DPDP for a Ministry of Ports, Shipping and Waterways and its offices
Seafarer records, port entry passes, crew lists and passenger data flow between the ministry, port authorities, DG Shipping and private terminal operators. Port systems are also likely to be critical information infrastructure, so security sits under closer watch.
Seafarers, port users, pass holders, crew and passengers. You work with port authorities, DG Shipping, terminal operators and system integrators.
Where it usually goes wrong
Port entry passes with ID copies held by many parties
Seafarer records shared with training institutes and agencies
Terminal operator systems outside the ministry's direct control
Read it from your seat
Data protection nodal officerIn a ministry, you are often the first officer to look at personal data as something the department owes duties on, not just files it holds.
CISOMinistry portals and scheme systems are high-value targets, and many are run by system integrators.
IT head / NIC coordinatorYou run or oversee systems that hold data for crores of people, often through NIC and integrators.
Secretary / Head of DepartmentAs Secretary or Head of Department, you own the department's duty to citizens whose data it holds.
Oversight: AS / JS / boardIn oversight roles, your questions decide whether data protection gets attention among many priorities.
Establishment and administrationEstablishment sections hold service records, ACRs or APARs, medical and family details of officers and staff.
Legal cellThe legal cell decides which basis each scheme rests on and what contracts must say.
Short answer: Usually not; Section 7(b) or 7(c) with Rule 5 standards
Usually not. Section 7(b) allows the State to process personal data to give a subsidy, benefit, service, certificate, licence or permit, and Section 7(c) covers functions under law. Rule 5 then asks that this processing meet the Second Schedule standards. Consent is still needed for uses outside these, such as publicity stories or surveys not tied to the scheme.
What the law says
Section 7(b) and 7(c) set the bases. Rule 5 and the Second Schedule set the standards. Section 7 · Section 4
Steps
Write the basis for each scheme: 7(b), 7(c) or consent.
Check each scheme against the Second Schedule standards.
Short answer: Seven practical standards, each needing evidence
Process lawfully and only for the scheme's purpose, collect only the data needed, keep it accurate, keep it only as long as needed or required by law, protect it with reasonable safeguards, give people a contact for questions and rights, and be accountable for meeting these standards.
Short answer: No, but correction and security still apply
No. Section 17(4) says the erasure duty in Section 8(7) and the erasure right in Section 12(3) do not apply to processing by the State. Retention follows public records rules and schedules. Correction rights and all other duties, including security and breach reporting, still apply.
Short answer: Yes, at every point where you collect data
A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.
In Central government
A scheme portal should show what data is collected, why, and a contact for questions and corrections, even where consent is not the basis.
What the law says
Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14
Steps
List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
Write one short notice per collection point, with the data items and purpose side by side.
Add how to withdraw consent, how to make a request and the DPO or contact person's details.
Offer the notice in English and in the languages your citizens and beneficiaries actually use.
Keep each version with the date it went live.
Evidence to keep
Screenshots or copies of the notice at each collection point, with dates
Notice version history
Translations, where used
Common mistakes
Hiding the notice inside terms and conditions
One notice for everything, with no link between data items and purposes
Short answer: It depends on the use; most organisations need both
For every use of personal data you need one basis: consent, or one of the legitimate uses in Section 7, such as a legal duty, employment, a medical emergency, or data a person gave voluntarily for a specific purpose. Anything beyond what the person expects, such as marketing, profiling or sharing with partners, usually needs consent.
In Central government
Most scheme work rests on Section 7(b) or 7(c). Surveys, publicity and newsletters need consent.
What the law says
Section 4 allows processing only with consent or for a legitimate use. Section 6 sets what valid consent looks like. Section 7 lists the uses that need no consent. Section 4 · Section 6 · Section 7
Steps
List each purpose for which you use personal data.
Against each purpose, write the basis: consent or the exact clause of Section 7.
Where the basis is consent, check that it was asked separately, with a clear action and no pre-ticked box.
Stop or re-paper any purpose with no basis.
Review the list whenever a new product, campaign or system starts.
Evidence to keep
Purpose and basis register
Consent records with date, version and channel
Legal sign-off on each legitimate use relied on
Common mistakes
Treating account terms as consent for marketing
Bundling several purposes in one tick-box
Relying on 'legitimate interest', which the Indian Act does not have
Short answer: Yes, a clear summary, inside the published timeline
Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.
In Central government
A beneficiary can ask what the department holds and who it was shared with, such as states and banks.
What the law says
Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14
Steps
Log the request in one register the day it arrives.
Verify identity using details you already hold.
Search every system, including vendors' copies.
Write a plain summary: what data, why it is used, who received it.
Send it, and file the request, search notes and reply.