Back to Sectors & Impact

Government and Public Sector

DPDPA compliance for government bodies - Section 17 exemptions, legitimate uses for public functions, digital public infrastructure, and residual obligations.

8 min read

Sector Overview

Government bodies at central, state, and local levels process vast quantities of personal data for public administration, welfare schemes, taxation, law enforcement, national security, and e-governance services. The DPDPA treats Government instrumentalities as Data Fiduciaries but provides significant carve-outs through exemption provisions and legitimate uses. The growing adoption of digital public infrastructure - Aadhaar, DigiLocker, UPI, CoWIN, and various e-governance platforms - makes government data processing increasingly digital and squarely within the DPDPA's scope. Understanding the boundaries of government exemptions is critical.

Key DPDPA Provisions for Government

Section 17 (Exemptions): Two layers of exemptions apply. (i) Under Section 17(2)(a), the Central Government may notify specific instrumentalities to be exempt from the entire Act in the interest of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order, or prevention of offences. (ii) Section 17(1) also provides "automatic" exemptions for all Data Fiduciaries (including private entities) for specific purposes such as enforcement of legal claims, judicial functions, and prevention, detection, investigation or prosecution of offences - without requiring a separate notification. Section 7 (Legitimate Uses): Government processing falls under specific, enumerated legitimate use categories - performance of State functions (permits, licenses, subsidies, benefits) and compliance with legal obligations. The DPDPA does not include a broad "public interest" ground equivalent to the GDPR; processing must map to a specific Section 7 sub-clause or rely on consent. Section 8 (Residual Obligations): Section 8(5) (Security Safeguards) is non-derogable - even notified exempt agencies (such as IB or CBI) must maintain reasonable security safeguards. By contrast, under Section 17(4), the State is specifically exempted from the accuracy requirement (Section 8(3)) and the erasure requirement (Section 8(7)) where the processing is not used to make a decision that affects the Data Principal. Section 18-26 (Data Protection Board): The Board adjudicates complaints against Government bodies (unless exempted). Government entities must establish grievance redressal mechanisms and respond to Data Principal requests.

Compliance Considerations

1. Scope of Exemptions: Not all government processing is exempt. Exemptions must be specifically notified by the Central Government. Until notification, general DPDPA obligations apply. 2. Legitimate Uses Boundaries: While many government functions fall under legitimate uses, processing for purposes beyond the specific function requires consent. For example, using welfare scheme data for political purposes would not be a legitimate use. 3. Digital Public Infrastructure: Aadhaar-based authentication, DigiLocker document access, and UPI transactions involve processing personal data. The entities managing these platforms must comply with the DPDPA's security and accuracy requirements. 4. Security Safeguards: Government bodies are not exempt from security safeguard obligations. Implementing Rule 6 measures (encryption, access controls, log retention) across government IT systems is required. 5. Outsourced Processing: Government entities frequently outsource data processing to private sector vendors (e-governance projects, IT system management). These vendors are data processors subject to contractual obligations. 6. Data Retention: Government data retention practices must align with the DPDPA. Rule 8 permits retention of personal data processed by or on behalf of the State for up to 1 year after the purpose is fulfilled.

Practical Compliance Checklist

*Note: This checklist is interpretive guidance derived from the DPDPA's general provisions (Sections 7-8, 17, Rules 6, 8, 14). It should be validated by legal counsel for your specific organisational context.* • Identify which processing activities are covered by notified exemptions • Classify remaining processing under legitimate uses vs. consent-based • Implement security safeguards per Rule 6 across government IT systems • Review outsourcing contracts for DPDPA-aligned data processing clauses • Establish web-based grievance redressal mechanisms per Rule 14 • Define data retention policies (1-year post-purpose for State processing per Rule 8) • Ensure data accuracy in citizen-facing databases and systems • Train government personnel on DPDPA obligations and citizen data rights • Conduct DPIA for large-scale government data processing programmes • Review digital public infrastructure platforms for DPDPA compliance

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.