| DPDP Act, Section 2(x) and Article 12 of the Constitution | The Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control. | Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties. | MeitY |
| CERT-In Directions, 2022 | Report specified cyber incidents within six hours; keep ICT logs 180 days in India. | Applies to every PSU. | CERT-In |
| IT Act, Section 70 and NCIIPC | Systems notified as protected systems come under NCIIPC's critical information infrastructure framework. | Plant control, grid and pipeline systems may be notified; personal data in them follows DPDP too. | NCIIPC |
| CEA (Cyber Security in Power Sector) Guidelines, 2021 | Cyber security requirements for power sector utilities, including incident reporting and supply chain controls. | Power PSUs and discoms can use this evidence for DPDP Rule 6. | Central Electricity Authority |
| Aadhaar Act, 2016 | Aadhaar-linked subsidies such as LPG must store Aadhaar numbers securely and limit sharing. | Distributor systems and counters must not keep Aadhaar copies. | UIDAI |
| Labour Codes (in force from 21 November 2025) | Registers for workers and contract labour, health and safety records for hazardous work. | Set retention for worker and contract labour records against the codes and state rules. | Ministry of Labour |
| SEBI LODR Regulations (listed PSUs) | Listed PSUs follow disclosure and governance rules. | Board-level reporting on data protection fits into existing risk committee work. | SEBI |
| RTI Act, Section 8(1)(j) as amended | Personal information is exempt from RTI disclosure since 13 November 2025. | PSU CPIOs should apply the new wording with reasoned orders. | SFLC.in summary |