InfraVeritas360DPDPiq

DPDP Insights › Public sector undertakings and utilities › Transport undertakings (rail PSUs, metro, state road transport)

Public sector undertakings and utilities

DPDP for a transport undertakings (rail psus, metro, state road transport)

Ticketing, passes and travel cards collect identity, travel history and payment data. CCTV on stations and buses adds more.

Read it from your seat in the tool

Whose data you hold

Passengers, pass holders and ticket buyers. You work with ticketing vendors, payment partners and caterers.

Where it usually goes wrong

  1. Passenger lists and reservation charts
  2. Concession passes with ID copies
  3. CCTV and travel-card data

Read it from your seat

Questions that come up first

Is our PSU 'the State' under DPDP, and what changes if it is?

Short answer: Possibly, for some activities; get a written legal view

The DPDP Act uses the Article 12 meaning of 'State'. Many PSUs have been treated as the State by courts, depending on how deeply the government controls them. If you are, Section 7(b) and 7(c) and Section 17(4) may apply to public functions, but not automatically to commercial customer-facing work. Write an activity-wise legal view and keep the State provisions narrow.

What the law says

Section 2(x) defines State by reference to Article 12. Sections 7(b), 7(c) and 17(4) apply to the State. Section 7 · Section 8(7) · Rule 8

Steps
  1. List activities: public functions, schemes, commercial sales.
  2. Get a legal view for each.
  3. Apply full duties where unsure.
  4. Record the view and get board approval.
  5. Review if courts or MeitY clarify.
Evidence to keep
  • Legal note
  • Board approval
Common mistakes
  • Claiming State status for marketing
  • No written view
  • Assuming exemption from security
Related questions

What about distributors, dealers and franchisees?

Short answer: Yes, you are responsible for what they do with your consumers' data

When distributors, dealers or franchisees handle consumer data for your service, they act for you, and you are responsible. Give them only what they need, add a data clause to agreements, train them, and check a sample every year. If a partner uses data for its own business, such as selling insurance, that is outside your purpose and must stop.

What the law says

Section 8(1) and 8(2) cover processors. Section 8(1)–(2) · Section 8(5) · Rule 6 · Section 6

Steps
  1. List partner types and numbers.
  2. Issue a standard data clause.
  3. Give masked views where possible.
  4. Train partners.
  5. Check samples yearly.
Evidence to keep
  • Partner list
  • Signed clauses
  • Training and check records
Common mistakes
  • Full consumer exports to partners
  • No clause
  • No checks
Related questions

What should our privacy notice say, and where must people see it?

Short answer: Yes, at every point where you collect data

A notice must tell people, in plain words, what data you collect, why, how they can withdraw consent, how they can use their rights and how they can complain to the Data Protection Board. It has to stand on its own, separate from long terms and conditions, and be shown at the point where data is collected.

In PSUs and utilities

LPG booking, new connection forms, ticket counters and bill payment portals each need a notice.

What the law says

Section 5 and Rule 3 ask for a notice that can be understood on its own, with an itemised list of the data and the purpose for each item. Data you already hold from before the Act also needs a notice, as soon as reasonably practicable. Section 5 · Rule 3 · Section 6 · Sections 11–14 · Rule 14

Steps
  1. List every point where personal data comes in: forms, apps, counters, calls, emails, partner feeds.
  2. Write one short notice per collection point, with the data items and purpose side by side.
  3. Add how to withdraw consent, how to make a request and the DPO or contact person's details.
  4. Offer the notice in English and in the languages your passengers actually use.
  5. Keep each version with the date it went live.
Evidence to keep
  • Screenshots or copies of the notice at each collection point, with dates
  • Notice version history
  • Translations, where used
Common mistakes
  • Hiding the notice inside terms and conditions
  • One notice for everything, with no link between data items and purposes
  • Forgetting old data collected before the Act
Related questions

Someone asks what data we hold about them. What do we send?

Short answer: Yes, a clear summary, inside the published timeline

Send a summary of the personal data you hold about them and what you do with it, and the names of the other organisations you shared it with and what was shared. Check the person's identity first, log the request and keep a copy of your reply.

In PSUs and utilities

Consumers can ask who received their data: distributors, franchisees, payment partners.

What the law says

Section 11 gives the right to a summary and the list of organisations it was shared with. Rule 14 asks you to publish how requests are made and to answer within the period you publish. Sections 11–14 · Rule 14 · Section 8(9)–(10) · Rules 9, 14

Steps
  1. Log the request in one register the day it arrives.
  2. Verify identity using details you already hold.
  3. Search every system, including vendors' copies.
  4. Write a plain summary: what data, why it is used, who received it.
  5. Send it, and file the request, search notes and reply.
Evidence to keep
  • Request register
  • Search notes for each request
  • Copy of each reply with date
Common mistakes
  • Sending raw database dumps
  • Forgetting data held by vendors
  • No identity check before sending
Related questions

How do we handle a privacy complaint within 90 days?

Short answer: Reply within your published period, never beyond 90 days

Publish one clear way to complain, log every complaint, give it an owner and reply within the period you publish, never more than 90 days. People can go to the Data Protection Board only after using your process, so a good process keeps most matters with you.

In PSUs and utilities

Complaints come through call centres, portals and CPGRAMS. Tag the data ones.

What the law says

Section 8(10) requires a working grievance process. Rule 14(3) caps the reply time at 90 days. Section 13 says people must use your process before approaching the Board. Section 8(9)–(10) · Rules 9, 14 · Sections 11–14 · Rule 14 · Sections 18–26

Steps
  1. Publish one contact for privacy complaints on your website, app and notices.
  2. Log each complaint with the date, channel and a named owner.
  3. Acknowledge within a few days, and set an internal target well under 90 days.
  4. Find and fix the cause, not just the single case.
  5. Reply in writing and close the entry with the date.
Evidence to keep
  • Complaint register with dates
  • Replies sent
  • Monthly summary to management
Common mistakes
  • Mixing privacy complaints into general complaints with no tag
  • No owner, so nobody counts the days
  • Closing a complaint without fixing the cause
Related questions
Explore our research-built assessment platformsEach one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.