InfraVeritas360DPDPiq

DPDP Insights › Public sector undertakings and utilities › Operations head

Public sector undertakings and utilities

DPDP for the Operations head in PSUs and utilities

Field offices, counters and distributor networks handle consumer data daily.

Open this seat in the interactive tool

What is different here

Paper registers, delivery slips and counter forms are everywhere.

The first four things to sort out

  1. Remove Aadhaar copies from counters.
  2. Secure registers.
  3. Log consumer requests.
  4. Report losses.

A worked example: Delivery slips with addresses in the open

  1. Day 1Slips are found in a delivery vehicle dustbin.
  2. Day 2The DPO is informed.
  3. Week 1App-based delivery confirmation is rolled out.
  4. AfterPaper slips stop.

Evidence kept: Report; Change.

Remove paper where you can.

What others in the sector usually do. Field teams are moving to app-based delivery confirmation.

Where it usually goes wrong, by organisation type

Organisation typeHotspots
Oil and gas marketingDistributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Power generation and transmissionContract labour gate passes and biometrics; PSU hospital records of employees and families; Township allotment and resident records
Electricity distribution (state discoms)Smart-meter data held by the meter vendor; Billing files shared with collection agencies; Consumer lists exposed on public bill lookup pages
Transport undertakings (rail PSUs, metro, state road transport)Passenger lists and reservation charts; Concession passes with ID copies; CCTV and travel-card data
Steel, mining, defence production and heavy industryMedical surveillance records of workers; Township and school records; Resettlement and compensation records of affected families
State development corporations and boardsLottery and allotment lists published with full details; Ration and supply records; Old paper files in record rooms

8 guides for the Operations head, in full

What about distributors, dealers and franchisees?

Short answer: Yes, you are responsible for what they do with your consumers' data

When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.

From your seat: Operations head. Field teams see partner practice first.
What the law says

Section 8(1) and 8(2) cover processors. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

Steps
  1. List partner types and numbers.
  2. Issue a standard data clause.
  3. Give masked views where possible.
  4. Train partners.
  5. Check samples yearly.
Evidence to keep
  • Partner list
  • Signed clauses
  • Training and check records
Common mistakes
  • Full consumer exports to partners
  • No clause
  • No checks
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

From your seat: Operations head. Your counters, forms and call scripts are where notices are actually seen. Check that each one shows the current version.
In PSUs and utilities

LPG booking, new connection forms, ticket counters and bill payment portals each need a notice.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your consumers actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

From your seat: Operations head. Front-line staff receive most requests. Teach them to log the request and pass it on the same day, not to answer it themselves.
In PSUs and utilities

Consumers can ask who received their data: distributors, franchisees, payment partners.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

From your seat: Operations head. Many complaints start as service complaints. Tag the ones about personal data so they enter the privacy log.
In PSUs and utilities

Complaints come through call centres, portals and CPGRAMS. Tag the data ones.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions

Staff share personal data on WhatsApp and personal email. What do we do?

Short answer: Yes, this is a common breach; give staff a safer option

Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.

From your seat: Operations head. Shift groups and vendor chats are where data leaks. Give supervisors an approved way to share lists and photos.
In PSUs and utilities

Field and distributor groups share consumer lists on chat.

What the law says

Section 8(5) asks for reasonable safeguards. A wrong send is a breach under Section 2(u), and Section 8(6) applies. Section 8(5) · Rule 6 · Section 8(6) · Rule 7

Steps
  1. Ask teams how they actually share files and photos today.
  2. Provide an approved tool for that job.
  3. Set three simple rules: approved tool, no personal accounts, report wrong sends.
  4. Teach the rules with real examples from your own work.
  5. Treat a quick report as good behaviour, not a disciplinary case.
Evidence to keep
  • Approved-tool policy
  • Training record
  • Incident reports of wrong sends
Common mistakes
  • A ban with no alternative
  • Punishing people who report
  • Ignoring group chats with vendors
Related questions

What about CCTV, visitor registers and biometric attendance?

Short answer: Yes, with notice, limits and a deletion period

All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.

From your seat: Operations head. Check notices at entrances and recording areas, and who on site can view footage.
In PSUs and utilities

Stations, plants, townships and offices.

What the law says

Section 5 needs notice. Section 8(5) needs safeguards. Section 8(7) needs erasure after the purpose. For staff, Section 7(i) can cover security and attendance. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8 · Section 7

Steps
  1. Put notices at CCTV points and reception, in the local language.
  2. Ask visitors only for name, phone and whom they are meeting, unless security needs more.
  3. Set a period for footage and registers, then delete.
  4. Restrict who can view footage, and log viewing.
  5. Check the vendor contracts for CCTV, guards and attendance systems.
Evidence to keep
  • Notices in place
  • Retention settings on the recorder
  • Viewing log
Common mistakes
  • Photocopying visitor IDs as routine
  • Footage kept until the disk fills
  • Biometric systems with vendor default passwords
Related questions

What about call recordings and customer service screens?

Short answer: Yes, with notice, a retention period and masking

Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.

From your seat: Operations head. Call scripts need a recording notice, and agents need to know when to pause the recording.
In PSUs and utilities

Booking and complaint lines record calls.

What the law says

Section 5 needs notice, Section 8(5) needs safeguards, and Section 8(7) needs erasure after the purpose. Section 5 · Rule 3 · Section 8(5) · Rule 6 · Section 8(7) · Rule 8

Steps
  1. Play a short recording notice at the start of calls.
  2. Set a retention period by call type.
  3. Pause recording when card or other sensitive details are given.
  4. Limit replay rights to quality and complaint teams.
  5. Lock agent screens and stop phones on the floor if data is sensitive.
Evidence to keep
  • Recording notice script
  • Retention settings
  • Replay access list
Common mistakes
  • Recordings kept indefinitely
  • Card numbers in recordings
  • Open replay access for all supervisors
Related questions

Someone asks us to delete their data. Must we?

Short answer: Yes, unless a law requires you to keep it

You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.

From your seat: Operations head. Front-line teams need a simple answer for 'delete my data': log it, pass it on, and explain the timeline.
In PSUs and utilities

If State provisions do not apply to the activity, normal erasure applies after legal retention.

What the law says

Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8

Steps
  1. Log the request and verify identity.
  2. Check the retention schedule for each record type involved.
  3. Delete what has no legal reason to stay, including copies with vendors and in test systems.
  4. Mark what must stay, with the law and the end date.
  5. Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
  • Erasure log
  • Vendor deletion confirmations
  • Reply to the person
Common mistakes
  • Refusing every erasure request 'because of backups'
  • Deleting records a law requires
  • Not telling vendors
Related questions

Practical examples

Notice wording, request log, retention schedule, vendor clause and breach notice for public sector undertakings and utilities.

The sections you will use most

Other rules that sit alongside DPDP

RuleWhat it saysWhat it means alongside DPDPSource
DPDP Act, Section 2(x) and Article 12 of the ConstitutionThe Act defines 'State' with the meaning in Article 12. Many PSUs have been treated as 'the State' by courts, depending on government control.Get a legal view on which activities can rely on Section 7(b), 7(c) and 17(4). Customer-facing commercial work usually follows full duties.MeitY
CERT-In Directions, 2022Report specified cyber incidents within six hours; keep ICT logs 180 days in India.Applies to every PSU.CERT-In
IT Act, Section 70 and NCIIPCSystems notified as protected systems come under NCIIPC's critical information infrastructure framework.Plant control, grid and pipeline systems may be notified; personal data in them follows DPDP too.NCIIPC
CEA (Cyber Security in Power Sector) Guidelines, 2021Cyber security requirements for power sector utilities, including incident reporting and supply chain controls.Power PSUs and discoms can use this evidence for DPDP Rule 6.Central Electricity Authority
Aadhaar Act, 2016Aadhaar-linked subsidies such as LPG must store Aadhaar numbers securely and limit sharing.Distributor systems and counters must not keep Aadhaar copies.UIDAI
Labour Codes (in force from 21 November 2025)Registers for workers and contract labour, health and safety records for hazardous work.Set retention for worker and contract labour records against the codes and state rules.Ministry of Labour
SEBI LODR Regulations (listed PSUs)Listed PSUs follow disclosure and governance rules.Board-level reporting on data protection fits into existing risk committee work.SEBI
RTI Act, Section 8(1)(j) as amendedPersonal information is exempt from RTI disclosure since 13 November 2025.PSU CPIOs should apply the new wording with reasoned orders.SFLC.in summary
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.