| DPDP Act, Section 7(b) and 7(c) with Rule 5 and the Second Schedule | The State may process personal data without consent to provide a subsidy, benefit, service, certificate, licence or permit, and to perform functions under law. Rule 5 asks that this processing follow the Second Schedule standards: lawful, for the stated use, limited to necessary data, accurate, kept only as long as needed, secured, and with a contact for questions and rights. | Consent is not the basis for most scheme work. The standards are, and they need evidence. | MeitY |
| DPDP Act, Section 17(4) | For processing by the State, Section 8(7) (erasure) and Section 12(3) (erasure on request) do not apply, and where no decision affecting the person is made, Section 12(2) does not apply either. | Retention follows public records rules rather than DPDP erasure. Security, accuracy, breach reporting and grievance duties still apply. | MeitY |
| DPDP Act, Section 17(2) | The Central Government may exempt notified instrumentalities for sovereignty, security, public order and related interests, and processing for research, archiving or statistics that does not lead to decisions about individuals. | An exemption applies only if notified. Do not assume it. | MeitY |
| RTI Act, Section 8(1)(j), as amended by DPDP Section 44(3) (in force 13 November 2025) | Personal information is now exempt from disclosure under RTI, without the earlier public-interest test. | Train CPIOs on the new wording; the amendment is being challenged before the Supreme Court, so watch for changes. | SFLC.in summary |
| Public Records Act, 1993 and Public Records Rules, 1997 | Central government records may be destroyed only under approved record retention schedules. | Erasure of personal data in files follows these schedules, since Section 17(4) lifts DPDP erasure for the State. | National Archives of India |
| Aadhaar Act, 2016 | Section 7 allows Aadhaar for subsidies and benefits. Section 29 limits sharing of Aadhaar numbers and core biometric information. UIDAI asks entities storing Aadhaar numbers to keep them in an Aadhaar Data Vault. | Scheme systems should store Aadhaar numbers only in a vault and show them masked. | UIDAI |
| CERT-In Directions, 2022 and IT Act Section 70 | Report cyber incidents within six hours; keep ICT logs 180 days in India. Systems declared as protected systems under Section 70 come under NCIIPC. | Ministries and their portals follow these in addition to DPDP. | CERT-In |
| MeitY Email Policy and IT resources policy for Government | Official communication should use government email and approved resources. | Personal email and chat apps for files with citizen data break both these policies and DPDP safeguards. | MeitY |
| Guidelines for Indian Government Websites (GIGW) | Government websites must carry standard policies, including a privacy policy. | Update website privacy policies to DPDP notice standards with the contact person. | MeitY / NIC |