Skip to content

DPDP for government and public-sector bodies

State instrumentalities carry exemptions in some directions and heightened scrutiny in others. The practical question is rarely whether an exemption applies — it is whether the body can evidence which one it relied on, and when.

Deadline
13 May 2027
Pressure points
4 identified
Controls
4 products
Max penalty
₹250 Cr, per instance

Already regulated by

  • MeitY
  • CERT-In
  • Data Protection Board
  • CAG

DPDP sits alongside these rather than replacing them. Where a sectoral rule requires retention and the Act requires erasure, both are satisfiable — but only where the basis is recorded per attribute.

Where the pressure lands

What DPDP actually changes for governance & risk

The Act applies uniformly. The obligations that bite first do not — these are the ones this sector fails on.

Sec. 7, 17

Exemptions have to be evidenced, not assumed

Processing for subsidies, benefits, services, certificates, licences and permits is a listed legitimate use. Relying on it without recording the basis per activity turns a lawful position into an undocumented gap at inquiry.

Sec. 10(2)(c)(iii)

Algorithmic due diligence on public systems

Automated decisioning that affects entitlement carries the heaviest justification burden. Model purpose, training-data provenance, bias testing and human oversight all have to be on record.

Sec. 5

Notice in scheduled languages

Public-facing services reach citizens who are entitled to notice in any of the twenty-two Eighth Schedule languages. Serving English alone is a defect in the notice itself, not a translation backlog.

Sec. 28

Records production under inquiry

The Board may require production of records. For a public body the evidence trail is also the audit trail the CAG and the legislature will ask for.

What closes them

The controls, in the order they land

Discovery first, because every other obligation is undeliverable without a catalogue. Everything after that consumes what it built.

  1. 01

    Privacy Program Governance

    Run the whole privacy programme from one control plane, so the next regulation lands as configuration.

    Sec. 4, 7, 10, 16

  2. 02

    PIA / DPIA Assessment

    Assess privacy & AI risk with sign-off

    Sec. 10(2)

  3. 03

    Audit & Evidence Management

    Turn compliance into audit-ready evidence

    Sec. 10(2)(b)

  4. 04

    Intelligent Data Mapper

    Find and map personal data automatically

    Sec. 8(3), 8(7)

Sequence

A readiness plan that buys down the biggest exposure first

The same four phases apply in every sector; what changes is which systems go first.

  1. Phase 1

    Weeks 1–6

    See the estate

    • Deploy Discovery across priority systems
    • Build the identity-resolved catalogue
    • Reconcile collected data against notice
  2. Phase 2

    Weeks 4–12

    Stop the bleeding

    • Mask non-production and analytics estates
    • Deploy breach detection and playbooks
    • Wire intimation to the catalogue
  3. Phase 3

    Weeks 8–18

    Fix the basis

    • Roll out purpose-level consent and notice
    • Enforce withdrawal parity and cessation
    • Turn on children's age-band gating
  4. Phase 4

    Weeks 14–26

    Prove it

    • Automate DSAR intake and fulfilment
    • Run DPIA cadence for SDF duties
    • Open the auditor workspace

Also defending governance & risk?

Assurance and audit trails for public institutions deploying AI, with explainable detection output that stands up to oversight.

See the Governance & Risk solution

Find the gaps in your governance & risk programme

A readiness walkthrough maps what you already run onto the eighteen obligations, and names what is missing with the exposure attached.