Government Must Now Follow Its Own DPDP Rules
By Privy
Aug 28, 2026

Government Must Now Follow Its Own DPDP Rules

India's Cabinet Secretary has reportedly directed central ministries, departments, and state governments to align with the Digital Personal Data Protection Act, according to a report from CIO Bulletin dated 27 August 2026. We have not been able to independently verify this against a Cabinet Secretariat release or PIB notification at the time of writing, so treat the specific administrative details here as reported rather than confirmed, and check for an official notification before citing this as settled fact.

If accurate, this is less a legal first than an enforcement first. Government bodies were already data fiduciaries under the DPDP Act from the day it was notified. What appears to be new is administrative pressure to act on obligations that already existed on paper. MeitY Secretary S. Krishnan is quoted as describing the move as compliance by design, meant to protect citizens' privacy as India's digital public infrastructure keeps expanding. Government bodies would need to audit their own data practices, fix consent flows, and name accountable officers. For enterprises that build, host, or process data for government programmes, that pressure does not stop at the ministry gate.

What the Directive Actually Requires From Ministries and States

The instruction, as reported, is specific rather than symbolic. Ministries, departments, and state governments would need to audit how they collect and store citizen data, fix privacy notices that do not meet DPDP standards, and put working consent mechanisms in place wherever consent is the legal basis for processing.

Each government body would need to name someone accountable for privacy requests. Under Section 8 of the DPDP Act, this role has a formal name: a designated person whom data principals can contact to exercise their rights. Citizens dealing with a government portal, a welfare scheme, or a state health system should be able to access, correct, or ask for erasure of their data, the same rights they would have with a private company under the Act.

States would run their own infrastructure audits, with the Centre tracking progress to keep the pace consistent. A state government that lags creates a weak link for citizen data flowing through federated systems like Aadhaar-linked services or national health records, which is likely why this pushes states alongside ministries rather than ministries alone.

This lands inside a schedule that is already running. The DPDP Rules were notified on 13 November 2025. Consent Manager registration opens on 13 November 2026. The remaining substantive obligations, including consent, notice, and security requirements, become enforceable on 13 May 2027, with penalties up to ₹250 crore per contravention. For a fuller breakdown of what that timeline demands of any enterprise, our complete guide to DPDP compliance for 2026 walks through it end to end.

state vs centre data control

The Federalism Question Behind This Directive

India's data protection regime sits inside a federal structure, and that creates a real tension the DPDP Act has not fully resolved. Section 17 lets the Central Government exempt its own instrumentalities from most provisions when processing touches sovereignty, security of the state, public order, or friendly relations with foreign states. When an exemption applies, most data principal rights and data fiduciary duties stop applying, though the duty to keep reasonable security safeguards in place still holds.

That is a wide door, and critics argue these exemptions lack the independent oversight the Puttaswamy judgment's proportionality test calls for. The Supreme Court's 2017 ruling set three conditions for state action that restricts privacy: a legislative mandate, a legitimate state purpose, and proportionality between the action and the goal. A constitutional challenge to Section 17 is a real possibility as the regime matures.

There is a counterargument worth stating plainly, though. National security and law enforcement processing genuinely cannot run through the same consent and notice machinery as commercial processing, since telling a surveillance target that their data is being processed defeats the purpose of the processing. Most comparable regimes carve out similar space; GDPR's Article 23 allows member states to restrict data subject rights for national security and defence, for example. The debate is less about whether any exemption should exist and more about how tightly it should be scoped and who checks that it stays within bounds. This directive, if it results in real audits and named accountability officers, is one practical way to narrow that gap without touching the exemption itself.

One open question the reporting does not answer: what happens when a ministry does not comply? Private data fiduciaries answer to the Data Protection Board of India, with penalties running up to ₹250 crore. It is not yet clear whether government non-compliance routes through the same Board, through parliamentary oversight, through CAG audit, or through internal administrative action. That accountability gap is worth watching as more detail on this directive becomes available.

States occupy a different position again. They collect enormous volumes of citizen data through welfare schemes, state-run healthcare, and local administration, yet the Act does not clearly separate central and state authority the way India's constitutional structure usually does elsewhere. Some states have already built their own frameworks ahead of the Centre; Tamil Nadu's Safe and Ethical Artificial Intelligence Policy and Telangana's Data Sharing Protocol are two examples, so this directive is as much about pulling states into a common baseline as it is about ministries.

The RTI Conflict Nobody Has Fully Settled

The DPDP Act amended Section 8(1)(j) of the Right to Information Act, removing the public interest override that used to let citizens access personal information about public officials when disclosure served the larger public interest. What used to be a case-by-case balancing test is now closer to a blanket restriction on sharing personal information under RTI.

This creates what commentators have called the legitimate uses paradox. Government departments can process citizen data without consent under several DPDP provisions, including the performance of any function under law, while citizens making RTI requests can be denied access to official information under the same privacy rationale. That asymmetry is exactly what better consent, better notice, and named accountable officers are supposed to narrow, not paper over.

RTI vs DPDP

What This Looks Like in Practice

The abstract version of this story is a ministry auditing its own systems. The practical version runs through the private companies that actually operate those systems.

Take a Direct Benefit Transfer scheme that routes a subsidy from a central ministry through a bank, into a beneficiary's account, verified against Aadhaar. Or a state government's integration with the Ayushman Bharat Digital Mission, where a hospital network, an insurer, and a state health department all touch the same patient record. In both cases, the government body is only one node. A bank, an insurer, a fintech, or a hospital IT vendor is processing the same citizen data, often with looser oversight than the ministry itself has just been told to fix.

If a ministry's audit surfaces a gap in how a scheme handles consent or retention, the fastest place to close that gap is usually the vendor contract, not the ministry's own systems. That is where this directive stops being a government story and starts being an enterprise one.

Why This Matters Beyond Government Itself

Most companies that touch government data are not ministries. They are vendors, GovTech platforms, PSU contractors, and BFSI players running government-linked schemes, processing citizen data on the government's behalf as data processors, or holding direct data fiduciary obligations for their own layer of the data.

When a ministry has to demonstrate a working consent mechanism to the Cabinet Secretariat, that requirement tends to flow down its contracts. A vendor running a state welfare portal, a fintech disbursing subsidies, or a healthtech company integrated with a state health record system should expect the same questions its government client is now facing: where is the data mapped, what is the legal basis for processing, who is the accountable officer, and can a citizen actually exercise their rights through the system? Our guide on what constitutes PII data in India is a useful starting point for scoping what counts here.

Significant Data Fiduciaries face a sharper version of this, though it is worth being precise about where that status actually stands today. Section 10 gives the Central Government power to designate an entity as a Significant Data Fiduciary based on the volume and sensitivity of personal data it processes, risk to data principals, and potential impact on sovereignty, security, or public order, the same language Section 17 uses for government exemptions. No entity has been formally notified as an SDF yet, and MeitY has only proposed accelerating that timeline. A company processing large volumes of citizen data on behalf of government would be reasonable to prepare for that designation, but should not treat it as confirmed.

This is also where the picture connects to a separate regulatory track for banks and NBFCs. RBI's draft Guidance on Regulatory Expectations for Data Governance, released mid 2026, asks regulated entities to build a Single Source of Truth, metadata, and data lineage across all data, not personal data alone. A bank disbursing a government scheme now sits at the intersection of three expectations at once: DPDP's consent and rights obligations, RBI's data governance draft, and this directive's pressure on its government counterparty. We cover the RBI side in detail in RBI's New Data Governance Framework Meets DPDP, and the practical takeaway is the same either way: one data map, built once, tends to answer all three.

How Enterprises Build This Into an Ongoing Programme

Treating this as a one-time audit misses the point. Government contracts get renewed, schemes get renegotiated, and a compliance posture that was adequate at signing will not stay adequate through the life of the contract.

A workable programme puts someone specific in charge of government-linked data flows, distinct from your general DPDP owner, since the consent basis, retention rules, and reporting obligations often differ when government is the counterparty. It reviews those flows on a fixed cadence, not only when a contract is up for renewal, or an incident forces the question. It keeps the vendor inventory for any subcontractor touching government data current, since a compliance gap two vendors down the chain still lands on you. And it treats a change in government policy, like this directive, as a trigger to re-audit rather than a headline to note and move past.

best DPDP compliance platforms India

How Privy Supports Compliance in Government Linked Data Environments

This is where Privy by IDfy's full-stack approach earns its keep, because a directive like this does not stay contained to one team or one system. It touches data mapping, consent, vendor risk, and incident response all at once, and increasingly, for BFSI clients, RBI's data governance expectations too.

Data Compass, Privy's data discovery and governance module, maps personal data across systems, including the integrations that connect to government portals and schemes, so you know where government-linked citizen data lives before an auditor asks. The Privacy Impact Assessment module lets you run a focused assessment on that specific data flow rather than treating it as an afterthought inside a broader review. Our third-party risk management capability extends that same visibility to subcontractors, so a compliance gap two vendors down the chain does not become your liability.

IDfy also brings something no other Indian platform can claim here: it won the Indian government's own DPDP Innovation Challenge for consent technologies, recognised by MeitY and NeGD. When your data flows connect to government systems, working with a platform built alongside that same regulatory architecture is a practical advantage, not a marketing line.

Meity-NeGD's DPDP Innovation Challenge winner

Read more..

Conclusion

Government has spent two years operating under data protection obligations that mostly went unenforced against itself. This directive, if the reporting holds up, is a sign that is starting to change, and that pressure will move down through contracts to every vendor, GovTech platform, and BFSI player connected to a government scheme or portal.

Privy by IDfy already helps enterprises across banking, fintech, insurance, telecom, and e-commerce map, govern, and prove control over personal data, the same foundation this directive now asks of government itself. Book a demo to see how Privy by IDfy helps enterprises get ahead of government-linked DPDP exposure. To schedule a personalised walkthrough, contact shivani@idfy.com.

best DPDP compliance platforms India

FAQ’s

Does the DPDP Act apply to government departments?
Yes, government ministries, departments, and state bodies that collect, store, or process citizen data are treated as data fiduciaries under the Act, though Section 17 allows the Central Government to exempt specific instrumentalities from most provisions for reasons like sovereignty, security, or public order.

What is Section 17 of the DPDP Act?
Section 17 lets the Central Government exempt its own instrumentalities from most DPDP obligations when processing is necessary for the sovereignty and integrity of India, the security of the state, friendly relations with foreign states, public order, or preventing incitement to certain offences. The duty to maintain reasonable security safeguards still applies even when an exemption is granted.

How does the DPDP Act affect RTI requests?
The DPDP Act amended Section 8(1)(j) of the RTI Act and removed the public interest override that previously let citizens access personal information about officials when disclosure served the public interest. Personal information is now more broadly protected from disclosure by default.

Is the DPDP Act currently in force?
Yes, in phases. The Data Protection Board of India and foundational provisions took effect on 13 November 2025. Consent Manager registration opens on 13 November 2026. The remaining substantive obligations become enforceable on 13 May 2027.

What is a Significant Data Fiduciary under the DPDP Act?
A Significant Data Fiduciary is an entity the Central Government designates based on factors including the volume and sensitivity of personal data it processes, risk to data principals, and potential impact on sovereignty, security, or public order. No entity has been formally notified yet, though SDFs face enhanced obligations including mandatory data protection impact assessments and independent audits once designated.

Do vendors working with government data need to comply separately?
Yes. Vendors and contractors processing personal data on behalf of a government body typically function as data processors or as data fiduciaries in their own right for parts of the data flow they control, and government clients are increasingly likely to push DPDP compliance requirements into vendor contracts.

What should a company do if it processes data connected to a government scheme?
Map the data flow into and out of government systems, review contract clauses for updated compliance requirements, run a dedicated privacy impact assessment on that flow, extend vendor risk checks to any subcontractor in the chain, and set a fixed cadence to review the whole flow again rather than treating it as a one-time exercise.

Search Here

Reach out to us

Explore More

DPDP Compliance at Scale: A 90-Day Implementation Guide for Indian Enterprises
DPDP Rules

Feb 16, 2026

DPDP Compliance at Scale: A 90-Day Implementation Guide for Indian Enterprises

RBI's New Data Governance Framework Meets DPDP: What Banks and NBFCs Must Build
DPDP Rules

Jul 16, 2026

RBI's New Data Governance Framework Meets DPDP: What Banks and NBFCs Must Build

Share