer purchase data visible to companies and dealers; Kendra operators holding prescriptions and customer details
Other line ministries and departmentsBeneficiary lists published or shared in spreadsheets; System integrators with admin access; Grievance records with personal details
Citizen portals and DBT schemesAadhaar numbers stored outside a data vault; Bulk beneficiary data sent to states by email; Dashboards showing names and amounts publicly
Regulators and statutory bodiesOrders and filings published with personal details; Complaint data shared with regulated entities; Investigation files on shared drives

10 guides for the Legal cell, in full

Do we need citizens' consent to run a scheme?

Short answer: Usually not; Section 7(b) or 7(c) with Rule 5 standards

Usually not. Section 7(b) allows the State to process personal data to give a subsidy, benefit, service, certificate, licence or permit, and Section 7(c) covers functions under law. Rule 5 then asks that this processing meet the Second Schedule standards. Consent is still needed for uses outside these, such as publicity stories or surveys not tied to the scheme.

From your seat: Legal cell. Write the basis with the scheme's own law or guidelines.
What the law says

Section 7(b) and 7(c) set the bases. Rule 5 and the Second Schedule set the standards. Section 7 · Section 4

Steps
  1. Write the basis for each scheme: 7(b), 7(c) or consent.
  2. Check each scheme against the Second Schedule standards.
  3. Remove fields not needed for the benefit.
  4. Publish a contact for questions and rights.
  5. Take consent for extra uses.
Evidence to keep
  • Basis register
  • Standards check
  • Published contact
Common mistakes
  • Taking 'consent' that citizens cannot refuse
  • Collecting extra fields 'for analysis'
  • No contact for questions
Related questions

Must a ministry delete data when a citizen asks?

Short answer: No, but correction and security still apply

No. Section 17(4) says the erasure duty in Section 8(7) and the erasure right in Section 12(3) do not apply to processing by the State. Retention follows public records rules and schedules. Correction rights and all other duties, including security and breach reporting, still apply.

From your seat: Legal cell. Confirm the schedules that apply.
What the law says

Section 17(4) lifts DPDP erasure for the State. Public records rules govern destruction. Section 8(7) · Rule 8 · Sections 11–14 · Rule 14 · Section 8(3)

Steps
  1. Apply record retention schedules.
  2. Correct errors when asked.
  3. Tell the citizen why data is kept.
  4. Destroy records as the schedule allows.
  5. Keep access limited while records are kept.
Evidence to keep
  • Retention schedule
  • Correction log
  • Destruction register
Common mistakes
  • Thinking no duties apply
  • Ignoring correction requests
  • Keeping open access to old records
Related questions

How does the RTI amendment change replies about personal information?

Short answer: Personal information is exempt; give reasoned orders

DPDP Section 44(3), in force from 13 November 2025, amended RTI Section 8(1)(j). Personal information is now exempt from disclosure without the earlier public-interest test. The amendment is under challenge in the Supreme Court, so CPIOs should apply it carefully and keep reasoned orders.

From your seat: Legal cell. Brief CPIOs and track the litigation.
What the law says

RTI Act Section 8(1)(j) as amended by DPDP Section 44(3). Section 7

Steps
  1. Brief all CPIOs on the new wording.
  2. Separate personal from non-personal parts of records.
  3. Give the non-personal parts.
  4. Record reasons for each exemption.
  5. Watch for the Supreme Court's decision.
Evidence to keep
  • CPIO briefing
  • Reasoned orders
Common mistakes
  • Refusing whole files when only parts are personal
  • No reasons in the order
  • Ignoring pending litigation
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Legal cell. Approve the wording and keep it simple. A notice a regulator can read in two minutes is better than a complete one nobody reads.
In Central government

A scheme portal should show what data is collected, why, and a contact for questions and corrections, even where consent is not the basis.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your citizens and beneficiaries actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Legal cell. Draft one data-protection schedule and use it for every contract that involves personal data.
In Central government

System integrators, NIC, state agencies and field operators process data for the department.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Are we a Data Fiduciary or a Data Processor?

Short answer: Often both, for different data

You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.

From your seat: Legal cell. Check that contracts match the real role. Calling a vendor a processor while it uses data for its own purposes will not hold.
In Central government

The department is usually the fiduciary; integrators are processors.

What the law says

Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract. Section 8(1)–(2) · Section 17(1)(d)

Steps
  1. List each data set you handle.
  2. For each, ask: who decides the purpose?
  3. Mark yourself as fiduciary or processor, and name the other party.
  4. Check that contracts match the role.
  5. Route requests about processor data to the fiduciary.
Evidence to keep
  • Role register by data set
  • Contracts matching the role
Common mistakes
  • Calling yourself a processor for data you use for your own purposes
  • No contract when you act as processor
  • Answering requests that belong to your client
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Legal cell. Advise on whether a Fourth Schedule exemption applies to each purpose, and write the reasoning down.
In Central government

Scholarship, nutrition and school schemes involve children; Fourth Schedule exemptions may apply to some purposes.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

Police, a court or a regulator asks for someone's data. What do we do?

Short answer: Yes, when the request is lawful and in writing

Check that the request is in writing, comes from the right authority and cites the legal power. Share only what is asked for, record what you sent and to whom, and keep the request on file. The Act allows processing to meet a legal duty, but it does not mean sharing everything on a phone call.

From your seat: Legal cell. Own the authority request log. Check the legal power every time, even for familiar requesters.
In Central government

Requests from other agencies need a written basis and a log.

What the law says

Section 7(d) and 7(e) allow processing to meet a legal duty to disclose to the State, or to comply with a judgment or order. Section 17(1)(c) exempts processing for preventing, detecting or investigating offences. Section 7 · Section 8(5) · Rule 6

Steps
  1. Route every such request to Legal.
  2. Check the authority, the legal power and the scope.
  3. Share only what is asked, by a secure method.
  4. Log the request, what was sent, by whom and when.
  5. Tell the person, unless the law or the authority says you must not.
Evidence to keep
  • Authority request log
  • Copies of requests
  • Record of what was sent
Common mistakes
  • Sharing on a phone call
  • Sending whole files when a few lines were asked
  • No log
Related questions

Someone asks us to delete their data. Must we?

Short answer: Yes, unless a law requires you to keep it

You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.

From your seat: Legal cell. Approve the list of laws that require retention, so front-line teams can explain refusals correctly.
In Central government

Section 17(4) lifts DPDP erasure for the State; public records schedules apply.

What the law says

Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. Log the request and verify identity.
  2. Check the retention schedule for each record type involved.
  3. Delete what has no legal reason to stay, including copies with vendors and in test systems.
  4. Mark what must stay, with the law and the end date.
  5. Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
  • Erasure log
  • Vendor deletion confirmations
  • Reply to the person
Common mistakes
  • Refusing every erasure request 'because of backups'
  • Deleting records a law requires
  • Not telling vendors
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for central government: ministries and departments.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 7(b) and 7(c) with Rule 5 and the Second ScheduleThe State may process personal data without consent to provide a subsidy, benefit, service, certificate, licence or permit, and to perform functions under law. Rule 5 asks that this processing follow the Second Schedule standards: lawful, for the stated use, limited to necessary data, accurate, kept only as long as needed, secured, and with a contact for questions and rights.Consent is not the basis for most scheme work. The standards are, and they need evidence.MeitY
DPDP Act, Section 17(4)For processing by the State, Section 8(7) (erasure) and Section 12(3) (erasure on request) do not apply, and where no decision affecting the person is made, Section 12(2) does not apply either.Retention follows public records rules rather than DPDP erasure. Security, accuracy, breach reporting and grievance duties still apply.MeitY
DPDP Act, Section 17(2)The Central Government may exempt notified instrumentalities for sovereignty, security, public order and related interests, and processing for research, archiving or statistics that does not lead to decisions about individuals.An exemption applies only if notified. Do not assume it.MeitY
RTI Act, Section 8(1)(j), as amended by DPDP Section 44(3) (in force 13 November 2025)Personal information is now exempt from disclosure under RTI, without the earlier public-interest test.Train CPIOs on the new wording; the amendment is being challenged before the Supreme Court, so watch for changes.SFLC.in summary
Public Records Act, 1993 and Public Records Rules, 1997Central government records may be destroyed only under approved record retention schedules.Erasure of personal data in files follows these schedules, since Section 17(4) lifts DPDP erasure for the State.National Archives of India
Aadhaar Act, 2016Section 7 allows Aadhaar for subsidies and benefits. Section 29 limits sharing of Aadhaar numbers and core biometric information. UIDAI asks entities storing Aadhaar numbers to keep them in an Aadhaar Data Vault.Scheme systems should store Aadhaar numbers only in a vault and show them masked.UIDAI
CERT-In Directions, 2022 and IT Act Section 70Report cyber incidents within six hours; keep ICT logs 180 days in India. Systems declared as protected systems under Section 70 come under NCIIPC.Ministries and their portals follow these in addition to DPDP.CERT-In
MeitY Email Policy and IT resources policy for GovernmentOfficial communication should use government email and approved resources.Personal email and chat apps for files with citizen data break both these policies and DPDP safeguards.MeitY
Guidelines for Indian Government Websites (GIGW)Government websites must carry standard policies, including a privacy policy.Update website privacy policies to DPDP notice standards with the contact person.MeitY / NIC
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.