Government Orders

Cabinet Secretary Directs Ministries and States to Plan for DPDP Act Compliance

CADP Correspondent|

Cabinet Secretary T V Somanathan has asked central ministries, states and UTs to draw up time-bound DPDP Act implementation plans and appoint senior nodal officers.

Cabinet Secretary T V Somanathan has written to every secretary in the Union government and to the chief secretaries of all states and union territories, directing them to prepare time-bound plans for implementing the Digital Personal Data Protection Act, 2023 (DPDP Act) and to appoint senior nodal officers to oversee compliance. The Times of India, which reported the letter on 27 August 2026, describes it as the Centre's first formal push to enforce the Act across government. The letter asks departments to treat the law as a high priority and to send status reports so that common problems can be resolved together. The report does not say what deadlines the plans must meet.

The steps in the letter are concrete. Departments must identify where they process personal data and build data inventories. They must review their consent and grievance-redressal mechanisms, set up governance structures, strengthen technical and organisational safeguards, and revisit contracts with third-party data processors. The letter also calls for training officials and building privacy by design into government digital services. The Ministry of Electronics and Information Technology (MeitY), the nodal ministry for the Act, has begun issuing guidance material and running awareness and training programmes.

The letter treats government bodies as data fiduciaries, the entities that decide why and how personal data is processed. That reading is correct. Section 17 lets the Centre exempt notified instrumentalities of the State for purposes such as sovereignty, security and public order, but the Act contains no blanket exemption for government. A department running a scholarship portal or a land records system carries the same core duties as a private company. Section 7(b) does let the State process personal data without fresh consent to deliver subsidies, benefits, services, certificates, licences and permits, but only within the standards set by Rule 5 and the Second Schedule of the DPDP Rules, 2025.

I would argue the timing matters more than the tone. The operational duties in Rules 3 and 5 to 16, covering notice, security safeguards, breach reporting, retention and the rights of data principals, come into force in May 2027. For a large ministry with legacy systems, eight months is very little time to map data flows and rewrite vendor contracts. The data inventory is the step everything else depends on, and it is the step most likely to be rushed. So departments should start there. The letter also follows a period in which courts have pointed petitioners back to the executive; in May, the Supreme Court sent a PIL on stolen personal data to MeitY rather than hearing it. Private companies that build software or process data for government should expect their contracts to be reopened, with audit, breach notification and deletion clauses that were not there before.

Topics
DPDP ActCabinet SecretaryMeitYGovernment Data FiduciariesState GovernmentsDPDP Rules 2025Compliance Timelines
Get in Touch

Navigating the DPDP Act

Explore our research, training programmes, and advisory services on data protection law and compliance in India.