AMLEGALS — Strategic Lawyering

DPDPA for Government Contractors and Vendors

DPDPA for Government Contractors and Vendors

You hold the citizen's data. You hold the citizen's risk.

The scene

The contractor ran a state scheme's beneficiary portal. Millions of records: names, bank accounts, identity numbers, caste certificates. The department assumed the vendor was secure. The vendor assumed the department's exemption covered it.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Government work is exempt.

Section 17(2)(a) exempts notified instrumentalities of the State; vendors are not automatically covered.

Read the notification. Then read your contract.

The department sets the rules.

As processor you still need safeguards; as fiduciary for your own purposes you carry the Act directly.

Know which role you play in each system.

Public data isn't personal data.

Beneficiary data is personal data of citizens.

Protect it as though your name were on it. It often is.

Contracts decide

Government tenders are adding data protection clauses. The vendor that can evidence safeguards, breach readiness and deletion at contract end is the one that renews.

The full Government vendors briefing 3 deep dives

Deep dive 01 →

The State's exemption is not your exemption.

Read the notification. Then read your contract. Then read them again.

Deep dive 02 →

The contract ended. The citizens' data did not.

Handover is not finished until the last copy is gone.

Deep dive 03 →

Real citizens in test data.

Test data is not fake just because the server is.

Monday morning

01 List every government system you run that holds personal data.

02 Confirm in writing who is fiduciary for each.

03 Plan data return and deletion at contract end.

Questions, answered plainly

Does the government exemption under DPDPA apply to contractors? +

Section 17(2)(a) lets the Central Government exempt notified instrumentalities of the State in specified interests. It does not automatically exempt private vendors, and the scope of any exemption depends on the notification.

Are government IT vendors Data Processors under DPDPA? +

Where they process personal data on a department's instructions, they generally act as Data Processors. Where they use the data for their own purposes, they may be Data Fiduciaries.

Sector · Banking & BFSI Banks keep everything. The law now asks why. Read →

Sector · Fintech & NBFC Your onboarding takes ninety seconds. Your liability lasts years. Read →

Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).