DPDP Insights › Central government: ministries and departments › Practical examples
Five documents most organisations in this sector need before 13 May 2027.
Examples to adapt, not legal advice. Replace the text in square brackets with your own details.
The [Department] collects your name, address, Aadhaar (stored in a secure vault and shown masked), bank account and eligibility details to decide and pay your benefit under the [Scheme], as provided under [law or guideline]. This is done under Section 7(b) of the Digital Personal Data Protection Act, 2023.
Your details are shared only with [State department, bank, NPCI] to verify eligibility and make payment. They are kept as the records rules of the Government of India require.
For questions, to see what we hold or to correct your details, contact [nodal officer, email, phone]. If you are not satisfied, you may approach the Data Protection Board of India.
| Ref | Date | Citizen ID | Request | Scheme | Owner | Due | Status |
|---|---|---|---|---|---|---|---|
| DP-0091 | 02-11-2026 | verified | Correct name | Scheme A | Scheme cell | within published period | Corrected day 5 |
| DP-0092 | 03-11-2026 | verified | What is held and shared | Scheme B | Nodal officer | within published period | Replied day 8 |
| DP-0093 | 05-11-2026 | verified | Delete my data | Scheme A | Nodal officer | within published period | Kept under records rules; explained |
| Record | Keep for | Why |
|---|---|---|
| Beneficiary records | As the department's record retention schedule says | Public Records Act and Rules |
| Applications not approved | As per schedule, usually short | Purpose over |
| Grievance records | As per schedule | Records rules |
| Service records of staff | As service and pension rules require | Establishment rules |
| Access and activity logs | At least 1 year; ICT logs 180 days in India | DPDP Rules; CERT-In |
The System Integrator shall process personal data only for the purposes of the [Scheme] as instructed by the Department, and shall not use it for any other purpose. It shall host data only in India, shall give administrative access only to named personnel with multi-factor sign-in and logging, shall not engage any sub-contractor without written approval, and shall keep reasonable security safeguards as required by the Digital Personal Data Protection Act, 2023 and CERT-In directions. It shall inform the Department of any incident within [6] hours. On completion or termination, it shall hand over all data and delete its copies, with a certificate.
Dear beneficiary, on [date] we found that a list containing your name, village and benefit amount was visible on a public web page for [period]. Your Aadhaar and bank details were not part of the list. The page has been removed and we have informed CERT-In and the Data Protection Board. No action is needed from you. Please do not share OTPs with anyone claiming to be from the department. For questions, contact [nodal officer, phone, email].