Industry and team

DPDP Act for government departments and public bodies

Audience: government departments, public authorities, GovTech vendors and their compliance teams · Last reviewed: October 2026

The DPDP Act, 2023 applies to the State as well as to private businesses, with some specific routes and exemptions. This guide is for departments, public authorities and the vendors who build and run their systems.

“Person” includes the State (s.2(s)(vi)), and “State” means the State as defined under article 12 of the Constitution (s.2(zb)). Whether a particular body is “State” follows article 12, so check that first.

Legitimate uses for the State

Section 7 gives the State three grounds that do not need fresh consent:

  • Benefits and services (s.7(b)). To provide or issue a subsidy, benefit, service, certificate, licence or permit, where the person previously consented to processing for any such benefit, or the data is in a database or register maintained by the State and notified by the Central Government. The Act's illustration: a woman who enrols for a maternity benefit can have her data processed to check eligibility for other prescribed benefits.
  • Functions under law (s.7(c)). Performing any function under law, or in the interest of sovereignty and integrity of India or security of the State.
  • Legal disclosures (s.7(d)). Fulfilling a legal obligation on any person to disclose information to the State, in line with that law's disclosure provisions.

Rule 5(2) explains that a benefit provided “under law”, “under policy” or “using public funds” covers statutory functions, executive policy of the Central or a State Government, and spending from the Consolidated Funds, public accounts or a local authority's funds. Our lawful uses guide covers the other clauses.

Rule 5 and the Second Schedule standards

Processing under s.7(b) must follow the Second Schedule (Rule 5(1)), which requires technical and organisational measures so that:

  1. processing is lawful (item (a)) and limited to the uses in s.7(b) (item (b));
  2. only necessary personal data is processed (item (c));
  3. reasonable efforts are made for completeness, accuracy and consistency (item (d));
  4. data is kept only as long as needed or as law requires (item (e));
  5. reasonable security safeguards protect it, including with processors (item (f));
  6. the person is told about the processing, with a contact for questions and a link or other means to exercise her rights (item (g)); and
  7. whoever determines the purpose and means is accountable (item (h)).

Exemptions that apply to the State

ProvisionEffect
s.17(2)(a)The Act does not apply to instrumentalities the Central Government notifies in the interests of sovereignty, security, friendly relations with foreign States, public order or preventing incitement to related cognizable offences, or to the Central Government's processing of data they furnish.
s.17(1)(b)Courts, tribunals and bodies with judicial, quasi-judicial, regulatory or supervisory functions are outside Chapters II (except s.8(1) and 8(5)) and III and s.16, where processing is necessary for those functions.
s.17(1)(c)The same partial exemption for processing for prevention, detection, investigation or prosecution of offences.
s.17(4)For processing by the State or its instrumentalities, s.8(7) (erasure) and s.12(3) (erasure on request) do not apply; s.12(2) (correction) also does not apply where processing does not involve a decision affecting the person.
s.17(2)(b), Rule 16Research, archiving or statistical processing following Second Schedule standards, where no decision specific to the person is taken.

Outside these, the general duties remain, including security safeguards (s.8(5)) and breach intimation (s.8(6), Rule 7). See exemptions under DPDP.

Children's data in public services

Rule 12(2) and Part B of the Fourth Schedule lift the parental consent and tracking requirements of s.9(1) and 9(3) for exercising powers or duties in the interests of a child under law (item 1), and for providing a subsidy, benefit, service, certificate, licence or permit in a child's interests under s.7(b) (item 2). In both cases processing is restricted to the extent necessary. See children's data rules.

Rule 23: calling for information

Section 36 lets the Central Government require the Board, any Data Fiduciary or intermediary to furnish information for the purposes of the Act. Rule 23(1) operationalises this for the purposes listed in the Seventh Schedule, through the authorised person named there:

  • use by the State in the interest of sovereignty and integrity of India or security of the State (item 1);
  • use by the State to perform a function under law or to disclose information under a legal obligation (item 2); and
  • assessments for notifying Significant Data Fiduciaries (item 3).

Where disclosure could prejudice sovereignty, integrity or State security, the Government may require the recipient not to tell the affected person or anyone else without written permission (Rule 23(2)). Rule 8(3) requires one year of log retention for these same Seventh Schedule purposes.

The RTI Act amendment

Section 44(3) substitutes clause (j) of section 8(1) of the Right to Information Act, 2005 with: “(j) information which relates to personal information;”. According to the commencement note under s.1(2), s.44(3) came into force on 13 November 2025. Public information officers should read the amended text alongside their RTI guidance.

GovTech vendors

Vendors running portals, databases or call centres for a department usually act as Data Processors. The department needs a valid contract (s.8(2)) with security provisions (Rule 6(1)(f)), and Second Schedule item (f) extends safeguards to processing by processors. See DPDP obligations for Data Processors and reasonable security safeguards.

Rules 3, 5 to 16 and 23 come into force eighteen months from 13 November 2025 (Rule 1(4)).

Frequently asked questions

Does the DPDP Act apply to government departments?

Yes. The definition of person includes the State (s.2(s)(vi)), so a department can be a Data Fiduciary. Specific exemptions apply under section 17, and instrumentalities notified under s.17(2)(a) are outside the Act.

Do government schemes need consent to process personal data?

Not always. Section 7(b) allows the State to process data to provide a subsidy, benefit, service, certificate, licence or permit where the person previously consented for any such benefit or the data is in a notified State database, following the Second Schedule standards (Rule 5).

Must government bodies delete data on request under the DPDP Act?

Section 17(4) disapplies section 8(7) and section 12(3) for processing by the State or its instrumentalities, so the general erasure duties do not apply to them.

How did the DPDP Act change the RTI Act?

Section 44(3) replaced clause (j) of section 8(1) of the Right to Information Act, 2005 with: information which relates to personal information.

What is Rule 23 of the DPDP Rules?

Rule 23 lets the Central Government, through authorised persons named in the Seventh Schedule, require a Data Fiduciary or intermediary to furnish information for the purposes listed there, and to keep it confidential where disclosure could prejudice sovereignty, integrity or State security.

Practical next step

List each citizen-facing service, note whether it relies on s.7(b), s.7(c), consent or an exemption, and check that the Second Schedule intimation is in place. Then run a quick external check of your department's public pages.

Advertisement