A common assumption inside government offices is that the Digital Personal Data Protection Act is a private-sector problem. It is not. The Act applies to the processing of digital personal data broadly, and while it carves out exemptions for the State in specific circumstances — such as certain security, sovereignty and legal functions — those exemptions are purpose-specific, not a blanket pass for every department database and citizen-facing portal.
Where departments handle personal data
Think about what a typical department website and back office actually process: grievance forms with names and phone numbers, scheme applications with bank details, RTI requests, recruitment portals holding lakhs of candidate records, CCTV feeds, and contact databases shared with vendors who send SMS campaigns. Each of these is personal data processing with a defined purpose — and each needs a lawful basis, appropriate security, and a plan for what happens when a citizen asks what you hold about them.
The obligations that matter most in practice
Three areas deserve immediate attention. First, notice and consent where consent is the basis: citizen-facing forms should state plainly what is collected and why. Second, security safeguards: the Act expects reasonable measures to prevent breaches, and a breach must be reported — a department portal leaking applicant data is now a legal event, not just an embarrassment. Third, vendor discipline: the SMS gateway, the website contractor, the cloud provider — departments remain responsible for personal data processed on their behalf, which means data protection terms belong in every IT contract and tender.
A practical starting sequence
Map what personal data your department collects and where it lives — most departments discover forgotten Excel exports and legacy portals in this step. Fix the visible surface first: privacy policy on the website, purpose statements on forms, HTTPS and security headers on every portal. Then work inward: access control on databases, retention rules, and vendor agreements. Our free DPDP readiness check at karleesh.com/tools/dpdp-readiness gives you a scored gap report in ten minutes, and the full government-focused guide — including how DPDP interacts with GIGW 3.0 requirements — is in Issue 01 of The Karleesh Quarterly, free at karleesh.com/insights/magazine.
Free download
Website Security Checklist (PDF)
25 practical checks every business website should pass — from our security team.