The Centre has begun directing ministries, departments, states and Union Territories to prepare for compliance with the Digital Personal Data Protection (DPDP) Act, with the Cabinet Secretariat seeking defined implementation plans, senior-level oversight and a review of how government bodies collect, process and protect citizens’ personal data.
In a letter dated August 20 to secretaries of the Government of India and chief secretaries of states and Union Territories, Cabinet Secretary T V Somanathan asked government bodies to prepare phased implementation plans with clearly defined responsibilities and timelines. Progress is to be reviewed periodically by the secretary or chief secretary concerned.
The move places responsibility for implementing the data protection framework directly with the administrative leadership of ministries, departments and state governments, while requiring officials to examine existing personal-data practices and prepare the systems needed for compliance.
Senior Officers to Oversee DPDP Implementation
Each ministry, department and state has been asked to designate a senior officer to oversee implementation of the DPDP Act.
A nodal officer is also to be nominated to coordinate with the Ministry of Electronics and Information Technology, or MeitY, which is the nodal ministry for the law.
The Cabinet Secretary’s directions call for government bodies to draw up phased plans rather than approach compliance as a single exercise. These plans are expected to spell out responsibilities, implementation schedules and mechanisms for monitoring progress.
Periodic reviews by the secretary or chief secretary concerned are also envisaged, placing the compliance process under direct administrative supervision.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Government Bodies Asked to Map Personal Data Processing
A central part of the exercise will require government organisations to first establish how and where personal data is being processed.
Ministries, departments and states have been asked to identify their personal-data processing activities and prepare appropriate data inventories. The exercise is intended to provide authorities with a clearer picture of the types of personal information being handled and the processes through which it is collected and used.
Government bodies will also have to review privacy notices and consent mechanisms wherever applicable. Existing grievance-redressal arrangements are also expected to be examined as part of the compliance exercise.
The emphasis on preparing data inventories indicates that departments will first need to identify and document their existing data-handling practices before implementing changes required under the law.
Safeguards, Vendors and Staff Training Under Review
Government organisations have also been asked to strengthen technical and organisational safeguards connected with personal-data processing.
The review is expected to include contractual arrangements with third-party vendors and data processors, bringing outsourced data-handling arrangements within the broader compliance exercise.
Departments and states will also be required to focus on capacity building and sensitisation of officers responsible for implementing the Act. This is intended to ensure that officials handling compliance responsibilities understand the requirements governing personal-data processing and protection.
The Cabinet Secretariat’s directions therefore cover both administrative accountability and operational changes, ranging from identifying data-processing activities and creating inventories to reviewing consent practices, grievance mechanisms and safeguards.
With ministries, departments, states and Union Territories now being asked to assign officers, prepare timelines and periodically review progress, the implementation of the DPDP framework is set to require a wider examination of data practices across government bodies.