PSUs serve citizens as customers at very large scale: LPG and fuel consumers, electricity and water connections, passengers, and people living in townships. Many PSUs are treated as 'the State' under Article 12 of the Constitution, which the DPDP Act uses for its own definition. Whether the State provisions apply to a given activity needs legal advice; for commercial, customer-facing work, most PSUs plan as a normal Data Fiduciary with full duties.
The first four things to sort out
Payment data access.
Subsidy files.
Retention.
Secure transfer.
A worked example: Subsidy file mismatch
Day 1Wrong bank details for 200 consumers.
Day 3Corrected with consumers.
Week 1Accuracy check added.
AfterLogged.
Evidence kept: Correction log.
Accuracy is a duty.
What others in the sector usually do. Portals over email.
Distributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Short answer: Yes, you are responsible for what they do with your consumers' data
When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.
Short answer: For the legal or business period, then erase
Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.
From your seat: Finance department. Tax and audit rules require keeping some records for years. List them so they are kept, and the rest is deleted.
In PSUs and utilities
Pension and service records are kept long; consumer records follow legal and business needs.
What the law says
Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6
Steps
List the record types you hold.
Write the period for each, with the law, regulator rule or business reason.
Set a trigger for the period to start: end of relationship, date of transaction, exit date.
Automate deletion where you can; for paper, schedule shredding.
Keep a deletion log.
Evidence to keep
Retention schedule approved by Legal
Deletion log
Shredding or disposal certificates
Common mistakes
'Keep everything forever' because storage is cheap
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: Finance department. Payroll, payment and collection vendors hold sensitive data. Check their contracts.
In PSUs and utilities
Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.
Short answer: Only those who need it, reviewed every quarter
Only people who need it for their job, and only the part they need. Use named accounts, give access by role, review it every quarter and remove it on the day someone leaves. Watch privileged accounts closely.
From your seat: Finance department. Limit who can see bank details and salary data, and log access.
In PSUs and utilities
Partner and franchisee logins are the weak point.
What the law says
Rule 6 names access control as a minimum safeguard, along with logs and monitoring that can detect misuse. Section 8(5) · Rule 6
Steps
Write a role matrix for each key system.
Replace shared logins with named accounts.
Use multi-factor sign-in for admin and remote access.
Short answer: Not for employment purposes; yes for anything extra
Usually not for normal employment purposes. Section 7(i) lets you process employee data for employment, such as payroll, attendance, safety and preventing corporate espionage. Anything beyond that, such as wellness apps, photos for marketing or sharing with a bank for offers, needs consent.
From your seat: Finance department. Salary and bank details are employment data; sharing them beyond employment needs care.
In PSUs and utilities
Pension, medical and family records need tight access.
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
From your seat: Finance department. A misdirected salary file or payment list is a breach. Report it to the DPO at once.
In PSUs and utilities
A leaked consumer list from a distributor is your breach to report.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Short answer: Yes, unless a sector rule says otherwise
Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.
From your seat: Finance department. Check where finance and payroll SaaS is hosted.
In PSUs and utilities
Check vendor support access from abroad, especially for smart-meter and ticketing platforms.
What the law says
Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)
Steps
List where each system is hosted and where support teams log in from.
Check sector rules for localisation.
Put location and access terms in cloud and vendor contracts.
Keep the list current; new SaaS tools change it quietly.
Section 7: Uses allowed without consent. Employment purposes cover most workforce data. Whether Section 7(b) applies to subsidy work depends on the PSU's status and the scheme.
Section 8(7) · Rule 8: Erasure and retention. If the State provisions do not apply to an activity, normal DPDP erasure applies after legal retention.
Section 8(1)–(2): Responsibility for vendors. Distributors, franchisees, meter vendors, ticketing vendors and labour contractors process data for you.
Section 8(5) · Rule 6: Security safeguards. Large consumer systems and plant systems both need safeguards; some are protected systems.
Other rules that sit alongside DPDP
Rule
What it says
What it means alongside DPDP
Source
DPDP Act, Section 2(x) and Article 12 of the Constitution
The Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control.
Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties.