The first question is legal: for which activities, if any, can you use the State provisions? After that, the work looks like any large consumer business, with the extra weight of public scrutiny and RTI.
The first four things to sort out
Get a legal view on the State provisions, activity by activity.
List every partner network that sees consumer data.
Publish one contact and grievance route across channels.
Set retention by record type.
A worked example: An LPG consumer complains about marketing calls
Day 1A consumer complains that she gets insurance calls after booking a cylinder.
Day 4The DPO's team finds a distributor shared its consumer list with a local insurance agent.
Day 6The distributor is told to stop, the list is retrieved and the consumer is informed.
Month 1Distributor agreements get a data clause; distributors are trained.
What others in the sector usually do. PSUs that have started treat consumer-facing work as full DPDP and keep State provisions for narrow public functions.
Distributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Short answer: Possibly, for some activities; get a written legal view
The DPDP Act uses the Article 12 meaning of 'State'. Many PSUs have been treated as the State by courts, depending on how deeply the government controls them. If you are, Section 7(b) and 7(c) and Section 17(4) may apply to public functions, but not automatically to commercial customer-facing work. Write an activity-wise legal view and keep the State provisions narrow.
From your seat: DPO / Privacy lead. Apply the note in request replies.
What the law says
Section 2(x) defines State by reference to Article 12. Sections 7(b), 7(c) and 17(4) apply to the State. Section 7 · Section 8(7) · Rule 8
Steps
List activities: public functions, schemes, commercial sales.
Short answer: Yes, you are responsible for what they do with your consumers' data
When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.
From your seat: DPO / Privacy lead. Partner complaints are a leading indicator.
Short answer: Yes, at every point where you collect data
A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.
From your seat: DPO / Privacy lead. You own the wording and the version history. Keep a folder with every live notice, its date and who approved it; that folder is usually the first thing an auditor asks for.
In PSUs and utilities
LPG booking, new connection forms, ticket counters and bill payment portals each need a notice.
What the law says
Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14
Steps
List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
Write one short notice per collection point, with the data items and purpose side by side.
Add how to withdraw consent, how to make a request and the DPO or contact person's details.
Offer the notice in English and in the languages your consumers actually use.
Keep each version with the date it went live.
Evidence to keep
Screenshots or copies of the notice at each collection point, with dates
Notice version history
Translations, where used
Common mistakes
Hiding the notice inside terms and conditions
One notice for everything, with no link between data items and purposes
Short answer: It depends on the use; most organisations need both
For every use of personal data you need one basis: consent, or one of the legitimate uses in Section 7, such as a legal duty, employment, a medical emergency, or data a person gave voluntarily for a specific purpose. Anything beyond what the person expects, such as marketing, profiling or sharing with partners, usually needs consent.
From your seat: DPO / Privacy lead. Build the purpose-and-basis register yourself, even if each team fills its own rows. When someone asks why their data was used, this register is your answer.
In PSUs and utilities
Supplying the service rests on the purpose consumers gave data for; marketing and partner offers need consent.
What the law says
Section 4 allows processing only with consent or for a legitimate use. Section 6 sets what valid consent looks like. Section 7 lists the uses that need no consent. Section 4 · Section 6 · Section 7
Steps
List each purpose for which you use personal data.
Against each purpose, write the basis: consent or the exact clause of Section 7.
Where the basis is consent, check that it was asked separately, with a clear action and no pre-ticked box.
Stop or re-paper any purpose with no basis.
Review the list whenever a new product, campaign or system starts.
Evidence to keep
Purpose and basis register
Consent records with date, version and channel
Legal sign-off on each legitimate use relied on
Common mistakes
Treating account terms as consent for marketing
Bundling several purposes in one tick-box
Relying on 'legitimate interest', which the Indian Act does not have
Short answer: Yes, a clear summary, inside the published timeline
Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.
From your seat: DPO / Privacy lead. Requests land with you even when the data sits with other teams. Agree a turnaround with each system owner in advance, so you are not chasing people on day 25.
In PSUs and utilities
Consumers can ask who received their data: distributors, franchisees, payment partners.
What the law says
Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14
Steps
Log the request in one register the day it arrives.
Verify identity using details you already hold.
Search every system, including vendors' copies.
Write a plain summary: what data, why it is used, who received it.
Send it, and file the request, search notes and reply.
Short answer: Reply within your published period, never beyond 90 days
Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.
From your seat: DPO / Privacy lead. Count the days yourself. A short monthly note to management with open complaints and their age keeps the 90-day limit visible.
In PSUs and utilities
Complaints come through call centres, portals and CPGRAMS. Tag the data ones.
Short answer: For the legal or business period, then erase
Keep data for as long as its purpose needs, or as long as a law requires, and then erase it. Every organisation must keep personal data and logs for at least one year under Rule 8(3). Write a retention schedule by record type, with the law or reason against each period.
From your seat: DPO / Privacy lead. Draft the schedule, but get Legal and each department head to sign their rows. Your role is to make sure deletion actually happens.
In PSUs and utilities
Pension and service records are kept long; consumer records follow legal and business needs.
What the law says
Section 8(7) asks for erasure when the purpose is over, unless a law requires retention. Rule 8(3) sets a one-year minimum for personal data, traffic data and logs. Section 8(7) · Rule 8 · Section 8(5) · Rule 6
Steps
List the record types you hold.
Write the period for each, with the law, regulator rule or business reason.
Set a trigger for the period to start: end of relationship, date of transaction, exit date.
Automate deletion where you can; for paper, schedule shredding.
Keep a deletion log.
Evidence to keep
Retention schedule approved by Legal
Deletion log
Shredding or disposal certificates
Common mistakes
'Keep everything forever' because storage is cheap
Short answer: Check every channel; children often appear where you least expect
Anyone under 18 is a child under the Act. For a child's data you need verifiable consent from a parent or lawful guardian, and you must not track, behaviourally monitor or show targeted ads to children. Some classes and purposes are exempt under Rule 12 and the Fourth Schedule, for example healthcare to the extent needed to protect the child's health, and educational institutions for their educational work.
From your seat: DPO / Privacy lead. Ask every team, not only marketing. Dependants, interns, scholarship applicants and visitors are where children's data usually hides.
In PSUs and utilities
PSU schools and hospitals handle children's data.
What the law says
Section 9 sets the duties. Rule 10 explains how to verify the parent. Rule 12 and the Fourth Schedule list the exemptions. Section 9 · Rules 10, 12 · Section 6
Steps
Find where children's data enters: customers, dependants, interns, visitors, scholarships, app sign-ups.
Decide whether an exemption in the Fourth Schedule applies to that purpose.
Where none applies, add an age question and a parent-consent step.
Switch off tracking and targeted ads for under-18 users.
Record the decision for each channel.
Evidence to keep
Channel-by-channel note on children's data
Parent-consent records
Ad and tracking settings
Common mistakes
Assuming 'we are B2B, so no children'
Using the age 13 or 16 from foreign laws
Treating a tick-box from the child as parental consent
Short answer: Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Contain it, then tell people. A reportable cyber incident goes to CERT-In within six hours of being noticed. Under DPDP, each affected person and the Data Protection Board must be told without delay, and the Board needs a detailed report within 72 hours. Sector regulators may have their own clock too.
From your seat: DPO / Privacy lead. You decide whether people and the Data Protection Board must be told, so you must be on the first call, not informed the next morning.
In PSUs and utilities
A leaked consumer list from a distributor is your breach to report.
What the law says
Section 8(6) and Rule 7 set the DPDP steps. The CERT-In Directions of 28 April 2022 set the six-hour report. A breach includes accidental disclosure and loss of access, not only hacking. Section 8(6) · Rule 7 · Section 8(5) · Rule 6
Steps
Name one incident lead and a back-up, with phone numbers that work at night.
Write the first-hour steps: isolate, preserve logs, tell the DPO and the incident lead.
Keep ready-made drafts for CERT-In, the regulator, the Board and affected people.
Decide in advance who signs off each message.
Rehearse once a year with the people who would actually be called.
Evidence to keep
Incident plan with clocks
Rehearsal record
Incident log with times of each step
Common mistakes
Waiting to finish the investigation before telling anyone
Treating a wrong email or a lost laptop as 'not a breach'
Short answer: Yes, every vendor that touches personal data
You stay responsible for what your vendors do with personal data. The contract should say what data they get, for what purpose, the security they must keep, how fast they must tell you about an incident, that sub-contractors need your approval, and how data is returned or deleted at the end.
From your seat: DPO / Privacy lead. Keep the vendor register with IT and Procurement. You decide which vendors carry the most personal-data risk and need review first.
In PSUs and utilities
Distributors, franchisees, meter vendors, ticketing vendors and labour contractors.