Key Points
- Cabinet Secretary directs all ministries and states to prepare DPDP Act compliance plans
- Government bodies must create data inventories and review privacy notices
- Privacy-by-design principles to be embedded in all government digital services
Cabinet Secretary TV Somanathan has directed all central ministries, state governments and Union Territory administrations to prepare implementation plans for the Digital Personal Data Protection Act, marking the Centre’s first formal push to bring its own agencies under the 2023 law.
In a letter dated 20 August addressed to Secretaries of the Government of India and Chief Secretaries of states and Union Territories, Somanathan asked government bodies to designate senior officials to oversee compliance, nominate nodal officers for coordination with MeitY and prepare phased implementation plans with defined responsibilities and timelines.
Progress on implementation is to be reviewed periodically by the Secretary or Chief Secretary concerned, placing accountability for compliance directly with the administrative leadership of each ministry and state.
The directive is significant because government agencies are among the country’s largest collectors of citizens’ personal data. Digital systems spanning welfare delivery, taxation, healthcare, identity verification and public services process personal information at scale, making government compliance a critical early test of how the DPDP Act will work in practice.
Data inventories
The compliance exercise requires government organisations to first establish how and where they process personal data. The Cabinet Secretary has called for identification of all personal data processing activities and preparation of data inventories, which are structured records of what data is collected, why and how it is stored.
Government bodies must also review privacy notices, consent mechanisms and grievance redressal arrangements. They will need to examine contractual arrangements with third-party vendors and data processors to ensure these meet the requirements of the new law.
A key requirement is embedding privacy considerations into government technology systems rather than treating compliance as an afterthought. Ministries and states have been asked to incorporate privacy-by-design principles, meaning the building of data protection safeguards into systems from the design stage rather than adding them later, into the development, enhancement and operation of digital government services.
Legacy systems, meaning older technology infrastructure built before current privacy requirements existed, are to be reviewed in a phased, risk-based manner.
“A senior officer is designated to oversee implementation of the Act” and “a nodal officer is nominated for coordination with the Ministry of Electronics and Information Technology,” Somanathan said in the letter.
Capacity building
The Cabinet Secretary has called for capacity building and sensitisation of officers responsible for implementing the law. This will require departments to examine not only their technology systems but also internal processes governing access to, use and protection of personal information.
Appropriate governance mechanisms and institutional processes are to be established across government agencies.
MeitY has already begun preparing guidance material, conducting awareness initiatives and capacity building programmes, and consulting stakeholders to support implementation. The ministry will continue to provide implementation support to all government bodies.
The letter asks government bodies to accord the matter “high priority” and initiate appropriate institutional, administrative and technical measures for timely implementation of the law.
Somanathan has also sought a brief note on the status of implementation from each ministry, department and state so that common implementation issues requiring guidance or support may be addressed in a coordinated manner.
The Digital Personal Data Protection Act was passed by Parliament in August 2023 and received Presidential assent on 11 August 2023. The law establishes a framework for how personal data can be collected, processed and stored, and creates the Data Protection Board of India to adjudicate complaints.
Government agencies qualify as data fiduciaries under the Act, meaning they have obligations around lawful processing, purpose limitation, data minimisation and ensuring accuracy of personal data they hold. Citizens have rights under the law including the right to access their data, correct inaccuracies and request erasure.
The implementation timeline for various provisions of the Act is being notified in phases by MeitY.
Your Questions, Answered
What has the Cabinet Secretary asked ministries to do for DPDP Act compliance?
Ministries must designate senior officers to oversee implementation, nominate nodal officers for coordination with MeitY, prepare phased implementation plans with timelines and create data inventories of all personal data processing activities.
What is privacy-by-design and why must government agencies implement it?
Privacy-by-design means building data protection safeguards into technology systems from the design stage rather than adding them later. Government agencies must incorporate these principles into all digital government services.
Why is government compliance with the DPDP Act significant?
Government agencies are among India's largest collectors of citizens' personal data through welfare delivery, taxation, healthcare and identity systems. Their compliance is an early test of how the law will work in practice.
What legacy system review does the Cabinet Secretary require?
Older government technology systems built before current privacy requirements must be reviewed in a phased, risk-based manner to ensure they meet DPDP Act requirements.

