InfraVeritas360DPDPiq

DPDP Insights › Public sector undertakings and utilities › Finance department

Public sector undertakings and utilities

DPDP for the Finance department in PSUs and utilities

Finance holds subsidy, payment and payroll data.

Open this seat in the interactive tool

What is different here

PSUs serve citizens as customers at very large scale: LPG and fuel consumers, electricity and water connections, passengers, and people living in townships. Many PSUs are treated as 'the State' under Article 12 of the Constitution, which the DPDP Act uses for its own definition. Whether the State provisions apply to a given activity needs legal advice; for commercial, customer-facing work, most PSUs plan as a normal Data Fiduciary with full duties.

The first four things to sort out

  1. Payment data access.
  2. Subsidy files.
  3. Retention.
  4. Secure transfer.

A worked example: Subsidy file mismatch

  1. Day 1Wrong bank details for 200 consumers.
  2. Day 3Corrected with consumers.
  3. Week 1Accuracy check added.
  4. AfterLogged.

Evidence kept: Correction log.

Accuracy is a duty.

What others in the sector usually do. Portals over email.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Oil and gas marketingDistributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Power generation and transmissionContract labour gate passes and biometrics; PSU hospital records of employees and families; Township allotment and resident records
Electricity distribution (state discoms)Smart-meter data held by the meter vendor; Billing files shared with collection agencies; Consumer lists exposed on public bill lookup pages
Transport undertakings (rail PSUs, metro, state road transport)Passenger lists and reservation charts; Concession passes with ID copies; CCTV and travel-card data
Steel, mining, defence production and heavy industryMedical surveillance records of workers; Township and school records; Resettlement and compensation records of affected families
State development corporations and boardsLottery and allotment lists published with full details; Ration and supply records; Old paper files in record rooms

7 guides for the Finance department, in full

What about distributors, dealers and franchisees?

Short answer: Yes, you are responsible for what they do with your consumers' data

When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.

What the law says

Section 8(1) and 8(2) cover processors. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

Steps
  1. List partner types and numbers.
  2. Issue a standard data clause.
  3. Give masked views where possible.
  4. Train partners.
  5. Check samples yearly.
Evidence to keep
  • Partner list
  • Signed clauses
  • Training and check records
Common mistakes
  • Full consumer exports to partners
  • No clause
  • No checks
Related questions

How long can we keep personal data?

Short answer: For the legal or business period, then erase

Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.

From your seat: Finance department. Tax and audit rules require keeping some records for years. List them so they are kept, and the rest is deleted.
In PSUs and utilities

Pension and service records are kept long; consumer records follow legal and business needs.

What the law says

Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6

Steps
  1. List the record types you hold.
  2. Write the period for each, with the law, regulator rule or business reason.
  3. Set a trigger for the period to start: end of relationship, date of transaction, exit date.
  4. Automate deletion where you can; for paper, schedule shredding.
  5. Keep a deletion log.
Evidence to keep
  • Retention schedule approved by Legal
  • Deletion log
  • Shredding or disposal certificates
Common mistakes
  • 'Keep everything forever' because storage is cheap
  • Deleting before the legal minimum
  • Forgetting email, shared drives and backups
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Finance department. Payroll, payment and collection vendors hold sensitive data. Check their contracts.
In PSUs and utilities

Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Who should be able to see personal data in our systems?

Short answer: Only those who need it, reviewed every quarter

Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.

From your seat: Finance department. Limit who can see bank details and salary data, and log access.
In PSUs and utilities

Partner and franchisee logins are the weak point.

What the law says

Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6

Steps
  1. Write a role matrix for each key system.
  2. Replace shared logins with named accounts.
  3. Use multi-factor sign-in for admin and remote access.
  4. Review access every quarter with each manager.
  5. Remove access on the last working day.
Evidence to keep
  • Role matrix
  • Quarterly review sign-offs
  • Leaver removal report
Common mistakes
  • Generic logins on shared machines
  • Access that only grows
  • No review of vendor accounts
Related questions

Do we need consent for employee data?

Short answer: Not for employment purposes; yes for anything extra

Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.

From your seat: Finance department. Salary and bank details are employment data; sharing them beyond employment needs care.
In PSUs and utilities

Pension, medical and family records need tight access.

What the law says

Section 7(i) covers employment purposes and safeguarding the employer from loss or liability. Notice, security, retention and rights still apply to employees. Section 7 · Section 5 · Rule 3 · Section 8(7) · Rule 8 · Sections 11–14 · Rule 14

Steps
  1. List what you collect from staff and why.
  2. Mark which items are employment purposes and which are extra.
  3. Take consent for the extras, separately.
  4. Give staff a short employee privacy notice.
  5. Set retention for ex-employee records.
Evidence to keep
  • Employee data list with basis
  • Employee privacy notice
  • Consent for extras
Common mistakes
  • A blanket consent clause in the offer letter
  • Keeping candidate data forever
  • Sharing staff data with vendors without terms
Related questions

Something has gone wrong. What happens in the first 72 hours?

Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report

Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.

From your seat: Finance department. A misdirected salary file or payment list is a breach. Report it to the DPO at once.
In PSUs and utilities

A leaked consumer list from a distributor is your breach to report.

What the law says

Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6

Steps
  1. Name one incident lead and a back-up, with phone numbers that work at night.
  2. Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
  3. Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
  4. Decide in advance who signs off each message.
  5. Rehearse once a year with the people who would actually be called.
Evidence to keep
  • Incident plan with clocks
  • Rehearsal record
  • Incident log with times of each step
Common mistakes
  • Waiting to finish the investigation before telling anyone
  • Treating a wrong email or a lost laptop as 'not a breach'
  • Only IT knowing the plan
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: Finance department. Check where finance and payroll SaaS is hosted.
In PSUs and utilities

Check vendor support access from abroad, especially for smart-meter and ticketing platforms.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for public sector undertakings and utilities.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 2(x) and Article 12 of the ConstitutionThe Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control.Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties.MeitY
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.Applies to every PSU.CERT-In
IT Act, Section 70 and NCIIPCSystems notified as protected systems come under NCIIPC's critical information infrastructure framework.Plant control, grid and pipeline systems may be notified; personal data in them follows DPDP too.NCIIPC
CEA (Cyber Security in Power Sector) Guidelines, 2021Cyber security requirements for power sector utilities, including incident reporting and supply chain controls.Power PSUs and discoms can use this evidence for DPDP Rule 6.Central Electricity Authority
Aadhaar Act, 2016Aadhaar-linked subsidies such as LPG must store Aadhaar numbers securely and limit sharing.Distributor systems and counters must not keep Aadhaar copies.UIDAI
Labour Codes (in force from 21 November 2025)Registers for workers and contract labour, health and safety records for hazardous work.Set retention for worker and contract labour records against the codes and state rules.Ministry of Labour
SEBI LODR Regulations (listed PSUs)Listed PSUs follow disclosure and governance rules.Board-level reporting on data protection fits into existing risk committee work.SEBI
RTI Act, Section 8(1)(j) as amendedPersonal information is exempt from RTI disclosure since 13 November 2025.PSU CPIOs should apply the new wording with reasoned orders.SFLC.in summary
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.