InfraVeritas360DPDPiq

DPDP Insights › Public sector undertakings and utilities › Legal department

Public sector undertakings and utilities

DPDP for the Legal department in PSUs and utilities

Legal holds the Article 12 view and contracts.

Open this seat in the interactive tool

What is different here

PSUs serve citizens as customers at very large scale: LPG and fuel consumers, electricity and water connections, passengers, and people living in townships. Many PSUs are treated as 'the State' under Article 12 of the Constitution, which the DPDP Act uses for its own definition. Whether the State provisions apply to a given activity needs legal advice; for commercial, customer-facing work, most PSUs plan as a normal Data Fiduciary with full duties.

The first four things to sort out

  1. Activity-wise view.
  2. Partner terms.
  3. RTI.
  4. Vendor terms.

A worked example: RTI asking for consumer list

  1. Day 1CPIO consults legal.
  2. Day 2Personal information exempt.
  3. Day 10Reasoned reply.
  4. AfterLogged.

Evidence kept: Reply.

Reasoned orders.

What others in the sector usually do. Board-approved note.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Oil and gas marketingDistributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Power generation and transmissionContract labour gate passes and biometrics; PSU hospital records of employees and families; Township allotment and resident records
Electricity distribution (state discoms)Smart-meter data held by the meter vendor; Billing files shared with collection agencies; Consumer lists exposed on public bill lookup pages
Transport undertakings (rail PSUs, metro, state road transport)Passenger lists and reservation charts; Concession passes with ID copies; CCTV and travel-card data
Steel, mining, defence production and heavy industryMedical surveillance records of workers; Township and school records; Resettlement and compensation records of affected families
State development corporations and boardsLottery and allotment lists published with full details; Ration and supply records; Old paper files in record rooms

8 guides for the Legal department, in full

Is our PSU 'the State' under DPDP, and what changes if it is?

Short answer: Possibly, for some activities; get a written legal view

The DPDP Act uses the Article 12 meaning of 'State'. Many PSUs have been treated as the State by courts, depending on how deeply the government controls them. If you are, Section 7(b) and 7(c) and Section 17(4) may apply to public functions, but not automatically to commercial customer-facing work. Write an activity-wise legal view and keep the State provisions narrow.

What the law says

Section 2(x) defines State by reference to Article 12. Sections 7(b), 7(c) and 17(4) apply to the State. Section 7 · Section 8(7) · Rule 8

Steps
  1. List activities: public functions, schemes, commercial sales.
  2. Get a legal view for each.
  3. Apply full duties where unsure.
  4. Record the view and get board approval.
  5. Review if courts or MeitY clarify.
Evidence to keep
  • Legal note
  • Board approval
Common mistakes
  • Claiming State status for marketing
  • No written view
  • Assuming exemption from security
Related questions

How does the RTI amendment change replies about personal information?

Short answer: Personal information is exempt; give reasoned orders

DPDP Section 44(3), in force from 13 November 2025, amended RTI Section 8(1)(j). Personal information is now exempt from disclosure without the earlier public-interest test. The amendment is under challenge in the Supreme Court, so CPIOs should apply it carefully and keep reasoned orders.

From your seat: Legal department. Review sample orders.
What the law says

RTI Act Section 8(1)(j) as amended by DPDP Section 44(3). Section 7

Steps
  1. Brief all CPIOs on the new wording.
  2. Separate personal from non-personal parts of records.
  3. Give the non-personal parts.
  4. Record reasons for each exemption.
  5. Watch for the Supreme Court's decision.
Evidence to keep
  • CPIO briefing
  • Reasoned orders
Common mistakes
  • Refusing whole files when only parts are personal
  • No reasons in the order
  • Ignoring pending litigation
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Legal department. Keep a standard data-protection schedule and insist on it.
In PSUs and utilities

Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Are we a Data Fiduciary or a Data Processor?

Short answer: Often both, for different data

You are a Data Fiduciary when you decide why and how personal data is used, as you do for your own staff and customers. You are a Data Processor when you handle data only on another organisation's instructions. Many organisations are both, for different data sets.

From your seat: Legal department. Decide the role for each data set and make contracts match.
In PSUs and utilities

Partners act for you when handling your consumers' data.

What the law says

Section 2(i) and 2(k) define the two roles. Section 8(1) puts the duties on the Data Fiduciary, which must use processors only under a valid contract. Section 8(1)–(2) · Section 17(1)(d)

Steps
  1. List each data set you handle.
  2. For each, ask: who decides the purpose?
  3. Mark yourself as fiduciary or processor, and name the other party.
  4. Check that contracts match the role.
  5. Route requests about processor data to the fiduciary.
Evidence to keep
  • Role register by data set
  • Contracts matching the role
Common mistakes
  • Calling yourself a processor for data you use for your own purposes
  • No contract when you act as processor
  • Answering requests that belong to your client
Related questions

Police, a court or a regulator asks for someone's data. What do we do?

Short answer: Yes, when the request is lawful and in writing

Check that the request is in writing, comes from the right authority and cites the legal power. Share only what is asked for, record what you sent and to whom, and keep the request on file. The Act allows processing to meet a legal duty, but it does not mean sharing everything on a phone call.

From your seat: Legal department. Check the legal power for every request and log what was shared.
In PSUs and utilities

Police and agencies ask for consumer details; log each request.

What the law says

Section 7(d) and 7(e) allow processing to meet a legal duty to disclose to the State, or to comply with a judgment or order. Section 17(1)(c) exempts processing for preventing, detecting or investigating offences. Section 7 · Section 8(5) · Rule 6

Steps
  1. Route every such request to Legal.
  2. Check the authority, the legal power and the scope.
  3. Share only what is asked, by a secure method.
  4. Log the request, what was sent, by whom and when.
  5. Tell the person, unless the law or the authority says you must not.
Evidence to keep
  • Authority request log
  • Copies of requests
  • Record of what was sent
Common mistakes
  • Sharing on a phone call
  • Sending whole files when a few lines were asked
  • No log
Related questions

Can personal data be stored or accessed outside India?

Short answer: Yes, unless a sector rule says otherwise

Under DPDP, yes, unless the government restricts a country, and none had been restricted when this page was last reviewed. A sector rule can be stricter, for example RBI's rule that payment system data must be stored only in India. Remote support access from abroad also counts as data going outside India.

From your seat: Legal department. Track sector localisation rules and add location clauses to contracts.
In PSUs and utilities

Check vendor support access from abroad, especially for smart-meter and ticketing platforms.

What the law says

Section 16 allows transfers unless restricted, and keeps stricter sector laws in force. Rule 15 adds conditions on making data available to foreign states. Section 16 · Rule 15 · Section 8(1)–(2)

Steps
  1. List where each system is hosted and where support teams log in from.
  2. Check sector rules for localisation.
  3. Put location and access terms in cloud and vendor contracts.
  4. Keep the list current; new SaaS tools change it quietly.
  5. Tell people in your notice if data goes abroad.
Evidence to keep
  • Hosting and access-location list
  • Contract clauses
  • Sector rule check
Common mistakes
  • Forgetting email, CRM and helpdesk SaaS
  • Ignoring overseas support logins
  • Assuming 'Indian vendor' means 'data in India'
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Legal department. Record the Fourth Schedule reasoning for each purpose.
In PSUs and utilities

PSU schools and hospitals handle children's data.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for public sector undertakings and utilities.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 2(x) and Article 12 of the ConstitutionThe Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control.Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties.MeitY
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.Applies to every PSU.CERT-In
IT Act, Section 70 and NCIIPCSystems notified as protected systems come under NCIIPC's critical information infrastructure framework.Plant control, grid and pipeline systems may be notified; personal data in them follows DPDP too.NCIIPC
CEA (Cyber Security in Power Sector) Guidelines, 2021Cyber security requirements for power sector utilities, including incident reporting and supply chain controls.Power PSUs and discoms can use this evidence for DPDP Rule 6.Central Electricity Authority
Aadhaar Act, 2016Aadhaar-linked subsidies such as LPG must store Aadhaar numbers securely and limit sharing.Distributor systems and counters must not keep Aadhaar copies.UIDAI
Labour Codes (in force from 21 November 2025)Registers for workers and contract labour, health and safety records for hazardous work.Set retention for worker and contract labour records against the codes and state rules.Ministry of Labour
SEBI LODR Regulations (listed PSUs)Listed PSUs follow disclosure and governance rules.Board-level reporting on data protection fits into existing risk committee work.SEBI
RTI Act, Section 8(1)(j) as amendedPersonal information is exempt from RTI disclosure since 13 November 2025.PSU CPIOs should apply the new wording with reasoned orders.SFLC.in summary
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.