InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Practical examples

Central government: ministries and departments

Practical examples for Central government

Five documents most organisations in this sector need before 13 May 2027.

Examples to adapt, not legal advice. Replace the text in square brackets with your own details.

EXAMPLE · NOT LEGAL ADVICE

Notice wording: Scheme application portal

The [Department] collects your name, address, Aadhaar (stored in a secure vault and shown masked), bank account and eligibility details to decide and pay your benefit under the [Scheme], as provided under [law or guideline]. This is done under Section 7(b) of the Digital Personal Data Protection Act, 2023.

Your details are shared only with [State department, bank, NPCI] to verify eligibility and make payment. They are kept as the records rules of the Government of India require.

For questions, to see what we hold or to correct your details, contact [nodal officer, email, phone]. If you are not satisfied, you may approach the Data Protection Board of India.

EXAMPLE

Request and complaint log

RefDateCitizen IDRequestSchemeOwnerDueStatus
DP-009102-11-2026verifiedCorrect nameScheme AScheme cellwithin published periodCorrected day 5
DP-009203-11-2026verifiedWhat is held and sharedScheme BNodal officerwithin published periodReplied day 8
DP-009305-11-2026verifiedDelete my dataScheme ANodal officerwithin published periodKept under records rules; explained
EXAMPLE · NOT LEGAL ADVICE

Retention schedule

RecordKeep forWhy
Beneficiary recordsAs the department's record retention schedule saysPublic Records Act and Rules
Applications not approvedAs per schedule, usually shortPurpose over
Grievance recordsAs per scheduleRecords rules
Service records of staffAs service and pension rules requireEstablishment rules
Access and activity logsAt least 1 year; ICT logs 180 days in IndiaDPDP Rules; CERT-In
EXAMPLE · NOT LEGAL ADVICE

Vendor data clause

The System Integrator shall process personal data only for the purposes of the [Scheme] as instructed by the Department, and shall not use it for any other purpose. It shall host data only in India, shall give administrative access only to named personnel with multi-factor sign-in and logging, shall not engage any sub-contractor without written approval, and shall keep reasonable security safeguards as required by the Digital Personal Data Protection Act, 2023 and CERT-In directions. It shall inform the Department of any incident within [6] hours. On completion or termination, it shall hand over all data and delete its copies, with a certificate.

EXAMPLE · NOT LEGAL ADVICE

Breach notice to affected people

Dear beneficiary, on [date] we found that a list containing your name, village and benefit amount was visible on a public web page for [period]. Your Aadhaar and bank details were not part of the list. The page has been removed and we have informed CERT-In and the Data Protection Board. No action is needed from you. Please do not share OTPs with anyone claiming to be from the department. For questions, contact [nodal officer, phone, email].

Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.