InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Office head / Section officer

Central government: ministries and departments

DPDP for the Office head / Section officer in Central government

Offices still run on files, registers and counters as well as portals.

Open this seat in the interactive tool

What is different here

Applications, ID copies and grievance letters sit in files and cupboards. Inward registers record names and addresses. All of this is personal data.

The first four things to sort out

  1. Lock cupboards with personal files.
  2. Stop sharing files on personal WhatsApp.
  3. Shred spare photocopies.
  4. Log citizen requests about their data.

A worked example: A file with ID copies goes missing

  1. Day 1A section officer cannot find a file with 40 applicants' ID copies.
  2. Day 2The search fails; the nodal officer is told.
  3. Day 3Applicants are informed and a breach record is made.
  4. AfterSpare copies are no longer kept; files move to e-Office.

Evidence kept: Missing file report; Breach record; Change.

Paper losses are breaches too.

What others in the sector usually do. Offices moving to e-Office are cutting paper copies of ID documents.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Ministry of Ports, Shipping and Waterways and its officesPort entry passes with ID copies held by many parties; Seafarer records shared with training institutes and agencies; Terminal operator systems outside the ministry's direct control
Ministry of Road Transport and Highways and its officesBulk or API access by private entities; Accident and challan data; Toll and FASTag transaction data with vendors
Ministry of Chemicals and Fertilizers and its departmentsAadhaar authentication at retailer PoS devices; Farmer purchase data visible to companies and dealers; Kendra operators holding prescriptions and customer details
Other line ministries and departmentsBeneficiary lists published or shared in spreadsheets; System integrators with admin access; Grievance records with personal details
Citizen portals and DBT schemesAadhaar numbers stored outside a data vault; Bulk beneficiary data sent to states by email; Dashboards showing names and amounts publicly
Regulators and statutory bodiesOrders and filings published with personal details; Complaint data shared with regulated entities; Investigation files on shared drives

9 guides for the Office head / Section officer, in full

How does the RTI amendment change replies about personal information?

Short answer: Personal information is exempt; give reasoned orders

DPDP Section 44(3), in force from 13 November 2025, amended RTI Section 8(1)(j). Personal information is now exempt from disclosure without the earlier public-interest test. The amendment is under challenge in the Supreme Court, so CPIOs should apply it carefully and keep reasoned orders.

From your seat: Office head / Section officer. Inward sections pass RTI files to CPIOs quickly.
What the law says

RTI Act Section 8(1)(j) as amended by DPDP Section 44(3). Section 7

Steps
  1. Brief all CPIOs on the new wording.
  2. Separate personal from non-personal parts of records.
  3. Give the non-personal parts.
  4. Record reasons for each exemption.
  5. Watch for the Supreme Court's decision.
Evidence to keep
  • CPIO briefing
  • Reasoned orders
Common mistakes
  • Refusing whole files when only parts are personal
  • No reasons in the order
  • Ignoring pending litigation
Related questions

Must a ministry delete data when a citizen asks?

Short answer: No, but correction and security still apply

No. Section 17(4) says the erasure duty in Section 8(7) and the erasure right in Section 12(3) do not apply to processing by the State. Retention follows public records rules and schedules. Correction rights and all other duties, including security and breach reporting, still apply.

What the law says

Section 17(4) lifts DPDP erasure for the State. Public records rules govern destruction. Section 8(7) · Rule 8 · Sections 11–14 · Rule 14 · Section 8(3)

Steps
  1. Apply record retention schedules.
  2. Correct errors when asked.
  3. Tell the citizen why data is kept.
  4. Destroy records as the schedule allows.
  5. Keep access limited while records are kept.
Evidence to keep
  • Retention schedule
  • Correction log
  • Destruction register
Common mistakes
  • Thinking no duties apply
  • Ignoring correction requests
  • Keeping open access to old records
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Office head / Section officer. Your counters, forms and call scripts are where notices are actually seen. Check that each one shows the current version.
In Central government

A scheme portal should show what data is collected, why, and a contact for questions and corrections, even where consent is not the basis.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your citizens and beneficiaries actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: Office head / Section officer. Front-line staff receive most requests. Teach them to log the request and pass it on the same day, not to answer it themselves.
In Central government

A beneficiary can ask what the department holds and who it was shared with, such as states and banks.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

From your seat: Office head / Section officer. Many complaints start as service complaints. Tag the ones about personal data so they enter the privacy log.
In Central government

Data complaints often arrive through CPGRAMS or the scheme helpline. Tag them.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: Office head / Section officer. Shift groups and vendor chats are where data leaks. Give supervisors an approved way to share lists and photos.
In Central government

Government email and e-Office are the approved routes; WhatsApp groups are not.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: Office head / Section officer. Check notices at entrances and recording areas, and who on site can view footage.
In Central government

Office CCTV and visitor passes need notices and limits.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

What about call recordings and customer service screens?

Short answer: Yes, with notice, a retention period and masking

Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.

From your seat: Office head / Section officer. Call scripts need a recording notice, and agents need to know when to pause the recording.
In Central government

Helpline recordings need a notice and a retention period.

What the law says

Section 5 needs notice, Section 8(5) needs safeguards, and Section 8(7) needs erasure after the purpose. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. Play a short recording notice at the start of calls.
  2. Set a retention period by call type.
  3. Pause recording when card or other sensitive details are given.
  4. Limit replay rights to quality and complaint teams.
  5. Lock agent screens and stop phones on the floor if data is sensitive.
Evidence to keep
  • Recording notice script
  • Retention settings
  • Replay access list
Common mistakes
  • Recordings kept indefinitely
  • Card numbers in recordings
  • Open replay access for all supervisors
Related questions

Someone asks us to delete their data. Must we?

Short answer: Yes, unless a law requires you to keep it

You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.

From your seat: Office head / Section officer. Front-line teams need a simple answer for 'delete my data': log it, pass it on, and explain the timeline.
In Central government

Section 17(4) lifts DPDP erasure for the State; public records schedules apply.

What the law says

Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. Log the request and verify identity.
  2. Check the retention schedule for each record type involved.
  3. Delete what has no legal reason to stay, including copies with vendors and in test systems.
  4. Mark what must stay, with the law and the end date.
  5. Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
  • Erasure log
  • Vendor deletion confirmations
  • Reply to the person
Common mistakes
  • Refusing every erasure request 'because of backups'
  • Deleting records a law requires
  • Not telling vendors
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for central government: ministries and departments.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 7(b) and 7(c) with Rule 5 and the Second ScheduleThe State may process personal data without consent to provide a subsidy, benefit, service, certificate, licence or permit, and to perform functions under law. Rule 5 asks that this processing follow the Second Schedule standards: lawful, for the stated use, limited to necessary data, accurate, kept only as long as needed, secured, and with a contact for questions and rights.Consent is not the basis for most scheme work. The standards are, and they need evidence.MeitY
DPDP Act, Section 17(4)For processing by the State, Section 8(7) (erasure) and Section 12(3) (erasure on request) do not apply, and where no decision affecting the person is made, Section 12(2) does not apply either.Retention follows public records rules rather than DPDP erasure. Security, accuracy, breach reporting and grievance duties still apply.MeitY
DPDP Act, Section 17(2)The Central Government may exempt notified instrumentalities for sovereignty, security, public order and related interests, and processing for research, archiving or statistics that does not lead to decisions about individuals.An exemption applies only if notified. Do not assume it.MeitY
RTI Act, Section 8(1)(j), as amended by DPDP Section 44(3) (in force 13 November 2025)Personal information is now exempt from disclosure under RTI, without the earlier public-interest test.Train CPIOs on the new wording; the amendment is being challenged before the Supreme Court, so watch for changes.SFLC.in summary
Public Records Act, 1993 and Public Records Rules, 1997Central government records may be destroyed only under approved record retention schedules.Erasure of personal data in files follows these schedules, since Section 17(4) lifts DPDP erasure for the State.National Archives of India
Aadhaar Act, 2016Section 7 allows Aadhaar for subsidies and benefits. Section 29 limits sharing of Aadhaar numbers and core biometric information. UIDAI asks entities storing Aadhaar numbers to keep them in an Aadhaar Data Vault.Scheme systems should store Aadhaar numbers only in a vault and show them masked.UIDAI
CERT-In Directions, 2022 and IT Act Section 70Report cyber incidents within six hours; keep ICT logs 180 days in India. Systems declared as protected systems under Section 70 come under NCIIPC.Ministries and their portals follow these in addition to DPDP.CERT-In
MeitY Email Policy and IT resources policy for GovernmentOfficial communication should use government email and approved resources.Personal email and chat apps for files with citizen data break both these policies and DPDP safeguards.MeitY
Guidelines for Indian Government Websites (GIGW)Government websites must carry standard policies, including a privacy policy.Update website privacy policies to DPDP notice standards with the contact person.MeitY / NIC
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.