Question · Central government: ministries and departments
Can we share data with states, banks or other ministries?
Short answer: Yes, with a written basis, minimum fields and a log
Yes, where the scheme or a law needs it, through a written MoU or order that sets the purpose, the fields, security and retention. Share the minimum, through logged channels, and record each transfer. Bulk sharing with private parties needs a clear legal basis and should mask personal details where possible.
What the law says
Section 7 bases, Section 8(1) for processors, Section 8(5) for safeguards.
Section 7: Some uses need no consent: data a person gave voluntarily for a specified purpose, duties under law, medical emergencies involving a threat to life, health services during an epidemic, safety during a disaster, and purposes of employment.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Steps
List every outgoing data flow.
Write an MoU or order for each.
Cut fields to the minimum.
Use logged channels.
Review flows yearly.
Evidence to keep
Flow register
MoUs
Transfer logs
Common mistakes
Email attachments
Full data when counts would do
No MoU
From each seat
IT head / NIC coordinator: Replace email flows with APIs.
Oversight: AS / JS / board: Ask how many outgoing flows exist and how many have MoUs.
Legal cell: Draft the MoU template.
Scheme or programme head: Approve the fields each partner gets.
What a good answer from management sounds like
“Every outgoing flow has an MoU, minimum fields and a log.” Effort and time: Medium.