InfraVeritas360DPDPiq

DPDP Insights › Public sector undertakings and utilities › CISO / Security head

Public sector undertakings and utilities

DPDP for the CISO / Security head in PSUs and utilities

You protect both consumer systems and plant or network systems, some of which may be protected systems.

Open this seat in the interactive tool

What is different here

OT and IT meet in PSUs. Personal data sits in HR, access control, billing and township systems, often next to critical control networks.

The first four things to sort out

  1. Separate personal-data systems from control networks.
  2. Bring partner and vendor access under named accounts.
  3. Keep logs for a year and 180 days in India.
  4. Rehearse an incident with the DPO and administrative ministry contacts.

A worked example: Malware on a township management PC

  1. MorningAntivirus flags malware on the township office PC that holds resident records.
  2. Hour 2The PC is isolated. Logs show data was sent to an unknown server.
  3. Hour 5CERT-In is informed within six hours; the DPO is told.
  4. Day 2Residents and the Data Protection Board are informed; the township system moves to the central data centre.

Evidence kept: Incident log; CERT-In report; Resident message; Migration record.

Small local systems hold big risks.

What others in the sector usually do. Power utilities are using CEA guideline evidence as the base for Rule 6.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Oil and gas marketingDistributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Power generation and transmissionContract labour gate passes and biometrics; PSU hospital records of employees and families; Township allotment and resident records
Electricity distribution (state discoms)Smart-meter data held by the meter vendor; Billing files shared with collection agencies; Consumer lists exposed on public bill lookup pages
Transport undertakings (rail PSUs, metro, state road transport)Passenger lists and reservation charts; Concession passes with ID copies; CCTV and travel-card data
Steel, mining, defence production and heavy industryMedical surveillance records of workers; Township and school records; Resettlement and compensation records of affected families
State development corporations and boardsLottery and allotment lists published with full details; Ration and supply records; Old paper files in record rooms

Control map: DPDP to NIST CSF 2.0 and ISO/IEC 27001:2022

DPDP dutyLawNIST CSF 2.0ISO/IEC 27001 Annex AEvidence
Know where personal data isSection 8(5) · Rule 6ID.AM-02, ID.AM-075.9, 5.12Inventory of systems and data types, with owner and hosting location
Only the right people get inSection 8(5) · Rule 6PR.AA-01, PR.AA-055.15, 5.16, 5.18, 8.2Role matrix, quarterly access review sign-off, leaver removal report
Strong sign-in for admins and remote usersSection 8(5) · Rule 6PR.AA-035.17, 8.5MFA enforcement report for admin, VPN and email accounts
Encrypt or mask dataSection 8(5) · Rule 6PR.DS-01, PR.DS-028.11, 8.24Encryption settings for databases, laptops, backups and transfers; masking in test copies
Keep and watch logsSection 8(5) · Rule 6PR.PS-04, DE.CM-01, DE.CM-038.15, 8.16, 8.17Log retention settings (one year; 180 days in India for CERT-In), alert rules, NTP source
Backups that restoreSection 8(5) · Rule 6PR.DS-11, RC.RP-038.13, 5.30Backup schedule, offline copy, last restore test with date and result
Separate networksSection 8(5) · Rule 6PR.IR-018.20, 8.22Network diagram showing segments, firewall rule review
Patch and fix weaknessesSection 8(5) · Rule 6ID.RA-018.8Vulnerability scan results and closure tracker
Handle incidents and tell peopleSection 8(6) · Rule 7RS.MA-01, RS.CO-02, RS.CO-035.24, 5.25, 5.26, 6.8Incident plan with the 6-hour and 72-hour steps, drill record, contact list
Learn from incidentsSection 8(6) · Rule 7DE.AE-02, ID.IM-015.27, 5.28Post-incident review and actions closed
Vendors protect data tooSection 8(1)–(2)GV.SC-05, GV.SC-075.19, 5.20, 5.22Contracts with data terms, vendor review record
Data comes back or is deleted at contract endSection 8(7) · Rule 8GV.SC-105.20, 8.10Exit clause and deletion certificate from the vendor
Cloud is set up safelySection 16 · Rule 15GV.SC-05, PR.DS-015.23Cloud region list, shared-responsibility note, configuration review
Delete when the purpose is overSection 8(7) · Rule 8PR.DS-018.10, 7.14Retention schedule, deletion log, disposal certificates for disks and paper
People know the rulesSection 8(5) · Rule 6PR.AT-016.3Training attendance and short test results by department
Legal duties are trackedSection 8(5) · Rule 6GV.OC-035.31, 5.34Register of laws and rules that apply, reviewed yearly
Roles are namedSection 8(9)–(10) · Rules 9, 14GV.RR-025.2, 5.4Named owners for each system and each duty, approved by management

Logs, backups and access checklist

9 guides for the CISO / Security head, in full

Townships, hospitals and schools run by the PSU: what applies?

Short answer: Yes, full duties for each service

These hold residents', patients' and students' data. Each needs a notice, access limits and retention. PSU hospital records follow medical record rules; school records may involve children, where Fourth Schedule exemptions for educational institutions and healthcare may apply to some purposes.

From your seat: CISO / Security head. Bring township systems under central control.
What the law says

Sections 5, 8(5), 8(7) and 9 apply to each service. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 9 · Rules 10, 12 · Section 8(7) · Rule 8

Steps
  1. List township services that hold personal data.
  2. Give each a notice.
  3. Restrict medical records.
  4. Check children's data rules for schools.
  5. Set retention.
Evidence to keep
  • Service list
  • Notices
  • Access settings
Common mistakes
  • Township PCs with no security
  • Medical records visible to HR
  • School data with no parent notice
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: CISO / Security head. You start the six-hour CERT-In clock and feed the DPO what is needed for the people and Board messages. Keep the timeline evidence: who saw what, and when.
In PSUs and utilities

A leaked consumer list from a distributor is your breach to report.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Which logs must we keep, for how long, and where?

Short answer: At least one year; 180 days of ICT logs in India

Keep logs that show who accessed personal data and what they did, for at least one year under the DPDP Rules. CERT-In separately asks for ICT system logs to be kept for 180 days within India. Logs must be protected so nobody can quietly change them.

From your seat: CISO / Security head. Check retention on every log source against one year, and make sure ICT logs stay in India for 180 days. Logs that can be edited by the admins they record are weak evidence.
In PSUs and utilities

Consumer systems and township systems both need logging.

What the law says

Rule 6 lists logs and monitoring as a minimum safeguard. Rule 8(3) asks for logs to be kept for at least one year. The CERT-In Directions of 2022 ask for 180 days of ICT logs kept within India. Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. List systems holding personal data and what each logs today.
  2. Turn on access logging where it is missing.
  3. Send logs to one protected store, with at least one year of retention.
  4. Keep a copy of ICT logs in India for at least 180 days.
  5. Sync clocks and review alerts every day.
Evidence to keep
  • Log source list
  • Retention settings
  • Alert review records
Common mistakes
  • Logging only failures, not who viewed a record
  • Logs stored on the same server they describe
  • Clocks out of sync, so timelines cannot be built
Related questions

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

From your seat: CISO / Security head. Prioritise privileged and remote access. One review of admin accounts across core systems usually finds the biggest gaps.
In PSUs and utilities

Partner and franchisee logins are the weak point.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6

Steps
  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.
Evidence to keep
  • Role matrix
  • Quarterly review sign-offs
  • Leaver removal report
Common mistakes
  • Generic logins on shared machines
  • Access that only grows
  • No review of vendor accounts
Related questions

Does deletion have to reach backups and test copies?

Short answer: Yes, through a written backup-expiry rule

Deletion should reach every copy you control. For backups, the usual practice is to let deleted records expire with the normal backup cycle, never restore them into live use, and write this down. Test and training copies should use masked data.

From your seat: CISO / Security head. Test a full restore, not a file restore. Then check that backup retention does not quietly keep deleted records for years.
In PSUs and utilities

Backups of billing and ticketing systems follow retention.

What the law says

Section 8(7) asks for erasure. Rule 6 asks for backups for continuity. The two meet in a backup retention rule that is short enough and written down. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List where copies live: backups, replicas, test, analytics, laptops, vendors.
  2. Set backup retention to match the retention schedule.
  3. Write a rule: deleted records are not restored into live systems.
  4. Mask personal data in test and training copies.
  5. Get deletion confirmations from vendors.
Evidence to keep
  • Backup retention settings
  • Written backup-expiry rule
  • Masking procedure for test data
Common mistakes
  • Ten-year backups for convenience
  • Live copies in test
  • Restoring old backups and bringing deleted records back
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: CISO / Security head. Set the technical schedule: incident notice in hours, logging, MFA, sub-contractor approval. Ask for evidence once a year.
In PSUs and utilities

Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: CISO / Security head. Look at where admins and support staff log in from, not only where servers sit. Overseas support access is a transfer.
In PSUs and utilities

Check vendor support access from abroad, especially for smart-meter and ticketing platforms.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: CISO / Security head. Your tooling can help: data-loss rules on email, an approved file-share, mobile device controls. Pair it with a reporting route that people trust.
In PSUs and utilities

Field and distributor groups share consumer lists on chat.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

Does ISO 27001 or NIST CSF cover our DPDP duties?

Short answer: They cover security, not the whole Act

They help a great deal with the security part. ISO/IEC 27001 and NIST CSF 2.0 are good evidence of reasonable security safeguards. They do not cover notice, consent, rights, complaints or children's data. ISO/IEC 27701 adds privacy controls, but no certificate replaces the Act.

From your seat: CISO / Security head. Use the control map below. Most of Rule 6 is already in your ISO or NIST work; the job is to collect the evidence in one place.
In PSUs and utilities

CEA guidelines and ISO 27001 cover much of Rule 6.

What the law says

Section 8(5) and Rule 6 ask for reasonable security safeguards. A recognised standard is strong evidence of that duty, and only of that duty. Section 8(5) · Rule 6

Steps
  1. Map your current controls to Rule 6.
  2. Add the DPDP-only items: notice, consent, rights, complaints, children, retention.
  3. Use the same evidence for audits and for DPDP.
  4. Include privacy in the scope of your next internal audit.
  5. Consider ISO/IEC 27701 if clients ask for it.
Evidence to keep
  • Control map
  • Audit reports
  • Gap list for DPDP-only items
Common mistakes
  • Treating a certificate as DPDP compliance
  • Scope that leaves out the systems with the most personal data
  • No owner for the non-security duties
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for public sector undertakings and utilities.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 2(x) and Article 12 of the ConstitutionThe Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control.Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties.MeitY
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.Applies to every PSU.CERT-In
IT Act, Section 70 and NCIIPCSystems notified as protected systems come under NCIIPC's critical information infrastructure framework.Plant control, grid and pipeline systems may be notified; personal data in them follows DPDP too.NCIIPC
CEA (Cyber Security in Power Sector) Guidelines, 2021Cyber security requirements for power sector utilities, including incident reporting and supply chain controls.Power PSUs and discoms can use this evidence for DPDP Rule 6.Central Electricity Authority
Aadhaar Act, 2016Aadhaar-linked subsidies such as LPG must store Aadhaar numbers securely and limit sharing.Distributor systems and counters must not keep Aadhaar copies.UIDAI
Labour Codes (in force from 21 November 2025)Registers for workers and contract labour, health and safety records for hazardous work.Set retention for worker and contract labour records against the codes and state rules.Ministry of Labour
SEBI LODR Regulations (listed PSUs)Listed PSUs follow disclosure and governance rules.Board-level reporting on data protection fits into existing risk committee work.SEBI
RTI Act, Section 8(1)(j) as amendedPersonal information is exempt from RTI disclosure since 13 November 2025.PSU CPIOs should apply the new wording with reasoned orders.SFLC.in summary
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.