For years, India’s data-protection debate was framed largely as a compliance challenge for technology companies, banks, digital platforms and other private enterprises. That frame is now changing. The next—and arguably more consequential—test of India’s privacy regime will take place inside the government itself.
Cabinet Secretary T.V. Somanathan has directed Union ministries, state governments and Union Territory administrations to draw up time-bound implementation plans for the Digital Personal Data Protection (DPDP) Act, 2023, setting in motion a government-wide exercise to identify personal data, examine how it is being processed and establish institutional responsibility for compliance.
The August 20 communication calls for senior officials to oversee implementation, nodal officers to coordinate with the Ministry of Electronics and Information Technology (MeitY), and phased plans with defined responsibilities and timelines.
The significance extends far beyond administrative compliance. Government departments operate some of India’s largest repositories of personal information, spanning welfare delivery, taxation, healthcare, education, identity verification, licensing and citizen services. As governance becomes increasingly digital and databases become interoperable, the question is no longer simply whether the government can collect and use data efficiently, but whether it can demonstrate accountability for how that data is stored, accessed, shared and eventually erased.
From legislation to implementation
The DPDP Act received Presidential assent on August 11, 2023, while the Digital Personal Data Protection Rules, 2025 were notified in November last year. The government described the framework as balancing citizens’ privacy with lawful data processing and identified consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards and accountability among its core principles. The Rules provide for phased implementation, giving organisations time to re-engineer their systems and processes.
Somanathan’s intervention effectively brings these principles into the administrative machinery of government.
The Cabinet Secretary has asked ministries and states to identify their personal-data processing activities and prepare data inventories. In practical terms, this means departments will have to determine what personal information they possess, where it resides, why it was collected, how it is processed, who has access to it and with whom it is shared.
Departments have also been asked to review privacy notices, consent mechanisms and grievance-redressal arrangements, while examining contracts with vendors and data processors. Legacy technology systems are expected to undergo phased, risk-based reviews.
“A senior officer is designated to oversee implementation of the Act” and “a nodal officer is nominated for coordination with the Ministry of Electronics and Information Technology,” Somanathan said in the communication, according to the reported text. The letter asks authorities to accord implementation “high priority.”
The legacy-database challenge
Creating an inventory may sound procedural, but it could become one of the most difficult parts of the exercise.
Many government databases were built over years—or decades—under different technological standards, administrative mandates and security architectures. Data may exist across departmental servers, cloud environments, state data centres, district-level systems, mobile applications and platforms managed by external technology vendors.
The first compliance challenge, therefore, is visibility: before a department can protect personal information effectively, it must know what it holds and how that information moves through its systems.
The second is purpose. Data originally collected for one government programme may subsequently be used for verification, analytics or delivery of another benefit. The DPDP framework expressly permits specified processing by the State for subsidies, benefits, services, certificates, licences and permits, but requires such processing to conform to prescribed standards.
The third challenge is cybersecurity. Privacy compliance and cybersecurity are distinct disciplines, but in digital government they increasingly converge. A department may have legal authority to process information and still expose citizens to risk if access controls, encryption, logging, vendor management and breach-response mechanisms are inadequate.
Privacy by design, not privacy by repair
Perhaps the most important element of the Cabinet Secretary’s directive is the emphasis on embedding privacy considerations into government technology rather than treating them as a retrospective legal checklist.
Government agencies have been asked to incorporate privacy-by-design principles into the development, enhancement and operation of digital services. That potentially changes the architecture of future e-governance projects: questions about data minimisation, retention, access, sharing and security would have to be considered while systems are being designed, rather than after deployment.
This is particularly relevant as India’s Digital Public Infrastructure expands and artificial intelligence and data analytics become more deeply integrated with public administration. The larger and more interconnected government databases become, the greater the consequences of weak data governance.
The DPDP regime, however, does not treat every government use of data identically. The Act contains specific exemptions, including for notified instrumentalities of the State in areas such as sovereignty, national security and public order. The implementation challenge will therefore involve distinguishing between lawful exemptions and routine administrative processing that remains subject to the broader accountability framework.
Accountability reaches the top
Somanathan’s directive also makes DPDP compliance an administrative leadership issue rather than leaving it solely to government IT departments.
Progress is expected to be reviewed periodically by the secretary or chief secretary concerned. Ministries, departments and states have also been asked to submit brief status notes so that common implementation problems can be identified and addressed through coordinated guidance. MeitY, meanwhile, is expected to provide implementation support, including guidance and capacity-building.
This governance structure could prove critical. Effective privacy compliance requires coordination between administrative departments, CIOs and IT teams, cybersecurity officials, legal divisions, programme managers and external technology providers. Appointing a nodal officer creates ownership, but the effectiveness of the exercise will ultimately depend on whether that official has sufficient authority, technical expertise and institutional support.
The government itself has described the DPDP framework as one designed to “empower citizens and protect privacy,” while supporting responsible use of data. The Cabinet Secretary’s directive now puts that proposition to a practical test.
India has already demonstrated its capacity to build digital public systems at extraordinary scale. DPDP implementation presents a different institutional challenge: governing the enormous quantities of data generated by that digital transformation.
The crucial question, therefore, is not merely whether ministries and states can meet a compliance deadline. It is whether privacy, security and accountability can become routine elements of public administration.
If that transition succeeds, the DPDP Act could do more than regulate databases. It could establish a new operating principle for digital government: that the State’s capacity to use citizens’ data must grow alongside its responsibility to protect it.


