InfraVeritas360DPDPiq

DPDP Insights › Central government: ministries and departments › Ministry of Chemicals and Fertilizers and its departments

Central government: ministries and departments

DPDP for a Ministry of Chemicals and Fertilizers and its departments

Subsidised fertiliser is sold through Aadhaar-enabled PoS devices at retailers, and every sale is captured in iFMS. That links farmer identity, land and purchase data across the department, companies and lakhs of retailers. The Department of Pharmaceuticals also runs Jan Aushadhi Kendras through private operators.

Read it from your seat in the tool

Whose data you hold

Farmers buying fertiliser, jan aushadhi customers, retailers and dealers. You work with fertiliser companies, retailers with PoS devices, Jan Aushadhi Kendra operators and NIC.

Where it usually goes wrong

  1. Aadhaar authentication at retailer PoS devices
  2. Farmer purchase data visible to companies and dealers
  3. Kendra operators holding prescriptions and customer details

Read it from your seat

Questions that come up first

Do we need citizens' consent to run a scheme?

Short answer: Usually not; Section 7(b) or 7(c) with Rule 5 standards

Usually not. Section 7(b) allows the State to process personal data to give a subsidy, benefit, service, certificate, licence or permit, and Section 7(c) covers functions under law. Rule 5 then asks that this processing meet the Second Schedule standards. Consent is still needed for uses outside these, such as publicity stories or surveys not tied to the scheme.

What the law says

Section 7(b) and 7(c) set the bases. Rule 5 and the Second Schedule set the standards. Section 7 · Section 4

Steps
  1. Write the basis for each scheme: 7(b), 7(c) or consent.
  2. Check each scheme against the Second Schedule standards.
  3. Remove fields not needed for the benefit.
  4. Publish a contact for questions and rights.
  5. Take consent for extra uses.
Evidence to keep
  • Basis register
  • Standards check
  • Published contact
Common mistakes
  • Taking 'consent' that citizens cannot refuse
  • Collecting extra fields 'for analysis'
  • No contact for questions
Related questions

What do the Second Schedule standards ask of a scheme?

Short answer: Seven practical standards, each needing evidence

Process lawfully and only for the scheme's purpose, collect only the data needed, keep it accurate, keep it only as long as needed or required by law, protect it with reasonable safeguards, give people a contact for questions and rights, and be accountable for meeting these standards.

What the law says

Rule 5 and the Second Schedule apply to State processing under Section 7(b). Section 7 · Section 8(5) · Rule 6 · Section 8(3)

Steps
  1. Field review: needed or not.
  2. Accuracy: how errors are corrected.
  3. Retention: which schedule applies.
  4. Security: who can access.
  5. Contact: published on the portal.
  6. Accountability: a named officer.
Evidence to keep
  • Standards checklist per scheme
  • Correction process
  • Retention schedule
Common mistakes
  • Treating standards as a formality
  • No correction route
  • No named officer
Related questions

Must a ministry delete data when a citizen asks?

Short answer: No, but correction and security still apply

No. Section 17(4) says the erasure duty in Section 8(7) and the erasure right in Section 12(3) do not apply to processing by the State. Retention follows public records rules and schedules. Correction rights and all other duties, including security and breach reporting, still apply.

What the law says

Section 17(4) lifts DPDP erasure for the State. Public records rules govern destruction. Section 8(7) · Rule 8 · Sections 11–14 · Rule 14 · Section 8(3)

Steps
  1. Apply record retention schedules.
  2. Correct errors when asked.
  3. Tell the citizen why data is kept.
  4. Destroy records as the schedule allows.
  5. Keep access limited while records are kept.
Evidence to keep
  • Retention schedule
  • Correction log
  • Destruction register
Common mistakes
  • Thinking no duties apply
  • Ignoring correction requests
  • Keeping open access to old records
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

In Central government

A scheme portal should show what data is collected, why, and a contact for questions and corrections, even where consent is not the basis.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your citizens and beneficiaries actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

In Central government

A beneficiary can ask what the department holds and who it was shared with, such as states and banks.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.