Distributor registers and delivery slips with addresses; Subsidy and Aadhaar data in distributor software; Consumer numbers shared with marketing partners
Short answer: Yes, you are responsible for what they do with your consumers' data
When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.
From your seat: Operations head. Field teams see partner practice first.
Short answer: Yes, at every point where you collect data
A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.
From your seat: Operations head. Your counters, forms and call scripts are where notices are actually seen. Check that each one shows the current version.
In PSUs and utilities
LPG booking, new connection forms, ticket counters and bill payment portals each need a notice.
What the law says
Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14
Steps
List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
Write one short notice per collection point, with the data items and purpose side by side.
Add how to withdraw consent, how to make a request and the DPO or contact person's details.
Offer the notice in English and in the languages your consumers actually use.
Keep each version with the date it went live.
Evidence to keep
Screenshots or copies of the notice at each collection point, with dates
Notice version history
Translations, where used
Common mistakes
Hiding the notice inside terms and conditions
One notice for everything, with no link between data items and purposes
Short answer: Yes, a clear summary, inside the published timeline
Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.
From your seat: Operations head. Front-line staff receive most requests. Teach them to log the request and pass it on the same day, not to answer it themselves.
In PSUs and utilities
Consumers can ask who received their data: distributors, franchisees, payment partners.
What the law says
Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14
Steps
Log the request in one register the day it arrives.
Verify identity using details you already hold.
Search every system, including vendors' copies.
Write a plain summary: what data, why it is used, who received it.
Send it, and file the request, search notes and reply.
Short answer: Reply within your published period, never beyond 90 days
Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.
From your seat: Operations head. Many complaints start as service complaints. Tag the ones about personal data so they enter the privacy log.
In PSUs and utilities
Complaints come through call centres, portals and CPGRAMS. Tag the data ones.
Short answer: Yes, this is a common breach; give staff a safer option
Sending personal data to the wrong chat or a personal account is one of the most common breaches. Banning messaging rarely works. Give staff an approved tool that is easy to use, set simple rules, and make it safe to report a wrong send at once.
From your seat: Operations head. Shift groups and vendor chats are where data leaks. Give supervisors an approved way to share lists and photos.
In PSUs and utilities
Field and distributor groups share consumer lists on chat.
Short answer: Yes, with notice, limits and a deletion period
All three are personal data. Put a clear notice where people are recorded, collect only what you need at reception, keep footage and registers for a set period, and protect biometric templates carefully. Do not keep copies of ID documents unless you must.
From your seat: Operations head. Check notices at entrances and recording areas, and who on site can view footage.
Short answer: Yes, with notice, a retention period and masking
Call recordings, chat transcripts and agent screens hold a lot of personal data. Tell callers that calls are recorded and why, keep recordings for a set period, limit who can listen, and mask card numbers and passwords on screen and in recordings.
From your seat: Operations head. Call scripts need a recording notice, and agents need to know when to pause the recording.
Short answer: Yes, unless a law requires you to keep it
You must erase data that you no longer need for the purpose it was collected for, unless a law requires you to keep it. Where a law does require it, keep the data, stop using it for anything else, and tell the person why it is being kept and until when.
From your seat: Operations head. Front-line teams need a simple answer for 'delete my data': log it, pass it on, and explain the timeline.
In PSUs and utilities
If State provisions do not apply to the activity, normal erasure applies after legal retention.
What the law says
Section 12 gives the right to correction and erasure. Section 8(7) allows retention only where a law requires it. Rule 8(3) asks every organisation to keep personal data and logs for at least one year first. Sections 11–14 · Rule 14 · Section 8(7) · Rule 8
Steps
Log the request and verify identity.
Check the retention schedule for each record type involved.
Delete what has no legal reason to stay, including copies with vendors and in test systems.
Mark what must stay, with the law and the end date.
Reply in plain words: what was deleted, what is kept, why and until when.
Evidence to keep
Erasure log
Vendor deletion confirmations
Reply to the person
Common mistakes
Refusing every erasure request 'because of backups'