Skip to content
FaceOff Technologies

DPDP by industry

DPDP for government and public-sector bodies

State instrumentalities carry exemptions in some directions and heightened scrutiny in others. The practical question is rarely whether an exemption applies — it is whether the body can evidence which one it relied on, and when.

Deadline
13 May 2027
Pressure points
4 identified
Controls
4 products
Max penalty
₹250 Cr, per instance

Already regulated by

  • MeitY
  • CERT-In
  • Data Protection Board
  • CAG

DPDP sits alongside these rather than replacing them. Where a sectoral rule requires retention and the Act requires erasure, both are satisfiable — but only where the basis is recorded per attribute.

Where the pressure lands

What DPDP actually changes for governance & risk

The Act applies uniformly. The obligations that bite first do not — these are the ones this sector fails on.

Sec. 7, 17

Exemptions have to be evidenced, not assumed

Processing for subsidies, benefits, services, certificates, licences and permits is a listed legitimate use. Relying on it without recording the basis per activity turns a lawful position into an undocumented gap at inquiry.

Sec. 10(2)(c)(iii)

Algorithmic due diligence on public systems

Automated decisioning that affects entitlement carries the heaviest justification burden. Model purpose, training-data provenance, bias testing and human oversight all have to be on record.

Sec. 5

Notice in scheduled languages

Public-facing services reach citizens who are entitled to notice in any of the twenty-two Eighth Schedule languages. Serving English alone is a defect in the notice itself, not a translation backlog.

Sec. 28

Records production under inquiry

The Board may require production of records. For a public body the evidence trail is also the audit trail the CAG and the legislature will ask for.

What closes them

The controls, in the order they land

Discovery first, because every other obligation is undeliverable without a catalogue. Everything after that consumes what it built.

  1. 01

    Privacy Program Governance

    Run the whole privacy programme from one control plane, so the next regulation lands as configuration.

    Sec. 4, 7, 10, 16

  2. 02

    PIA / DPIA Assessment

    Find and price privacy risk at design time, and keep a defensible assessment record the auditor can read.

    Sec. 10(2)

  3. 03

    Audit & Evidence Management

    Prove compliance from evidence rather than assert it from policy, at any depth, on demand.

    Sec. 10(2)(b)

  4. 04

    Intelligent Data Mapper

    Replace stale inventories with a live, identity-resolved map of every place personal data actually lives.

    Sec. 8(3), 8(7)

Sequence

A readiness plan that buys down the biggest exposure first

The same four phases apply in every sector; what changes is which systems go first.

  1. Phase 1

    Weeks 1–6

    See the estate

    • Deploy Discovery across priority systems
    • Build the identity-resolved catalogue
    • Reconcile collected data against notice
  2. Phase 2

    Weeks 4–12

    Stop the bleeding

    • Mask non-production and analytics estates
    • Deploy breach detection and playbooks
    • Wire intimation to the catalogue
  3. Phase 3

    Weeks 8–18

    Fix the basis

    • Roll out purpose-level consent and notice
    • Enforce withdrawal parity and cessation
    • Turn on children's age-band gating
  4. Phase 4

    Weeks 14–26

    Prove it

    • Automate DSAR intake and fulfilment
    • Run DPIA cadence for SDF duties
    • Open the auditor workspace

Also defending governance & risk?

Assurance and audit trails for public institutions deploying AI, with explainable detection output that stands up to oversight.

See the Governance & Risk solution

Find the gaps in your governance & risk programme.

A readiness walkthrough maps what you already run onto the eighteen obligations, and names what is missing with the exposure attached.