InfraVeritas360DPDPiq

DPDP Insights › Public sector undertakings and utilities › Marketing department

Public sector undertakings and utilities

DPDP for the Marketing department in PSUs and utilities

Marketing runs consumer campaigns and loyalty schemes.

Open this seat in the interactive tool

What is different here

PSUs serve citizens as customers at very large scale: LPG and fuel consumers, electricity and water connections, passengers, and people living in townships. Many PSUs are treated as 'the State' under Article 12 of the Constitution, which the DPDP Act uses for its own definition. Whether the State provisions apply to a given activity needs legal advice; for commercial, customer-facing work, most PSUs plan as a normal Data Fiduciary with full duties.

The first four things to sort out

  1. Consent for offers.
  2. Partner sharing.
  3. Notices.
  4. Stop options.

A worked example: A loyalty programme launch

  1. Week 1Separate consent added.
  2. Week 2Partner sharing limited.
  3. Week 3Stop option tested.
  4. AfterLaunch.

Evidence kept: Form.

Consent first.

What others in the sector usually do. Consent-only campaigns.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Oil and gas marketingDistributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Power generation and transmissionContract labour gate passes and biometrics; PSU hospital records of employees and families; Township allotment and resident records
Electricity distribution (state discoms)Smart-meter data held by the meter vendor; Billing files shared with collection agencies; Consumer lists exposed on public bill lookup pages
Transport undertakings (rail PSUs, metro, state road transport)Passenger lists and reservation charts; Concession passes with ID copies; CCTV and travel-card data
Steel, mining, defence production and heavy industryMedical surveillance records of workers; Township and school records; Resettlement and compensation records of affected families
State development corporations and boardsLottery and allotment lists published with full details; Ration and supply records; Old paper files in record rooms

7 guides for the Marketing department, in full

What about distributors, dealers and franchisees?

Short answer: Yes, you are responsible for what they do with your consumers' data

When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.

What the law says

Section 8(1) and 8(2) cover processors. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

Steps
  1. List partner types and numbers.
  2. Issue a standard data clause.
  3. Give masked views where possible.
  4. Train partners.
  5. Check samples yearly.
Evidence to keep
  • Partner list
  • Signed clauses
  • Training and check records
Common mistakes
  • Full consumer exports to partners
  • No clause
  • No checks
Related questions

Can we send offers to past customers and leads?

Short answer: Only with separate consent and an easy way to stop

Marketing needs consent that is separate and specific, unless the person clearly expects it from the relationship. Bought or scraped lead lists are risky because you cannot show consent. Every message should carry an easy way to stop.

From your seat: Marketing department. Every campaign list needs a consent source. If you cannot say where the consent came from, do not use the list.
In PSUs and utilities

Do not let partners use consumer lists for their own offers.

What the law says

Section 6 sets the consent standard. Section 5 needs a notice. Section 9 bars targeted advertising at children. Section 6 · Section 5 · Rule 3 · Section 9 · Rules 10, 12

Steps
  1. Separate service messages from marketing messages.
  2. Ask marketing consent separately, with a clear action.
  3. Stop using bought lists unless the seller can show consent for you.
  4. Add an easy stop option to every message.
  5. Respect the telecom preference rules for calls and SMS.
Evidence to keep
  • Marketing consent records
  • Lead source records
  • Stop requests and their handling
Common mistakes
  • Treating account sign-up as marketing consent
  • Agency lists with no consent proof
  • A stop option that does not work
Related questions

Someone withdraws consent. What has to stop, and how fast?

Short answer: Stop that use quickly, across every system and vendor

Withdrawal must be as easy as giving consent. Once someone withdraws, you and every vendor working for you must stop that use within a reasonable time. What was done before withdrawal stays lawful, and data that a law requires you to keep is kept.

From your seat: Marketing department. Make the stop option work across every channel and agency within a day.
What the law says

Section 6(4) to 6(6) give the right to withdraw at any time, with the same ease, and require processors to stop as well. Section 8(7) then asks for erasure unless a law requires retention. Section 6 · Section 8(7) · Rule 8 · Section 8(1)–(2)

Steps
  1. Give one simple way to withdraw on every channel where consent is taken.
  2. Record the withdrawal against the person and the purpose.
  3. Push the change to every system and vendor that uses that purpose.
  4. Confirm to the person, in writing, what has stopped and what is kept by law.
  5. Check a sample every month to see that the change actually reached every list.
Evidence to keep
  • Withdrawal log with time stamps
  • Proof that downstream systems and vendors updated
  • Confirmation sent to the person
Common mistakes
  • Withdrawal by email only, while consent was one tap in an app
  • Stopping in the main system but not in vendor lists
  • Deleting records a law requires you to keep
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Marketing department. Landing pages, contest forms and event sign-ups each need a short notice.
In PSUs and utilities

LPG booking, new connection forms, ticket counters and bill payment portals each need a notice.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your consumers actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Do we process children's data, and what changes if we do?

Short answer: Check every channel; children often appear where you least expect

Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.

From your seat: Marketing department. Switch off targeting for under-18 audiences and avoid tracking them.
In PSUs and utilities

PSU schools and hospitals handle children's data.

What the law says

Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6

Steps
  1. Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
  2. Decide whether an exemption in the Fourth Schedule applies to that purpose.
  3. Where none applies, add an age question and a parent-consent step.
  4. Switch off tracking and targeted ads for under-18 users.
  5. Record the decision for each channel.
Evidence to keep
  • Channel-by-channel note on children's data
  • Parent-consent records
  • Ad and tracking settings
Common mistakes
  • Assuming 'we are B2B, so no children'
  • Using the age 13 or 16 from foreign laws
  • Treating a tick-box from the child as parental consent
Related questions

What must a vendor contract say about personal data?

Short answer: Yes, every vendor that touches personal data

You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.

From your seat: Marketing department. Agencies, ad platforms and event partners receive data. Their contracts need data terms.
In PSUs and utilities

Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.

What the law says

Section 8(1) keeps responsibility with you. Section 8(2) allows a processor only under a valid contract. Rule 6 asks for security terms in that contract. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 8(6) · Rule 7 · Section 8(7) · Rule 8

Steps
  1. List vendors who receive or can see personal data.
  2. Rank them by how much and how sensitive.
  3. Add a data-protection schedule to each contract, starting with the top ten.
  4. Ask for evidence: certificates, test results, deletion confirmations.
  5. Review the top vendors every year.
Evidence to keep
  • Vendor register
  • Signed data-protection schedules
  • Annual review notes
Common mistakes
  • Relying on the vendor's standard terms
  • No incident-notice time
  • No exit and deletion clause
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for public sector undertakings and utilities.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 2(x) and Article 12 of the ConstitutionThe Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control.Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties.MeitY
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.Applies to every PSU.CERT-In
IT Act, Section 70 and NCIIPCSystems notified as protected systems come under NCIIPC's critical information infrastructure framework.Plant control, grid and pipeline systems may be notified; personal data in them follows DPDP too.NCIIPC
CEA (Cyber Security in Power Sector) Guidelines, 2021Cyber security requirements for power sector utilities, including incident reporting and supply chain controls.Power PSUs and discoms can use this evidence for DPDP Rule 6.Central Electricity Authority
Aadhaar Act, 2016Aadhaar-linked subsidies such as LPG must store Aadhaar numbers securely and limit sharing.Distributor systems and counters must not keep Aadhaar copies.UIDAI
Labour Codes (in force from 21 November 2025)Registers for workers and contract labour, health and safety records for hazardous work.Set retention for worker and contract labour records against the codes and state rules.Ministry of Labour
SEBI LODR Regulations (listed PSUs)Listed PSUs follow disclosure and governance rules.Board-level reporting on data protection fits into existing risk committee work.SEBI
RTI Act, Section 8(1)(j) as amendedPersonal information is exempt from RTI disclosure since 13 November 2025.PSU CPIOs should apply the new wording with reasoned orders.SFLC.in summary
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.