Distributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Short answer: Yes, you are responsible for what they do with your consumers' data
When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.
From your seat: Chief risk officer. Rate partners by data volume.
Short answer: Possibly, for some activities; get a written legal view
The DPDP Act uses the Article 12 meaning of 'State'. Many PSUs have been treated as the State by courts, depending on how deeply the government controls them. If you are, Section 7(b) and 7(c) and Section 17(4) may apply to public functions, but not automatically to commercial customer-facing work. Write an activity-wise legal view and keep the State provisions narrow.
What the law says
Section 2(x) defines State by reference to Article 12. Sections 7(b), 7(c) and 17(4) apply to the State. Section 7 · Section 8(7) · Rule 8
Steps
List activities: public functions, schemes, commercial sales.
Short answer: One line per duty, with owner and evidence
Turn each duty into a risk line with an owner, a control, evidence and a review date. Map controls you already run for your regulator, auditors or certifications, so the same evidence serves several purposes. Track vendor risk separately.
From your seat: Chief risk officer. Split DPDP into separate duties. One line called 'DPDP compliance' hides where the risk actually is.
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
From your seat: Chief risk officer. Map every reporting clock that applies to you on one page: CERT-In, your regulator and the Data Protection Board.
In PSUs and utilities
A leaked consumer list from a distributor is your breach to report.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: Chief risk officer. Vendor risk is usually the largest single item. Track the top vendors as separate risk lines.
In PSUs and utilities
Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.
Short answer: Only by notification; none notified yet
Only the government can notify an organisation or a class of organisations as a Significant Data Fiduciary, based on the volume and sensitivity of data and the risk to people or the State. None had been notified when this page was last reviewed. Large holders of sensitive data should plan as if it could happen.
From your seat: Chief risk officer. Keep notification as a scenario in the register, with a trigger and an owner.
In PSUs and utilities
Large consumer-facing PSUs are natural candidates.
What the law says
Section 10 and Rule 13 set the extra duties: a DPO in India, an independent data auditor, a yearly Data Protection Impact Assessment and audit, and checks on algorithms. Rule 13(4) allows the government to restrict some data from leaving India. Section 10 · Rule 13 · Section 16 · Rule 15
Steps
Estimate how many people's data you hold and how sensitive it is.
Note any public or security role your data plays.
If you are a likely candidate, run a trial impact assessment this year.
Short answer: Yes, unless a sector rule says otherwise
Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.
From your seat: Chief risk officer. Record every system or support team outside India, and check each against sector localisation rules.
In PSUs and utilities
Check vendor support access from abroad, especially for smart-meter and ticketing platforms.
What the law says
Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)
Steps
List where each system is hosted and where support teams log in from.
Check sector rules for localisation.
Put location and access terms in cloud and vendor contracts.
Keep the list current; new SaaS tools change it quietly.
Short answer: They cover security, not the whole Act
They help a great deal with the security part. ISO/IEC 27001 and NIST CSF 2.0 are good evidence of reasonable security safeguards. They do not cover notice, consent, rights, complaints or children's data. ISO/IEC 27701 adds privacy controls, but no certificate replaces the Act.
From your seat: Chief risk officer. Use existing certifications as evidence, but record the DPDP duties they do not cover as their own risk lines.
In PSUs and utilities
CEA guidelines and ISO 27001 cover much of Rule 6.
What the law says
Section 8(5) and Rule 6 ask for reasonable security safeguards. A recognised standard is strong evidence of that duty, and only of that duty. Section 8(5) · Rule 6
Steps
Map your current controls to Rule 6.
Add the DPDP-only items: notice, consent, rights, complaints, children, retention.
Use the same evidence for audits and for DPDP.
Include privacy in the scope of your next internal audit.
Consider ISO/IEC 27701 if clients ask for it.
Evidence to keep
Control map
Audit reports
Gap list for DPDP-only items
Common mistakes
Treating a certificate as DPDP compliance
Scope that leaves out the systems with the most personal data
Short answer: Six to nine months of steady work for most
For most organisations it is a programme of six to nine months, not a single project. The heavy parts are the data inventory, vendor contracts, access control and the request process. Notices, the contact person and training are lighter. Starting now leaves time to fix what you find.
From your seat: Chief risk officer. Track the programme against dated milestones and report slippage early.
Section 10 · Rule 13: Significant Data Fiduciaries. Large consumer-facing PSUs are natural SDF candidates, though none had been notified when this page was last reviewed.