PSUs serve citizens as customers at very large scale: LPG and fuel consumers, electricity and water connections, passengers, and people living in townships. Many PSUs are treated as 'the State' under Article 12 of the Constitution, which the DPDP Act uses for its own definition. Whether the State provisions apply to a given activity needs legal advice; for commercial, customer-facing work, most PSUs plan as a normal Data Fiduciary with full duties.
The first four things to sort out
Tag data complaints.
Recording notice.
Identity checks.
Timelines.
A worked example: A caller asks who has his number
CallLogged.
Day 3Distributor and company records checked.
Day 6Summary sent.
AfterClosed.
Evidence kept: Log.
Know your partners.
What others in the sector usually do. Privacy tag in CRM.
Distributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Short answer: Yes, you are responsible for what they do with your consumers' data
When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.
Short answer: Yes, a clear summary, inside the published timeline
Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.
From your seat: Customer service department. Log every request on the day it comes in and route it to the DPO's register.
In PSUs and utilities
Consumers can ask who received their data: distributors, franchisees, payment partners.
What the law says
Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14
Steps
Log the request in one register the day it arrives.
Verify identity using details you already hold.
Search every system, including vendors' copies.
Write a plain summary: what data, why it is used, who received it.
Send it, and file the request, search notes and reply.
Short answer: Reply within your published period, never beyond 90 days
Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.
From your seat: Customer service department. Tag privacy complaints and count the days.
In PSUs and utilities
Complaints come through call centres, portals and CPGRAMS. Tag the data ones.
Short answer: Yes, with notice, a retention period and masking
Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.
From your seat: Customer service department. Play the recording notice and pause recording for card details.
Short answer: Yes, unless a law requires you to keep it
You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.
From your seat: Customer service department. Explain clearly what can be deleted and what the law requires to be kept.
In PSUs and utilities
If State provisions do not apply to the activity, normal erasure applies after legal retention.
What the law says
Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8
Steps
Log the request and verify identity.
Check the retention schedule for each record type involved.
Delete what has no legal reason to stay, including copies with vendors and in test systems.
Mark what must stay, with the law and the end date.
Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
Erasure log
Vendor deletion confirmations
Reply to the person
Common mistakes
Refusing every erasure request 'because of backups'
Short answer: Stop that use quickly, across every system and vendor
Withdrawal must be as easy as giving consent. Once someone withdraws, you and every vendor working for you must stop that use within a reasonable time. What was done before withdrawal stays lawful, and data that a law requires you to keep is kept.
From your seat: Customer service department. Process stop requests the same day and confirm in writing.
What the law says
Section 6(4) to 6(6) give the right to withdraw at any time, with the same ease, and require processors to stop as well. Section 8(7) then asks for erasure unless a law requires retention. Section 6 · Section 8(7) · Rule 8 · Section 8(1)–(2)
Steps
Give one simple way to withdraw on every channel where consent is taken.
Record the withdrawal against the person and the purpose.
Push the change to every system and vendor that uses that purpose.
Confirm to the person, in writing, what has stopped and what is kept by law.
Check a sample every month to see that the change actually reached every list.
Evidence to keep
Withdrawal log with time stamps
Proof that downstream systems and vendors updated
Confirmation sent to the person
Common mistakes
Withdrawal by email only, while consent was one tap in an app
Stopping in the main system but not in vendor lists
Short answer: Yes, this is a common breach; give staff a safer option
Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.
From your seat: Customer service department. Never send customer data from personal phones or accounts.
In PSUs and utilities
Field and distributor groups share consumer lists on chat.